detect one-note attachment abuse (malware)

kiran.landge

New Member
Nov 19, 2021
1
0
1
34
Hi,

We are witness of one-Note attachment with .one file extension which execute payload using cmd & Power-shell when user tryied to open it from MS Outlook mail client.

Can we detect & Block abuse contain inside of any one-note / document at Email Gateway ?

We have remove attachment rule for set of known executable file extensions as mentioned in attach snaps.

Please share configuration steps if anyone have enforce such rules with object to look inside file abuse code.

Regards,

Kiran Landge
 

Attachments

  • OneNote_Mail_Attachment.JPG
    OneNote_Mail_Attachment.JPG
    21.5 KB · Views: 11
  • Dangerous Content.JPG
    Dangerous Content.JPG
    80.5 KB · Views: 11
  • Remove attachment_Rule.JPG
    Remove attachment_Rule.JPG
    138.3 KB · Views: 10
Just add 'one' as further extension in the match filename object containing '.*\.(vbs|pif|...`

I hope this helps!
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!