MS Office 정상 URL 위장하여 유포중인 워드문서

2022-11-17 Ahnlab Word document being distributed disguised as MS Office normal URL

https://asec.ahnlab.com/ko/42233/

Thumbnail for MS Office 정상 URL 위장하여 유포중인 워드문서

AhnLab reports malicious Word documents distributed through channels such as group chats and crafted to resemble legitimate Microsoft Office URLs. The documents used OOXML external template injection, with domains visually close to openxmlformats.org, ms-office services, or Office template sites, to download remote macro templates. The filenames and themes targeted South Korean foreign-policy and security experts with topics such as China, North Korea, and diplomatic issues. The report emphasizes that attackers increasingly use lookalike Office infrastructure and document-theme personalization to make malicious template injection harder to identify.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://schemas.openxmlformats.o… 2020-03-20 2023-06-06
DOMAIN ms-offices.com 2022-11-17 2022-12-07
HASH d698fccf14f670595442155395f42642 2022-11-17 2022-11-25
URL https://ms-office.services/temp… 2022-11-17 2022-11-25
URL https://ms-office.services/temp… 2022-11-17 2022-11-25
URL https://ms-offices.com/template… 2022-11-17 2022-11-25
URL http://schemas.openxmlformat.or… 2022-11-17 2022-11-25
URL http://schemas.openxmlformat.or… 2022-11-17 2022-11-25
URL http://offices.word-template.net 2022-11-17 2022-11-25
URL https://ms-office.services/temp… 2022-11-17 2022-11-25
URL http://offices.word-template.ne… 2022-11-17 2022-11-25
URL https://ms-offices.com 2022-11-17 2022-11-25
URL https://ms-offices.com/template… 2022-11-17 2022-11-25
URL http://schemas.openxmlformat.org 2022-11-17 2022-11-25
URL https://ms-office.services 2022-11-17 2022-11-25
URL https://ms-office.services/temp… 2022-11-17 2022-11-25
URL https://ms-offices.com/template… 2022-11-17 2022-11-25
DOMAIN offices.word-template.net 2022-11-17 2022-11-25
DOMAIN ms-office.services 2022-11-17 2022-11-25

Related Actors

Related Reports

« Back