PerSwaysion | office 365´¹µö¹¥»÷ÊÂÎñ¹«¸æ
°ä²¼¹¦·ò 2020-05-010x00 ÊÂÎñ¸ÅÊö
½üÈÕ£¬ÐÂ¼ÓÆÂÍøÂ簲ȫ¹«Ë¾IB¼¯ÍÅ·¢ÏÖÁËÒ»¸öеÄÍøÂç´¹µö»î¶¯£¬ÃûΪPerSwaysion£¬Õâ´Î¹¥»÷»î¶¯ÀûÓÃMicrosoftµÄÎļþ¹²Ïí·þÎñ£¬ÒѾ³É¹¦¶ÔÈ«Çò¶à¼Ò¹«Ë¾µÄ150¶àλÖÎÀí²ãÔ±¹¤ÌáÒéÁËÍøÂç´¹µö¹¥»÷£¬ÖØÒªÉæ¼°µÄÊǽðÈÚ¡¢Ë¾·¨ºÍ·¿µØ²úÁìÓòµÄÆóÒµ¡£
0x01 ÊÂÎñÏêÇé
Õâ´Î¹¥»÷ÊÇÓÉÔ½ÄϵĺڿÍ×éÖ¯ÌáÒéµÄ£¬´Ó2019ÄêÄêÖÐÆðÍ·½øÐУ¬ÒòÀûÓÃÁËMicrosoft Sway¶ø±»³ÆÎªPerSwaysion¡£¸ÃºÚ¿Í×éÖ¯Ê×ÏÈÏòÊܺ¦Õß·¢ËÍÒ»·â´¹µöÓʼþ£¬¸ÃÓʼþÖвåÈëÁËαÔìµÄOffice 365Îļþ¹²ÏíµÄ֪ͨ£¬ÒÔÔö³¤ÆäÕæÊµÐÔ£¬»¹Ô̺¬Ò»¸ö¡°µ±¼´ÔĶÁ¡±µÄÁ´½Ó¡£µ±Êܺ¦Õßµã»÷Á´½Óºó£¬Êܺ¦Õ߱㱻³Á¶¨Ïòµ½ÁËÍйÜÔÚMicrosoft Swayƽ̨ÉϵÄÎļþ¡£¸ÃÒ³Ãæ»á֪ͨÊܺ¦Õß·¢¼þÈËÒѾ´ú±í¹«Ë¾¹²ÏíÁËÒ»¸öÎĵµ£¬²¢ÒªÇóÆäµã»÷Á´½ÓÔĶÁ¡£Ö®ºó£¬¸ÃÁ´½Ó½«Êܺ¦Õß³Á¶¨Ïòµ½×îºóµÄÍøÂç´¹µöµÇÂ¼Ò³Ãæ£¬¸ÃÒ³Ãæ¿´ÆðÀ´ÊÇOutlookµÄMicrosoftµ¥Ò»µÇ¼£¨SSO£©Ò³Ã棬²¢ÒªÇóÊܺ¦ÕßÊäÈëÆäƾ֤£¬ÒÔÖ´ÐÐ͵ÇÔ¡£ºÚ¿ÍÒ»µ©ÍµÇԳɹ¦£¬±ã»áʹÓÃIMAP API´Ó·þÎñÆ÷ÏÂÔØÊܺ¦Õߵĵç×ÓÓʼþÖеÄÊý¾Ý£¬¶øºó¼ÙÒâÆäÉí·ÝÓëÆäËûÈËͨѶ¡£×îºó£¬ËüÃÇ»¹»áʹÓÃÊܺ¦ÕßµÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·ºÍ¹«Ë¾Ãû³ÆÀ´ÌìÉúеĴ¹µöÓʼþ£¬¶ÔÏÂÒ»¸öÊܺ¦ÕßÌáÒé¹¥»÷¡£²¢ÇÒ£¬¸ÃÍŻﻹ»áÔÚ¹¥»÷ʵÏÖºó´ÓÊܺ¦Õߵķ¢¼þÏäÖÐɾ³ýαÔìµÄ´¹µöÓʼþ£¬ÒÔÃâÒýÆðÒÉ»ó¡£
Ŀǰ£¬¸ÃÊÂÎñÒѾ³É¹¦µØ¹¥»÷Á˵¹ú¡¢Ó¢¹ú¡¢ºÉÀ¼¡¢Ïã¸ÛºÍÐÂ¼ÓÆÂµÄ¶à¼Ò¹«Ë¾µÄÖÁÉÙ156λ¸ß¼¶¹ÙÔ±µÄ¹«Ë¾µç×ÓÓʼþÕÊ»§£¬ÖØÒªÕë¶ÔµÄÊǽðÈÚ·þÎñ¹«Ë¾£¨Ô¼50£¥£©£¬ÂÉʦÊÂÎñËùºÍ·¿µØ²ú¹«Ë¾¡£
Group-IB³ÉÁ¢ÁËÒ»¸öÔÚÏßÍøÒ³£¬Óû§Äܹ»Í¨¹ý¸ÃÍøÒ³²é³Æäµç×ÓÓʼþµØÖ·ÊÇ·ñΪPerSwaysion¹¥»÷Ò»²¿ÃÅ¡£
Group-IBDFIRÍŶӱ»Ô¼Çë²é³Ò»¼ÒÑÇÖÞ¹«Ë¾µÄÊÂÎñ£¬¸Ã¹«Ë¾È·¶¨PerSwaysionÊǸ´ÔÓµÄÈýÏàÍøÂç´¹µö²Ù×÷£¬ËüʹÓÃÌØÊâµÄÕ½ÊõºÍ¼¼ÊõÀ´Ô¤·À±»·¢ÏÖ¡£Íþв²Î¼ÓÕßͨ¹ý¡°Ëµ·þ¡±µ£ÈγÁÒª¹«Ë¾Ö°Î»µÄÈËÔ±´ò¿ªÀ´×ÔÆäÁªÏµÈËÕæÊµµØÖ·µÄ·Ç¶ñÒâPDFµç×ÓÓʼþ¸½¼þ£¬´Ó¶ø³ä·ÖÀûÓÃÁ˾«ÐÄÉè¼ÆµÄÉç»á¹¤³Ì¼¼Êõ¡£
PDF¸½¼þÊǶÔOffice 365Îļþ¹²ÏíµÄ¾«ÐÄÉè¼ÆµÄ֪ͨ£¬·ÂÕÕÁ˺Ϸ¨ÌåʽµÄÊܺ¦Õß¡£µ¥»÷¡°µ±¼´ÔĶÁ¡±ºó£¬ÔÚÕâÖÖÇé¿öÏ£¬Êܺ¦Õߣ¨´óÎÞÊýÇé¿öÏÂÊǸ߼¶¹ÙÔ±£©±»´øµ½MS SwayÉÏÍйܵÄÎļþÖС£¹¥»÷ÕßÑ¡ÔñºÏ·¨µÄ»ùÓÚÔÆµÄÄÚÈݹ²Ïí·þÎñ£¬ÀýÈçMicrosoft Sway£¬Microsoft SharePointºÍOneNote£¬ÒÔÔ¤·ÀÁ÷Á¿¼ì²â¡£¸ÃÒ³ÃæÀàËÆÓÚÕæÊµµÄMicrosoft Office 365Îļþ¹²ÏíÒ³Ãæ¡£µ«ÊÇ£¬ÕâÊÇÒ»¸öÌØÔìµÄÑÝʾÎĸåÒ³Ãæ£¬ËüÀÄÓÃÁËSwayĬÈϵÄÎ޼ʽçÊÓͼ¡£
´Ó´ËÒ³Ãæ½«Ö¸±êÓ×ÎÒ³Á¶¨Ïòµ½×îÖÕÖ¸±ê£¬¼´ÏÖʵµÄÍøÂç´¹µöÕ¾µã£¬Æä¼ÙװΪMicrosoft Single Sign-OnÒ³ÃæµÄ2017Äê°æ±¾¡£´Ë´¦£¬ÍøÂç´¹µö¹¤¾ßΪÊܺ¦Õß·ÖÅäÁËΨһµÄÐòÁкţ¬¸ÃÐòÁкÅÊǸù»ùµÄÖ¸ÎÆ¼ø±ð¼¼Êõ¡£³Á¸´ÒªÇóÆëȫһÑùµÄURL½«±»»Ø¾ø¡£ËüÖÕ³¡¶ÔÖ¸±ê½Ó¼ûµÄURLµÄÈκÎ×Ô¶¯Íþв¼ì²â¹¤×÷¡£µ±¸ß¼¶Ô±¹¤Ìá½»¹«Ë¾Office 365Í´´¦Ê±£¬¸ÃÐÅÏ¢½«Í¨¹ý°µ²ØÔÚÒ³ÃæÉϵĶî±íµç×ÓÓʼþµØÖ··¢Ë͵½µ¥¶ÀµÄÊý¾Ý·þÎñÆ÷¡£Õâ·âÓÐÓàµÄµç×ÓÓʼþÓÃ×÷ʵʱ֪ͨ²½Ö裬ÒÔÈ·±£¹¥»÷Õß¶ÔнüÊճɵį¾Ö¤×ö³ö·´Ó³¡£
0x02 ²Î¿¼Á´½Ó
https://securityaffairs.co/wordpress/102539/hacking/perswaysion-sophisticated-phishing-campaign.html
https://threatpost.com/microsoft-sway-abused-office-365-phishing-attack/155366/
https://thehackernews.com/2020/04/targeted-phishing-attacks-successfully.html
0x03 ¹¦·òÏß
2020-05-01 VSRC°ä²¼ÊÂÎñ¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ