PerSwaysion | office 365´¹ÂÚ¹¥»÷ÊÂÎñͨ¸æ
Ðû²¼Ê±¼ä 2020-05-010x00 ÊÂÎñ¸ÅÊö
¿ËÈÕ£¬£¬£¬ÐÂ¼ÓÆÂÍøÂçÇå¾²¹«Ë¾IB¼¯ÍÅ·¢Ã÷ÁËÒ»¸öеÄÍøÂç´¹Âڻ£¬£¬£¬ÃûΪPerSwaysion£¬£¬£¬´Ë´Î¹¥»÷»î¶¯Ê¹ÓÃMicrosoftµÄÎļþ¹²ÏíЧÀÍ£¬£¬£¬ÒѾÀֳɶÔÈ«Çò¶à¼Ò¹«Ë¾µÄ150¶àλÖÎÀí²ãÔ±¹¤ÌᳫÁËÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬Ö÷񻃾¼°µÄÊǽðÈÚ¡¢Ö´·¨ºÍ·¿µØ²úÁìÓòµÄÆóÒµ¡£¡£¡£¡£¡£¡£¡£¡£
0x01 ÊÂÎñÏêÇé
´Ë´Î¹¥»÷ÊÇÓÉÔ½ÄϵĺڿÍ×éÖ¯ÌᳫµÄ£¬£¬£¬´Ó2019ÄêÄêÖÐ×îÏȾÙÐУ¬£¬£¬ÒòʹÓÃÁËMicrosoft Sway¶ø±»³ÆÎªPerSwaysion¡£¡£¡£¡£¡£¡£¡£¡£¸ÃºÚ¿Í×éÖ¯Ê×ÏÈÏòÊܺ¦Õß·¢ËÍÒ»·â´¹ÂÚÓʼþ£¬£¬£¬¸ÃÓʼþÖвåÈëÁËαÔìµÄOffice 365Îļþ¹²ÏíµÄ֪ͨ£¬£¬£¬ÒÔÔöÌíÆäÕæÊµÐÔ£¬£¬£¬»¹°üÀ¨Ò»¸ö¡°Á¬Ã¦ÔĶÁ¡±µÄÁ´½Ó¡£¡£¡£¡£¡£¡£¡£¡£µ±Êܺ¦Õßµã»÷Á´½Óºó£¬£¬£¬Êܺ¦Õß±ã±»ÖØ¶¨Ïòµ½ÁËÍйÜÔÚMicrosoft Swayƽ̨ÉϵÄÎļþ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÒ³Ãæ»á¸æËßÊܺ¦Õß·¢¼þÈËÒѾ´ú±í¹«Ë¾¹²ÏíÁËÒ»¸öÎĵµ£¬£¬£¬²¢ÒªÇóÆäµã»÷Á´½ÓÔĶÁ¡£¡£¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬¸ÃÁ´½Ó½«Êܺ¦ÕßÖØ¶¨Ïòµ½×îºóµÄÍøÂç´¹ÂÚµÇÂ¼Ò³Ãæ£¬£¬£¬¸ÃÒ³Ãæ¿´ÆðÀ´ÊÇOutlookµÄMicrosoft¼òµ¥µÇ¼£¨SSO£©Ò³Ã棬£¬£¬²¢ÒªÇóÊܺ¦ÕßÊäÈëÆäƾ֤£¬£¬£¬ÒÔʵÑé͵ÇÔ¡£¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍÒ»µ©ÍµÇÔÀֳɣ¬£¬£¬±ã»áʹÓÃIMAP API´ÓЧÀÍÆ÷ÏÂÔØÊܺ¦Õߵĵç×ÓÓʼþÖеÄÊý¾Ý£¬£¬£¬È»ºóð³äÆäÉí·ÝÓëÆäËûÈËͨѶ¡£¡£¡£¡£¡£¡£¡£¡£×îºó£¬£¬£¬ËüÃÇ»¹»áʹÓÃÊܺ¦ÕßµÄÐÕÃû¡¢µç×ÓÓʼþµØµãºÍ¹«Ë¾Ãû³ÆÀ´ÌìÉúеĴ¹ÂÚÓʼþ£¬£¬£¬¶ÔÏÂÒ»¸öÊܺ¦ÕßÌᳫ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£²¢ÇÒ£¬£¬£¬¸ÃÍŻﻹ»áÔÚ¹¥»÷¿¢Êºó´ÓÊܺ¦Õߵķ¢¼þÏäÖÐɾ³ýαÔìµÄ´¹ÂÚÓʼþ£¬£¬£¬ÒÔÃâÒýÆðÏÓÒÉ¡£¡£¡£¡£¡£¡£¡£¡£
ÏÖÔÚ£¬£¬£¬¸ÃÊÂÎñÒѾÀֳɵع¥»÷Á˵¹ú¡¢Ó¢¹ú¡¢ºÉÀ¼¡¢Ïã¸ÛºÍÐÂ¼ÓÆÂµÄ¶à¼Ò¹«Ë¾µÄÖÁÉÙ156λ¸ß¼¶¹ÙÔ±µÄ¹«Ë¾µç×ÓÓʼþÕÊ»§£¬£¬£¬Ö÷ÒªÕë¶ÔµÄÊǽðÈÚЧÀ͹«Ë¾£¨Ô¼50£¥£©£¬£¬£¬×´Ê¦ÊÂÎñËùºÍ·¿µØ²ú¹«Ë¾¡£¡£¡£¡£¡£¡£¡£¡£
Group-IB½¨ÉèÁËÒ»¸öÔÚÏßÍøÒ³£¬£¬£¬Óû§¿ÉÒÔͨ¹ý¸ÃÍøÒ³¼ì²éÆäµç×ÓÓʼþµØµãÊÇ·ñΪPerSwaysion¹¥»÷Ò»²¿·Ö¡£¡£¡£¡£¡£¡£¡£¡£
Group-IBDFIRÍŶӱ»Ô¼Çë¼ì²éÒ»¼ÒÑÇÖÞ¹«Ë¾µÄÊÂÎñ£¬£¬£¬¸Ã¹«Ë¾È·¶¨PerSwaysionÊÇÖØ´óµÄÈýÏàÍøÂç´¹ÂÚ²Ù×÷£¬£¬£¬ËüʹÓÃÌØÊâµÄÕ½ÂÔºÍÊÖÒÕÀ´×èÖ¹±»·¢Ã÷¡£¡£¡£¡£¡£¡£¡£¡£Íþв¼ÓÈëÕßͨ¹ý¡°Ëµ·þ¡±µ£µ±Ö÷Òª¹«Ë¾Ö°Î»µÄÖ°Ô±·¿ªÀ´×ÔÆäÁªÏµÈËÕæÊµµØµãµÄ·Ç¶ñÒâPDFµç×ÓÓʼþ¸½¼þ£¬£¬£¬´Ó¶ø³ä·ÖʹÓÃÁËÈ«ÐÄÉè¼ÆµÄÉç»á¹¤³ÌÊÖÒÕ¡£¡£¡£¡£¡£¡£¡£¡£
PDF¸½¼þÊǶÔOffice 365Îļþ¹²ÏíµÄÈ«ÐÄÉè¼ÆµÄ֪ͨ£¬£¬£¬Ä£ÄâÁËÕýµ±ÃûÌõÄÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£¡£µ¥»÷¡°Á¬Ã¦ÔĶÁ¡±ºó£¬£¬£¬ÔÚÕâÖÖÇéÐÎÏ£¬£¬£¬Êܺ¦Õߣ¨´ó´ó¶¼ÇéÐÎÏÂÊǸ߼¶¹ÙÔ±£©±»´øµ½MS SwayÉÏÍйܵÄÎļþÖС£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÑ¡ÔñÕýµ±µÄ»ùÓÚÔÆµÄÄÚÈݹ²ÏíЧÀÍ£¬£¬£¬ÀýÈçMicrosoft Sway£¬£¬£¬Microsoft SharePointºÍOneNote£¬£¬£¬ÒÔ×èÖ¹Á÷Á¿¼ì²â¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÒ³ÃæÀàËÆÓÚÕæÊµµÄMicrosoft Office 365Îļþ¹²ÏíÒ³Ãæ¡£¡£¡£¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬ÕâÊÇÒ»¸öÌØÖÆµÄÑÝʾÎĸåÒ³Ãæ£¬£¬£¬ËüÀÄÓÃÁËSwayĬÈϵÄÎÞ½çÏßÊÓͼ¡£¡£¡£¡£¡£¡£¡£¡£
ÒÔºóÒ³Ãæ½«Ä¿µÄСÎÒ˽¼ÒÖØ¶¨Ïòµ½×îÖÕÄ¿µÄ£¬£¬£¬¼´ÏÖʵµÄÍøÂç´¹ÂÚÕ¾µã£¬£¬£¬ÆäαװΪMicrosoft Single Sign-OnÒ³ÃæµÄ2017Äê°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£´Ë´¦£¬£¬£¬ÍøÂç´¹ÂÚ¹¤¾ßΪÊܺ¦Õß·ÖÅÉÁËΨһµÄÐòÁкţ¬£¬£¬¸ÃÐòÁкÅÊÇ»ù±¾µÄÖ¸ÎÆÊ¶±ðÊÖÒÕ¡£¡£¡£¡£¡£¡£¡£¡£Öظ´ÇëÇóÍêÈ«ÏàͬµÄURL½«±»¾Ü¾ø¡£¡£¡£¡£¡£¡£¡£¡£Ëü×èÖ¹¶ÔÄ¿µÄ»á¼ûµÄURLµÄÈκÎ×Ô¶¯Íþв¼ì²âÊÂÇé¡£¡£¡£¡£¡£¡£¡£¡£µ±¸ß¼¶Ô±¹¤Ìá½»¹«Ë¾Office 365ƾ֤ʱ£¬£¬£¬¸ÃÐÅÏ¢½«Í¨¹ýÒþ²ØÔÚÒ³ÃæÉϵÄÌØÊâµç×ÓÓʼþµØµã·¢Ë͵½µ¥¶ÀµÄÊý¾ÝЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£¡£Õâ·â¶àÓàµÄµç×ÓÓʼþÓÃ×÷ʵʱ֪ͨҪÁ죬£¬£¬ÒÔÈ·±£¹¥»÷Õß¶ÔнüÊÕ»ñµÄƾ֤×ö³ö·´Ó¦¡£¡£¡£¡£¡£¡£¡£¡£
0x02 ²Î¿¼Á´½Ó
https://securityaffairs.co/wordpress/102539/hacking/perswaysion-sophisticated-phishing-campaign.html
https://threatpost.com/microsoft-sway-abused-office-365-phishing-attack/155366/
https://thehackernews.com/2020/04/targeted-phishing-attacks-successfully.html
0x03 ʱ¼äÏß
2020-05-01 VSRCÐû²¼ÊÂÎñͨ¸æ


¾©¹«Íø°²±¸11010802024551ºÅ