Skip to main content
← Back to Demos
Script Injection beginner · 15 min

OneNote Notebook Hides an Embedded Executable

OneNote notebooks are a favorite container for initial access because users treat .one files as harmless notes. Attackers embed executable files, scripts, or download stubs inside notebook pages, where they appear as unassuming attachments waiting to be double-clicked. This demo presents a .one file carrying a benign embedded command that only opens Calculator — the same structure real campaigns use to drop payloads. Deep CDR parses the notebook structure and reconstructs it from scratch, stripping embedded objects, OLE content, and active links while preserving the readable note text. The sanitized file keeps its business utility but contains no code that could execute on an endpoint.

Attack Technique

OneNote embedded file

MITRE ATT&CK

T1204.002 ↗

Platforms

linuxwindows

File Types

.html

MetaDefender Capabilities

Deep CDR

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---