Detecting Embedded Content in OOXML Documents

2022-08-18 Mandiant

https://www.mandiant.com/resources/detecting-embedded-content-in-ooxml-documents

Thumbnail for Detecting Embedded Content in OOXML Documents

Mandiant describes a method for clustering malicious Office Open XML documents by ZIP local-file-header metadata such as CRC-32 values, uncompressed sizes, and embedded file names. The DPRK-relevant example uses a YARA rule to detect OOXML documents carrying a specific PNG image found in files that drop LATEOP and are attributed to groups including UNC1130, which Mandiant identifies as a North Korean state-sponsored actor. The technique is presented as a repeatable way for analysts to find related documents that reuse the same embedded content over time, while other examples in the article cover non-DPRK activity such as FIN7.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 397ba1d0601558dfe34cd5aafaedd18e 2022-08-18 2022-08-18
HASH 0dc39af4899f6aa0a8d29426aba59314 2022-08-18 2022-08-18
HASH 3bdfaf98d820a1d8536625b9efd3bb14 2022-08-18 2022-08-18
HASH 252227b8701d45deb0cc6b0edad98836 2022-08-18 2022-08-18

Related Actors

« Back