Detecting Embedded Content in OOXML Documents
2022-08-18 • Mandiant •
https://www.mandiant.com/resources/detecting-embedded-content-in-ooxml-documents
Mandiant describes a method for clustering malicious Office Open XML documents by ZIP local-file-header metadata such as CRC-32 values, uncompressed sizes, and embedded file names. The DPRK-relevant example uses a YARA rule to detect OOXML documents carrying a specific PNG image found in files that drop LATEOP and are attributed to groups including UNC1130, which Mandiant identifies as a North Korean state-sponsored actor. The technique is presented as a repeatable way for analysts to find related documents that reuse the same embedded content over time, while other examples in the article cover non-DPRK activity such as FIN7.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 397ba1d0601558dfe34cd5aafaedd18e | 2022-08-18 | 2022-08-18 |
| HASH | 0dc39af4899f6aa0a8d29426aba59314 | 2022-08-18 | 2022-08-18 |
| HASH | 3bdfaf98d820a1d8536625b9efd3bb14 | 2022-08-18 | 2022-08-18 |
| HASH | 252227b8701d45deb0cc6b0edad98836 | 2022-08-18 | 2022-08-18 |