MS Office 정상 URL 위장하여 유포중인 워드문서
2022-11-17 • Ahnlab • Word document being distributed disguised as MS Office normal URL •
AhnLab reports malicious Word documents distributed through channels such as group chats and crafted to resemble legitimate Microsoft Office URLs. The documents used OOXML external template injection, with domains visually close to openxmlformats.org, ms-office services, or Office template sites, to download remote macro templates. The filenames and themes targeted South Korean foreign-policy and security experts with topics such as China, North Korea, and diplomatic issues. The report emphasizes that attackers increasingly use lookalike Office infrastructure and document-theme personalization to make malicious template injection harder to identify.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://schemas.openxmlformats.o… | 2020-03-20 | 2023-06-06 |
| DOMAIN | ms-offices.com | 2022-11-17 | 2022-12-07 |
| HASH | d698fccf14f670595442155395f42642 | 2022-11-17 | 2022-11-25 |
| URL | https://ms-office.services/temp… | 2022-11-17 | 2022-11-25 |
| URL | https://ms-office.services/temp… | 2022-11-17 | 2022-11-25 |
| URL | https://ms-offices.com/template… | 2022-11-17 | 2022-11-25 |
| URL | http://schemas.openxmlformat.or… | 2022-11-17 | 2022-11-25 |
| URL | http://schemas.openxmlformat.or… | 2022-11-17 | 2022-11-25 |
| URL | http://offices.word-template.net | 2022-11-17 | 2022-11-25 |
| URL | https://ms-office.services/temp… | 2022-11-17 | 2022-11-25 |
| URL | http://offices.word-template.ne… | 2022-11-17 | 2022-11-25 |
| URL | https://ms-offices.com | 2022-11-17 | 2022-11-25 |
| URL | https://ms-offices.com/template… | 2022-11-17 | 2022-11-25 |
| URL | http://schemas.openxmlformat.org | 2022-11-17 | 2022-11-25 |
| URL | https://ms-office.services | 2022-11-17 | 2022-11-25 |
| URL | https://ms-office.services/temp… | 2022-11-17 | 2022-11-25 |
| URL | https://ms-offices.com/template… | 2022-11-17 | 2022-11-25 |
| DOMAIN | offices.word-template.net | 2022-11-17 | 2022-11-25 |
| DOMAIN | ms-office.services | 2022-11-17 | 2022-11-25 |