Suspicious VBA Runtime Loaded by Process from OneNote Exported Directory

PremiumReviewedSigma · High · v1
Product
windows
Category
image_load
Author
HuntRule
Published
2026-05-15
Updated
2026-08-28

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects a process running from the OneNote exported attachment or temp directory loading the VBE7.dll VBA runtime, indicating macro or script execution from a weaponised OneNote embedded file. Legitimate applications rarely execute from the OneNote Exported path, so loading the VBA engine from there signals malicious code launched via a OneNote phishing lure.

Related detections9 linkedT1204.002 — drag to rearrange
Malicious more_eggs LOLBIN Scriptlet Execution via ie4uinit BaseSettings Abuse (via process_creation)
Suspicious FileFix TypedPaths Entry Containing PowerShell or URL
Windows: Detect Advanced Installer PSF AI_STUBS Executables with OriginalFileName popupwrapper.exe
Suspicious Cabinet Extraction of Masqueraded vstm Archive via extrac32
Suspicious Interlock Fake Updater Executable Execution
Malicious Office Application Loading a User-Path DLL via Regsvr32 or Rundll32 (via process_creation)
Suspicious Program Execution From a Mounted ISO or Disk Image (via process_creation)
SocGholish Fake Browser Update Script Execution (via process_creation)
Malicious DLL Execution via Wuauclt Update Handler (via process_creation)
Suspicious VBA Runtime Loaded by Process from OneNote Exported Directory
Pivot detection · T1204.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.