Detecting Embedded Content in OOXML Documents

2022-08-18 • Mandiant •

https://www.mandiant.com/resources/detecting-embedded-content-in-ooxml-documents

Thumbnail for Detecting Embedded Content in OOXML Documents

Mandiant describes a method for clustering malicious Office Open XML documents by ZIP local-file-header metadata such as CRC-32 values, uncompressed sizes, and embedded file names. The DPRK-relevant example uses a YARA rule to detect OOXML documents carrying a specific PNG image found in files that drop LATEOP and are attributed to groups including UNC1130, which Mandiant identifies as a North Korean state-sponsored actor. The technique is presented as a repeatable way for analysts to find related documents that reuse the same embedded content over time, while other examples in the article cover non-DPRK activity such as FIN7.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 41ce5bfa64b36af0c381e6353c67af6… 2022-08-18 2022-08-18
HASH de02527bf775ce9fe645f6a8c177e24… 2022-08-18 2022-08-18
HASH dc9f5060139b647b7f77123e9b91d6e… 2022-08-18 2022-08-18
HASH f8eb23b9ae7537934cf709f63b5056e… 2022-08-18 2022-08-18

Related Actors

« Back