PerSwaysion | office 365´¹µö¹¥»÷ÊÂÎñ¹«¸æ

°ä²¼¹¦·ò 2020-05-01

0x00 ÊÂÎñ¸ÅÊö


½üÈÕ £¬ÐÂ¼ÓÆÂÍøÂ簲ȫ¹«Ë¾IB¼¯ÍÅ·¢ÏÖÁËÒ»¸öеÄÍøÂç´¹µö»î¶¯ £¬ÃûΪPerSwaysion £¬Õâ´Î¹¥»÷»î¶¯ÀûÓÃMicrosoftµÄÎļþ¹²Ïí·þÎñ £¬ÒѾ­³É¹¦¶ÔÈ«Çò¶à¼Ò¹«Ë¾µÄ150¶àλÖÎÀí²ãÔ±¹¤ÌáÒéÁËÍøÂç´¹µö¹¥»÷ £¬ÖØÒªÉæ¼°µÄÊǽðÈÚ¡¢Ë¾·¨ºÍ·¿µØ²úÁìÓòµÄÆóÒµ¡£


0x01 ÊÂÎñÏêÇé


Õâ´Î¹¥»÷ÊÇÓÉÔ½ÄϵĺڿÍ×éÖ¯ÌáÒéµÄ £¬´Ó2019ÄêÄêÖÐÆðÍ·½øÐÐ £¬ÒòÀûÓÃÁËMicrosoft Sway¶ø±»³ÆÎªPerSwaysion¡£¸ÃºÚ¿Í×éÖ¯Ê×ÏÈÏòÊܺ¦Õß·¢ËÍÒ»·â´¹µöÓʼþ £¬¸ÃÓʼþÖвåÈëÁËαÔìµÄOffice 365Îļþ¹²ÏíµÄ֪ͨ £¬ÒÔÔö³¤ÆäÕæÊµÐÔ £¬»¹Ô̺¬Ò»¸ö¡°µ±¼´ÔĶÁ¡±µÄÁ´½Ó¡£µ±Êܺ¦Õßµã»÷Á´½Óºó £¬Êܺ¦Õ߱㱻³Á¶¨Ïòµ½ÁËÍйÜÔÚMicrosoft Swayƽ̨ÉϵÄÎļþ¡£¸ÃÒ³Ãæ»á֪ͨÊܺ¦Õß·¢¼þÈËÒѾ­´ú±í¹«Ë¾¹²ÏíÁËÒ»¸öÎĵµ £¬²¢ÒªÇóÆäµã»÷Á´½ÓÔĶÁ¡£Ö®ºó £¬¸ÃÁ´½Ó½«Êܺ¦Õß³Á¶¨Ïòµ½×îºóµÄÍøÂç´¹µöµÇÂ¼Ò³Ãæ £¬¸ÃÒ³Ãæ¿´ÆðÀ´ÊÇOutlookµÄMicrosoftµ¥Ò»µÇ¼£¨SSO£©Ò³Ãæ £¬²¢ÒªÇóÊܺ¦ÕßÊäÈëÆäƾ֤ £¬ÒÔÖ´ÐÐ͵ÇÔ¡£ºÚ¿ÍÒ»µ©ÍµÇԳɹ¦ £¬±ã»áʹÓÃIMAP API´Ó·þÎñÆ÷ÏÂÔØÊܺ¦Õߵĵç×ÓÓʼþÖеÄÊý¾Ý £¬¶øºó¼ÙÒâÆäÉí·ÝÓëÆäËûÈËͨѶ¡£×îºó £¬ËüÃÇ»¹»áʹÓÃÊܺ¦ÕßµÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·ºÍ¹«Ë¾Ãû³ÆÀ´ÌìÉúеĴ¹µöÓʼþ £¬¶ÔÏÂÒ»¸öÊܺ¦ÕßÌáÒé¹¥»÷¡£²¢ÇÒ £¬¸ÃÍŻﻹ»áÔÚ¹¥»÷ʵÏÖºó´ÓÊܺ¦Õߵķ¢¼þÏäÖÐɾ³ýαÔìµÄ´¹µöÓʼþ £¬ÒÔÃâÒýÆðÒÉ»ó¡£


Ŀǰ £¬¸ÃÊÂÎñÒѾ­³É¹¦µØ¹¥»÷Á˵¹ú¡¢Ó¢¹ú¡¢ºÉÀ¼¡¢Ïã¸ÛºÍÐÂ¼ÓÆÂµÄ¶à¼Ò¹«Ë¾µÄÖÁÉÙ156λ¸ß¼¶¹ÙÔ±µÄ¹«Ë¾µç×ÓÓʼþÕÊ»§ £¬ÖØÒªÕë¶ÔµÄÊǽðÈÚ·þÎñ¹«Ë¾£¨Ô¼50£¥£© £¬ÂÉʦÊÂÎñËùºÍ·¿µØ²ú¹«Ë¾¡£


Group-IB³ÉÁ¢ÁËÒ»¸öÔÚÏßÍøÒ³ £¬Óû§Äܹ»Í¨¹ý¸ÃÍøÒ³²é³­Æäµç×ÓÓʼþµØÖ·ÊÇ·ñΪPerSwaysion¹¥»÷Ò»²¿ÃÅ¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Group-IBDFIRÍŶӱ»Ô¼Çë²é³­Ò»¼ÒÑÇÖÞ¹«Ë¾µÄÊÂÎñ £¬¸Ã¹«Ë¾È·¶¨PerSwaysionÊǸ´ÔÓµÄÈýÏàÍøÂç´¹µö²Ù×÷ £¬ËüʹÓÃÌØÊâµÄÕ½ÊõºÍ¼¼ÊõÀ´Ô¤·À±»·¢ÏÖ¡£Íþв²Î¼ÓÕßͨ¹ý¡°Ëµ·þ¡±µ£ÈγÁÒª¹«Ë¾Ö°Î»µÄÈËÔ±´ò¿ªÀ´×ÔÆäÁªÏµÈËÕæÊµµØÖ·µÄ·Ç¶ñÒâPDFµç×ÓÓʼþ¸½¼þ £¬´Ó¶ø³ä·ÖÀûÓÃÁ˾«ÐÄÉè¼ÆµÄÉç»á¹¤³Ì¼¼Êõ¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


PDF¸½¼þÊǶÔOffice 365Îļþ¹²ÏíµÄ¾«ÐÄÉè¼ÆµÄ֪ͨ £¬·ÂÕÕÁ˺Ϸ¨ÌåʽµÄÊܺ¦Õß¡£µ¥»÷¡°µ±¼´ÔĶÁ¡±ºó £¬ÔÚÕâÖÖÇé¿öÏ £¬Êܺ¦Õߣ¨´óÎÞÊýÇé¿öÏÂÊǸ߼¶¹ÙÔ±£©±»´øµ½MS SwayÉÏÍйܵÄÎļþÖС£¹¥»÷ÕßÑ¡ÔñºÏ·¨µÄ»ùÓÚÔÆµÄÄÚÈݹ²Ïí·þÎñ £¬ÀýÈçMicrosoft Sway £¬Microsoft SharePointºÍOneNote £¬ÒÔÔ¤·ÀÁ÷Á¿¼ì²â¡£¸ÃÒ³ÃæÀàËÆÓÚÕæÊµµÄMicrosoft Office 365Îļþ¹²ÏíÒ³Ãæ¡£µ«ÊÇ £¬ÕâÊÇÒ»¸öÌØÔìµÄÑÝʾÎĸåÒ³Ãæ £¬ËüÀÄÓÃÁËSwayĬÈϵÄÎ޼ʽçÊÓͼ¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


´Ó´ËÒ³Ãæ½«Ö¸±êÓ×ÎÒ³Á¶¨Ïòµ½×îÖÕÖ¸±ê £¬¼´ÏÖʵµÄÍøÂç´¹µöÕ¾µã £¬Æä¼ÙװΪMicrosoft Single Sign-OnÒ³ÃæµÄ2017Äê°æ±¾¡£´Ë´¦ £¬ÍøÂç´¹µö¹¤¾ßΪÊܺ¦Õß·ÖÅäÁËΨһµÄÐòÁкÅ £¬¸ÃÐòÁкÅÊǸù»ùµÄÖ¸ÎÆ¼ø±ð¼¼Êõ¡£³Á¸´ÒªÇóÆëȫһÑùµÄURL½«±»»Ø¾ø¡£ËüÖÕ³¡¶ÔÖ¸±ê½Ó¼ûµÄURLµÄÈκÎ×Ô¶¯Íþв¼ì²â¹¤×÷¡£µ±¸ß¼¶Ô±¹¤Ìá½»¹«Ë¾Office 365Í´´¦Ê± £¬¸ÃÐÅÏ¢½«Í¨¹ý°µ²ØÔÚÒ³ÃæÉϵĶî±íµç×ÓÓʼþµØÖ··¢Ë͵½µ¥¶ÀµÄÊý¾Ý·þÎñÆ÷¡£Õâ·âÓÐÓàµÄµç×ÓÓʼþÓÃ×÷ʵʱ֪ͨ²½Öè £¬ÒÔÈ·±£¹¥»÷Õß¶ÔнüÊճɵį¾Ö¤×ö³ö·´Ó³¡£


0x02 ²Î¿¼Á´½Ó


https://securityaffairs.co/wordpress/102539/hacking/perswaysion-sophisticated-phishing-campaign.html

https://threatpost.com/microsoft-sway-abused-office-365-phishing-attack/155366/

https://thehackernews.com/2020/04/targeted-phishing-attacks-successfully.html


0x03 ¹¦·òÏß


2020-05-01  VSRC°ä²¼ÊÂÎñ¹«¸æ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾