Skip to content

Latest commit

 

History

History
57 lines (30 loc) · 3.23 KB

T1221.md

File metadata and controls

57 lines (30 loc) · 3.23 KB

T1221 - Template Injection

Adversaries may create or modify references in Office document templates to conceal malicious code or force authentication attempts. Microsoft’s Office Open XML (OOXML) specification defines an XML-based format for Office documents (.docx, xlsx, .pptx) to replace older binary formats (.doc, .xls, .ppt). OOXML files are packed together ZIP archives compromised of various XML files, referred to as parts, containing properties that collectively define how a document is rendered. (Citation: Microsoft Open XML July 2017)

Properties within parts may reference shared public resources accessed via online URLs. For example, template properties reference a file, serving as a pre-formatted document blueprint, that is fetched when the document is loaded.

Adversaries may abuse this technology to initially conceal malicious code to be executed via documents. Template references injected into a document may enable malicious payloads to be fetched and executed when the document is loaded. (Citation: SANS Brian Wiltse Template Injection) These documents can be delivered via other techniques such as Phishing and/or Taint Shared Content and may evade static detections since no typical indicators (VBA macro, script, etc.) are present until after the malicious payload is fetched. (Citation: Redxorblue Remote Template Injection) Examples have been seen in the wild where template injection was used to load malicious code containing an exploit. (Citation: MalwareBytes Template Injection OCT 2017)

This technique may also enable Forced Authentication by injecting a SMB/HTTPS (or other credential prompting) URL and triggering an authentication attempt. (Citation: Anomali Template Injection MAR 2018) (Citation: Talos Template Injection July 2017) (Citation: ryhanson phishery SEPT 2016)

Atomic Tests


Atomic Test #1 - WINWORD Remote Template Injection

Open a .docx file that loads a remote .dotm macro enabled template. Executes the code specified within the .dotm template.Requires download of WINWORD found in Microsoft Ofiice at Microsoft: https://www.microsoft.com/en-us/download/office.aspx. Opens Calculator.exe when test sucessfully executed, while AV turned off.

Supported Platforms: Windows

Inputs:

Name Description Type Default Value
docx file Location of the test docx file on the local filesystem. Path PathToAtomicsFolder\T1221\src\Calculator.docx
dotm template Location of the test dotm template on the remote server. Path https://github.com/redcanaryco/atomic-red-team/tree/master/atomics/T1221/src/opencalc.dotm

Attack Commands: Run with command_prompt!

start PathToAtomicsFolder\T1221\src\Calculator.docx

Dependencies: Run with powershell!

Description:
Check Prereq Commands:
 
Get Prereq Commands: