PerSwaysion | office 365´¹µö¹¥»÷ÊÂÎñ¹«¸æ

°ä²¼¹¦·ò 2020-05-01

0x00 ÊÂÎñ¸ÅÊö


½üÈÕ£¬ÐÂ¼ÓÆÂÍøÂ簲ȫ¹«Ë¾IB¼¯ÍÅ·¢ÏÖÁËÒ»¸öеÄÍøÂç´¹µö»î¶¯£¬ÃûΪPerSwaysion£¬Õâ´Î¹¥»÷»î¶¯ÀûÓÃMicrosoftµÄÎļþ¹²Ïí·þÎñ£¬ÒѾ­³É¹¦¶ÔÈ«Çò¶à¼Ò¹«Ë¾µÄ150¶àλÖÎÀí²ãÔ±¹¤ÌáÒéÁËÍøÂç´¹µö¹¥»÷£¬ÖØÒªÉæ¼°µÄÊǽðÈÚ¡¢Ë¾·¨ºÍ·¿µØ²úÁìÓòµÄÆóÒµ¡£


0x01 ÊÂÎñÏêÇé


Õâ´Î¹¥»÷ÊÇÓÉÔ½ÄϵĺڿÍ×éÖ¯ÌáÒéµÄ£¬´Ó2019ÄêÄêÖÐÆðÍ·½øÐУ¬ÒòÀûÓÃÁËMicrosoft Sway¶ø±»³ÆÎªPerSwaysion¡£¸ÃºÚ¿Í×éÖ¯Ê×ÏÈÏòÊܺ¦Õß·¢ËÍÒ»·â´¹µöÓʼþ£¬¸ÃÓʼþÖвåÈëÁËαÔìµÄOffice 365Îļþ¹²ÏíµÄ֪ͨ£¬ÒÔÔö³¤ÆäÕæÊµÐÔ£¬»¹Ô̺¬Ò»¸ö¡°Á¢¼´ÔĶÁ¡±µÄÁ´½Ó¡£µ±Êܺ¦Õßµã»÷Á´½Óºó£¬Êܺ¦Õ߱㱻³Á¶¨Ïòµ½ÁËÍйÜÔÚMicrosoft Swayƽ̨ÉϵÄÎļþ¡£¸ÃÒ³Ãæ»á֪ͨÊܺ¦Õß·¢¼þÈËÒѾ­´ú±í¹«Ë¾¹²ÏíÁËÒ»¸öÎĵµ£¬²¢ÒªÇóÆäµã»÷Á´½ÓÔĶÁ¡£Ö®ºó£¬¸ÃÁ´½Ó½«Êܺ¦Õß³Á¶¨Ïòµ½×îºóµÄÍøÂç´¹µöµÇÂ¼Ò³Ãæ£¬¸ÃÒ³Ãæ¿´ÆðÀ´ÊÇOutlookµÄMicrosoftµ¥Ò»µÇ¼£¨SSO£©Ò³Ã棬²¢ÒªÇóÊܺ¦ÕßÊäÈëÆäƾ֤£¬ÒÔÖ´ÐÐ͵ÇÔ¡£ºÚ¿ÍÒ»µ©ÍµÇԳɹ¦£¬±ã»áʹÓÃIMAP API´Ó·þÎñÆ÷ÏÂÔØÊܺ¦Õߵĵç×ÓÓʼþÖеÄÊý¾Ý£¬¶øºó¼ÙÒâÆäÉí·ÝÓëÆäËûÈËͨѶ¡£×îºó£¬ËüÃÇ»¹»áʹÓÃÊܺ¦ÕßµÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·ºÍ¹«Ë¾Ãû³ÆÀ´ÌìÉúеĴ¹µöÓʼþ£¬¶ÔÏÂÒ»¸öÊܺ¦ÕßÌáÒé¹¥»÷¡£²¢ÇÒ£¬¸ÃÍŻﻹ»áÔÚ¹¥»÷ʵÏÖºó´ÓÊܺ¦Õߵķ¢¼þÏäÖÐɾ³ýαÔìµÄ´¹µöÓʼþ£¬ÒÔÃâÒýÆðÒÉ»ó¡£


Ŀǰ£¬¸ÃÊÂÎñÒѾ­³É¹¦µØ¹¥»÷Á˵¹ú¡¢Ó¢¹ú¡¢ºÉÀ¼¡¢Ïã¸ÛºÍÐÂ¼ÓÆÂµÄ¶à¼Ò¹«Ë¾µÄÖÁÉÙ156λ¸ß¼¶¹ÙÔ±µÄ¹«Ë¾µç×ÓÓʼþÕÊ»§£¬ÖØÒªÕë¶ÔµÄÊǽðÈÚ·þÎñ¹«Ë¾£¨Ô¼50£¥£©£¬ÂÉʦÊÂÎñËùºÍ·¿µØ²ú¹«Ë¾¡£


Group-IB³ÉÁ¢ÁËÒ»¸öÔÚÏßÍøÒ³£¬Óû§Äܹ»Í¨¹ý¸ÃÍøÒ³²é³­Æäµç×ÓÓʼþµØÖ·ÊÇ·ñΪPerSwaysion¹¥»÷Ò»²¿ÃÅ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Group-IBDFIRÍŶӱ»Ô¼Çë²é³­Ò»¼ÒÑÇÖÞ¹«Ë¾µÄÊÂÎñ£¬¸Ã¹«Ë¾È·¶¨PerSwaysionÊǸ´ÔÓµÄÈýÏàÍøÂç´¹µö²Ù×÷£¬ËüʹÓÃÌØÊâµÄÕ½ÊõºÍ¼¼ÊõÀ´Ô¤·À±»·¢ÏÖ¡£Íþв²Î¼ÓÕßͨ¹ý¡°Ëµ·þ¡±µ£ÈγÁÒª¹«Ë¾Ö°Î»µÄÈËÔ±´ò¿ªÀ´×ÔÆäÁªÏµÈËÕæÊµµØÖ·µÄ·Ç¶ñÒâPDFµç×ÓÓʼþ¸½¼þ£¬´Ó¶ø³ä·ÖÀûÓÃÁ˾«ÐÄÉè¼ÆµÄÉç»á¹¤³Ì¼¼Êõ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


PDF¸½¼þÊǶÔOffice 365Îļþ¹²ÏíµÄ¾«ÐÄÉè¼ÆµÄ֪ͨ£¬·ÂÕÕÁ˺Ϸ¨ÌåʽµÄÊܺ¦Õß¡£µ¥»÷¡°Á¢¼´ÔĶÁ¡±ºó£¬ÔÚÕâÖÖÇé¿öÏ£¬Êܺ¦Õߣ¨´óÎÞÊýÇé¿öÏÂÊǸ߼¶¹ÙÔ±£©±»´øµ½MS SwayÉÏÍйܵÄÎļþÖС£¹¥»÷ÕßÑ¡ÔñºÏ·¨µÄ»ùÓÚÔÆµÄÄÚÈݹ²Ïí·þÎñ£¬ÀýÈçMicrosoft Sway£¬Microsoft SharePointºÍOneNote£¬ÒÔÔ¤·ÀÁ÷Á¿¼ì²â¡£¸ÃÒ³ÃæÀàËÆÓÚÕæÊµµÄMicrosoft Office 365Îļþ¹²ÏíÒ³Ãæ¡£µ«ÊÇ£¬ÕâÊÇÒ»¸öÌØÔìµÄÑÝʾÎĸåÒ³Ãæ£¬ËüÀÄÓÃÁËSwayĬÈϵÄÎ޼ʽçÊÓͼ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


´Ó´ËÒ³Ãæ½«Ö¸±êÓ×ÎÒ³Á¶¨Ïòµ½×îÖÕÖ¸±ê£¬¼´ÏÖʵµÄÍøÂç´¹µöÕ¾µã£¬Æä¼ÙװΪMicrosoft Single Sign-OnÒ³ÃæµÄ2017Äê°æ±¾¡£´Ë´¦£¬ÍøÂç´¹µö¹¤¾ßΪÊܺ¦Õß·ÖÅäÁËΨһµÄÐòÁкÅ£¬¸ÃÐòÁкÅÊǸù»ùµÄÖ¸ÎÆ¼ø±ð¼¼Êõ¡£³Á¸´ÒªÇóÆëȫһÑùµÄURL½«±»»Ø¾ø¡£ËüÖÕ³¡¶ÔÖ¸±ê½Ó¼ûµÄURLµÄÈκÎ×Ô¶¯Íþв¼ì²â¹¤×÷¡£µ±¸ß¼¶Ô±¹¤Ìá½»¹«Ë¾Office 365Í´´¦Ê±£¬¸ÃÐÅÏ¢½«Í¨¹ý°µ²ØÔÚÒ³ÃæÉϵĶî±íµç×ÓÓʼþµØÖ··¢Ë͵½µ¥¶ÀµÄÊý¾Ý·þÎñÆ÷¡£Õâ·âÓÐÓàµÄµç×ÓÓʼþÓÃ×÷ʵʱ֪ͨ²½Ö裬ÒÔÈ·±£¹¥»÷Õß¶ÔнüÊճɵį¾Ö¤×ö³ö·´Ó³¡£


0x02 ²Î¿¼Á´½Ó


https://securityaffairs.co/wordpress/102539/hacking/perswaysion-sophisticated-phishing-campaign.html

https://threatpost.com/microsoft-sway-abused-office-365-phishing-attack/155366/

https://thehackernews.com/2020/04/targeted-phishing-attacks-successfully.html


0x03 ¹¦·òÏß


2020-05-01  VSRC°ä²¼ÊÂÎñ¹«¸æ


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾