Word Documents Disguised as Normal MS Office URLs Being Distributed

2022-11-25 Ahnlab

https://asec.ahnlab.com/en/42554/

Thumbnail for Word Documents Disguised as Normal MS Office URLs Being Distributed

ASEC observed malicious OOXML Word documents distributed through channels such as KakaoTalk group chats, with filenames themed around North Korea, China, surveys, and diplomatic security specialists. The documents used template injection to fetch external content from domains carefully disguised as legitimate Microsoft Office or OpenXML infrastructure. Reported infrastructure included lookalike domains such as openxmlformat[.]org, ms-office[.]services, ms-offices[.]com, and offices.word-template[.]net. AhnLab detections included Downloader/DOC.External, Downloader/DOC.Kimsuky, and Downloader/XML.Generic, supporting DPRK-focused tracking of document-based phishing against Korean policy and security communities.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://schemas.openxmlformats.o… 2020-03-20 2023-06-06
DOMAIN ms-offices.com 2022-11-17 2022-12-07
HASH d698fccf14f670595442155395f42642 2022-11-17 2022-11-25
URL https://ms-office.services/temp… 2022-11-17 2022-11-25
URL https://ms-office.services/temp… 2022-11-17 2022-11-25
URL https://ms-offices.com/template… 2022-11-17 2022-11-25
URL http://schemas.openxmlformat.or… 2022-11-17 2022-11-25
URL http://schemas.openxmlformat.or… 2022-11-17 2022-11-25
URL http://offices.word-template.net 2022-11-17 2022-11-25
URL https://ms-office.services/temp… 2022-11-17 2022-11-25
URL http://offices.word-template.ne… 2022-11-17 2022-11-25
URL https://ms-offices.com 2022-11-17 2022-11-25
URL https://ms-offices.com/template… 2022-11-17 2022-11-25
URL http://schemas.openxmlformat.org 2022-11-17 2022-11-25
URL https://ms-office.services 2022-11-17 2022-11-25
URL https://ms-office.services/temp… 2022-11-17 2022-11-25
URL https://ms-offices.com/template… 2022-11-17 2022-11-25
DOMAIN offices.word-template.net 2022-11-17 2022-11-25
DOMAIN ms-office.services 2022-11-17 2022-11-25

Related Actors

Related Reports

« Back