Word Documents Disguised as Normal MS Office URLs Being Distributed
2022-11-25 • Ahnlab •
ASEC observed malicious OOXML Word documents distributed through channels such as KakaoTalk group chats, with filenames themed around North Korea, China, surveys, and diplomatic security specialists. The documents used template injection to fetch external content from domains carefully disguised as legitimate Microsoft Office or OpenXML infrastructure. Reported infrastructure included lookalike domains such as openxmlformat[.]org, ms-office[.]services, ms-offices[.]com, and offices.word-template[.]net. AhnLab detections included Downloader/DOC.External, Downloader/DOC.Kimsuky, and Downloader/XML.Generic, supporting DPRK-focused tracking of document-based phishing against Korean policy and security communities.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://schemas.openxmlformats.o… | 2020-03-20 | 2023-06-06 |
| DOMAIN | ms-offices.com | 2022-11-17 | 2022-12-07 |
| HASH | d698fccf14f670595442155395f42642 | 2022-11-17 | 2022-11-25 |
| URL | https://ms-office.services/temp… | 2022-11-17 | 2022-11-25 |
| URL | https://ms-office.services/temp… | 2022-11-17 | 2022-11-25 |
| URL | https://ms-offices.com/template… | 2022-11-17 | 2022-11-25 |
| URL | http://schemas.openxmlformat.or… | 2022-11-17 | 2022-11-25 |
| URL | http://schemas.openxmlformat.or… | 2022-11-17 | 2022-11-25 |
| URL | http://offices.word-template.net | 2022-11-17 | 2022-11-25 |
| URL | https://ms-office.services/temp… | 2022-11-17 | 2022-11-25 |
| URL | http://offices.word-template.ne… | 2022-11-17 | 2022-11-25 |
| URL | https://ms-offices.com | 2022-11-17 | 2022-11-25 |
| URL | https://ms-offices.com/template… | 2022-11-17 | 2022-11-25 |
| URL | http://schemas.openxmlformat.org | 2022-11-17 | 2022-11-25 |
| URL | https://ms-office.services | 2022-11-17 | 2022-11-25 |
| URL | https://ms-office.services/temp… | 2022-11-17 | 2022-11-25 |
| URL | https://ms-offices.com/template… | 2022-11-17 | 2022-11-25 |
| DOMAIN | offices.word-template.net | 2022-11-17 | 2022-11-25 |
| DOMAIN | ms-office.services | 2022-11-17 | 2022-11-25 |