PerSwaysion | office 365´¹ÂÚ¹¥»÷ÊÂÎñͨ¸æ
Ðû²¼Ê±¼ä 2020-05-010x00 ÊÂÎñ¸ÅÊö
¿ËÈÕ£¬£¬£¬£¬ÐÂ¼ÓÆÂÍøÂçÇå¾²¹«Ë¾IB¼¯ÍÅ·¢Ã÷ÁËÒ»¸öеÄÍøÂç´¹Âڻ£¬£¬£¬£¬ÃûΪPerSwaysion£¬£¬£¬£¬´Ë´Î¹¥»÷»î¶¯Ê¹ÓÃMicrosoftµÄÎļþ¹²ÏíЧÀÍ£¬£¬£¬£¬ÒѾÀֳɶÔÈ«Çò¶à¼Ò¹«Ë¾µÄ150¶àλÖÎÀí²ãÔ±¹¤ÌᳫÁËÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬Ö÷񻃾¼°µÄÊǽðÈÚ¡¢Ö´·¨ºÍ·¿µØ²úÁìÓòµÄÆóÒµ¡£¡£¡£
0x01 ÊÂÎñÏêÇé
´Ë´Î¹¥»÷ÊÇÓÉÔ½ÄϵĺڿÍ×éÖ¯ÌᳫµÄ£¬£¬£¬£¬´Ó2019ÄêÄêÖÐ×îÏȾÙÐУ¬£¬£¬£¬ÒòʹÓÃÁËMicrosoft Sway¶ø±»³ÆÎªPerSwaysion¡£¡£¡£¸ÃºÚ¿Í×éÖ¯Ê×ÏÈÏòÊܺ¦Õß·¢ËÍÒ»·â´¹ÂÚÓʼþ£¬£¬£¬£¬¸ÃÓʼþÖвåÈëÁËαÔìµÄOffice 365Îļþ¹²ÏíµÄ֪ͨ£¬£¬£¬£¬ÒÔÔöÌíÆäÕæÊµÐÔ£¬£¬£¬£¬»¹°üÀ¨Ò»¸ö¡°Á¬Ã¦ÔĶÁ¡±µÄÁ´½Ó¡£¡£¡£µ±Êܺ¦Õßµã»÷Á´½Óºó£¬£¬£¬£¬Êܺ¦Õß±ã±»ÖØ¶¨Ïòµ½ÁËÍйÜÔÚMicrosoft Swayƽ̨ÉϵÄÎļþ¡£¡£¡£¸ÃÒ³Ãæ»á¸æËßÊܺ¦Õß·¢¼þÈËÒѾ´ú±í¹«Ë¾¹²ÏíÁËÒ»¸öÎĵµ£¬£¬£¬£¬²¢ÒªÇóÆäµã»÷Á´½ÓÔĶÁ¡£¡£¡£Ö®ºó£¬£¬£¬£¬¸ÃÁ´½Ó½«Êܺ¦ÕßÖØ¶¨Ïòµ½×îºóµÄÍøÂç´¹ÂÚµÇÂ¼Ò³Ãæ£¬£¬£¬£¬¸ÃÒ³Ãæ¿´ÆðÀ´ÊÇOutlookµÄMicrosoft¼òµ¥µÇ¼£¨SSO£©Ò³Ã棬£¬£¬£¬²¢ÒªÇóÊܺ¦ÕßÊäÈëÆäƾ֤£¬£¬£¬£¬ÒÔʵÑé͵ÇÔ¡£¡£¡£ºÚ¿ÍÒ»µ©ÍµÇÔÀֳɣ¬£¬£¬£¬±ã»áʹÓÃIMAP API´ÓЧÀÍÆ÷ÏÂÔØÊܺ¦Õߵĵç×ÓÓʼþÖеÄÊý¾Ý£¬£¬£¬£¬È»ºóð³äÆäÉí·ÝÓëÆäËûÈËͨѶ¡£¡£¡£×îºó£¬£¬£¬£¬ËüÃÇ»¹»áʹÓÃÊܺ¦ÕßµÄÐÕÃû¡¢µç×ÓÓʼþµØµãºÍ¹«Ë¾Ãû³ÆÀ´ÌìÉúеĴ¹ÂÚÓʼþ£¬£¬£¬£¬¶ÔÏÂÒ»¸öÊܺ¦ÕßÌᳫ¹¥»÷¡£¡£¡£²¢ÇÒ£¬£¬£¬£¬¸ÃÍŻﻹ»áÔÚ¹¥»÷¿¢Êºó´ÓÊܺ¦Õߵķ¢¼þÏäÖÐɾ³ýαÔìµÄ´¹ÂÚÓʼþ£¬£¬£¬£¬ÒÔÃâÒýÆðÏÓÒÉ¡£¡£¡£
ÏÖÔÚ£¬£¬£¬£¬¸ÃÊÂÎñÒѾÀֳɵع¥»÷Á˵¹ú¡¢Ó¢¹ú¡¢ºÉÀ¼¡¢Ïã¸ÛºÍÐÂ¼ÓÆÂµÄ¶à¼Ò¹«Ë¾µÄÖÁÉÙ156λ¸ß¼¶¹ÙÔ±µÄ¹«Ë¾µç×ÓÓʼþÕÊ»§£¬£¬£¬£¬Ö÷ÒªÕë¶ÔµÄÊǽðÈÚЧÀ͹«Ë¾£¨Ô¼50£¥£©£¬£¬£¬£¬×´Ê¦ÊÂÎñËùºÍ·¿µØ²ú¹«Ë¾¡£¡£¡£
Group-IB½¨ÉèÁËÒ»¸öÔÚÏßÍøÒ³£¬£¬£¬£¬Óû§¿ÉÒÔͨ¹ý¸ÃÍøÒ³¼ì²éÆäµç×ÓÓʼþµØµãÊÇ·ñΪPerSwaysion¹¥»÷Ò»²¿·Ö¡£¡£¡£
Group-IBDFIRÍŶӱ»Ô¼Çë¼ì²éÒ»¼ÒÑÇÖÞ¹«Ë¾µÄÊÂÎñ£¬£¬£¬£¬¸Ã¹«Ë¾È·¶¨PerSwaysionÊÇÖØ´óµÄÈýÏàÍøÂç´¹ÂÚ²Ù×÷£¬£¬£¬£¬ËüʹÓÃÌØÊâµÄÕ½ÂÔºÍÊÖÒÕÀ´×èÖ¹±»·¢Ã÷¡£¡£¡£Íþв¼ÓÈëÕßͨ¹ý¡°Ëµ·þ¡±µ£µ±Ö÷Òª¹«Ë¾Ö°Î»µÄÖ°Ô±·¿ªÀ´×ÔÆäÁªÏµÈËÕæÊµµØµãµÄ·Ç¶ñÒâPDFµç×ÓÓʼþ¸½¼þ£¬£¬£¬£¬´Ó¶ø³ä·ÖʹÓÃÁËÈ«ÐÄÉè¼ÆµÄÉç»á¹¤³ÌÊÖÒÕ¡£¡£¡£
PDF¸½¼þÊǶÔOffice 365Îļþ¹²ÏíµÄÈ«ÐÄÉè¼ÆµÄ֪ͨ£¬£¬£¬£¬Ä£ÄâÁËÕýµ±ÃûÌõÄÊܺ¦Õß¡£¡£¡£µ¥»÷¡°Á¬Ã¦ÔĶÁ¡±ºó£¬£¬£¬£¬ÔÚÕâÖÖÇéÐÎÏ£¬£¬£¬£¬Êܺ¦Õߣ¨´ó´ó¶¼ÇéÐÎÏÂÊǸ߼¶¹ÙÔ±£©±»´øµ½MS SwayÉÏÍйܵÄÎļþÖС£¡£¡£¹¥»÷ÕßÑ¡ÔñÕýµ±µÄ»ùÓÚÔÆµÄÄÚÈݹ²ÏíЧÀÍ£¬£¬£¬£¬ÀýÈçMicrosoft Sway£¬£¬£¬£¬Microsoft SharePointºÍOneNote£¬£¬£¬£¬ÒÔ×èÖ¹Á÷Á¿¼ì²â¡£¡£¡£¸ÃÒ³ÃæÀàËÆÓÚÕæÊµµÄMicrosoft Office 365Îļþ¹²ÏíÒ³Ãæ¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬ÕâÊÇÒ»¸öÌØÖÆµÄÑÝʾÎĸåÒ³Ãæ£¬£¬£¬£¬ËüÀÄÓÃÁËSwayĬÈϵÄÎÞ½çÏßÊÓͼ¡£¡£¡£
ÒÔºóÒ³Ãæ½«Ä¿µÄСÎÒ˽¼ÒÖØ¶¨Ïòµ½×îÖÕÄ¿µÄ£¬£¬£¬£¬¼´ÏÖʵµÄÍøÂç´¹ÂÚÕ¾µã£¬£¬£¬£¬ÆäαװΪMicrosoft Single Sign-OnÒ³ÃæµÄ2017Äê°æ±¾¡£¡£¡£´Ë´¦£¬£¬£¬£¬ÍøÂç´¹ÂÚ¹¤¾ßΪÊܺ¦Õß·ÖÅÉÁËΨһµÄÐòÁкţ¬£¬£¬£¬¸ÃÐòÁкÅÊÇ»ù±¾µÄÖ¸ÎÆÊ¶±ðÊÖÒÕ¡£¡£¡£Öظ´ÇëÇóÍêÈ«ÏàͬµÄURL½«±»¾Ü¾ø¡£¡£¡£Ëü×èÖ¹¶ÔÄ¿µÄ»á¼ûµÄURLµÄÈκÎ×Ô¶¯Íþв¼ì²âÊÂÇé¡£¡£¡£µ±¸ß¼¶Ô±¹¤Ìá½»¹«Ë¾Office 365ƾ֤ʱ£¬£¬£¬£¬¸ÃÐÅÏ¢½«Í¨¹ýÒþ²ØÔÚÒ³ÃæÉϵÄÌØÊâµç×ÓÓʼþµØµã·¢Ë͵½µ¥¶ÀµÄÊý¾ÝЧÀÍÆ÷¡£¡£¡£Õâ·â¶àÓàµÄµç×ÓÓʼþÓÃ×÷ʵʱ֪ͨҪÁ죬£¬£¬£¬ÒÔÈ·±£¹¥»÷Õß¶ÔнüÊÕ»ñµÄƾ֤×ö³ö·´Ó¦¡£¡£¡£
0x02 ²Î¿¼Á´½Ó
https://securityaffairs.co/wordpress/102539/hacking/perswaysion-sophisticated-phishing-campaign.html
https://threatpost.com/microsoft-sway-abused-office-365-phishing-attack/155366/
https://thehackernews.com/2020/04/targeted-phishing-attacks-successfully.html
0x03 ʱ¼äÏß
2020-05-01 VSRCÐû²¼ÊÂÎñͨ¸æ


¾©¹«Íø°²±¸11010802024551ºÅ