Detecting Embedded Content in OOXML Documents
2022-08-18 • Mandiant •
https://www.mandiant.com/resources/detecting-embedded-content-in-ooxml-documents
Mandiant describes a method for clustering malicious Office Open XML documents by ZIP local-file-header metadata such as CRC-32 values, uncompressed sizes, and embedded file names. The DPRK-relevant example uses a YARA rule to detect OOXML documents carrying a specific PNG image found in files that drop LATEOP and are attributed to groups including UNC1130, which Mandiant identifies as a North Korean state-sponsored actor. The technique is presented as a repeatable way for analysts to find related documents that reuse the same embedded content over time, while other examples in the article cover non-DPRK activity such as FIN7.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 41ce5bfa64b36af0c381e6353c67af6… | 2022-08-18 | 2022-08-18 |
| HASH | de02527bf775ce9fe645f6a8c177e24… | 2022-08-18 | 2022-08-18 |
| HASH | dc9f5060139b647b7f77123e9b91d6e… | 2022-08-18 | 2022-08-18 |
| HASH | f8eb23b9ae7537934cf709f63b5056e… | 2022-08-18 | 2022-08-18 |