My colleague @r00tbsd wrote an awesome tool for parsing pesky malicious .one files we ( @volexity ) have been seeing around lately:

https://github.com/volexity/threat-intel/tree/main/tools/one-extract

If you wanna analyze these files in bulk, look no further!

threat-intel/tools/one-extract at main · volexity/threat-intel

Signatures and IoCs from public Volexity blog posts. - threat-intel/tools/one-extract at main · volexity/threat-intel

GitHub