PerSwaysion | office 365´¹ÂÚ¹¥»÷ÊÂÎñͨ¸æ

Ðû²¼Ê±¼ä 2020-05-01

0x00 ÊÂÎñ¸ÅÊö


¿ËÈÕ£¬£¬£¬£¬£¬£¬ÐÂ¼ÓÆÂÍøÂçÇå¾²¹«Ë¾IB¼¯ÍÅ·¢Ã÷ÁËÒ»¸öеÄÍøÂç´¹Âڻ£¬£¬£¬£¬£¬£¬ÃûΪPerSwaysion£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷»î¶¯Ê¹ÓÃMicrosoftµÄÎļþ¹²ÏíЧÀÍ£¬£¬£¬£¬£¬£¬ÒѾ­ÀֳɶÔÈ«Çò¶à¼Ò¹«Ë¾µÄ150¶àλÖÎÀí²ãÔ±¹¤ÌᳫÁËÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬Ö÷񻃾¼°µÄÊǽðÈÚ¡¢Ö´·¨ºÍ·¿µØ²úÁìÓòµÄÆóÒµ¡£¡£


0x01 ÊÂÎñÏêÇé


´Ë´Î¹¥»÷ÊÇÓÉÔ½ÄϵĺڿÍ×éÖ¯ÌᳫµÄ£¬£¬£¬£¬£¬£¬´Ó2019ÄêÄêÖÐ×îÏȾÙÐУ¬£¬£¬£¬£¬£¬ÒòʹÓÃÁËMicrosoft Sway¶ø±»³ÆÎªPerSwaysion¡£¡£¸ÃºÚ¿Í×éÖ¯Ê×ÏÈÏòÊܺ¦Õß·¢ËÍÒ»·â´¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬¸ÃÓʼþÖвåÈëÁËαÔìµÄOffice 365Îļþ¹²ÏíµÄ֪ͨ£¬£¬£¬£¬£¬£¬ÒÔÔöÌíÆäÕæÊµÐÔ£¬£¬£¬£¬£¬£¬»¹°üÀ¨Ò»¸ö¡°Á¬Ã¦ÔĶÁ¡±µÄÁ´½Ó¡£¡£µ±Êܺ¦Õßµã»÷Á´½Óºó£¬£¬£¬£¬£¬£¬Êܺ¦Õß±ã±»ÖØ¶¨Ïòµ½ÁËÍйÜÔÚMicrosoft Swayƽ̨ÉϵÄÎļþ¡£¡£¸ÃÒ³Ãæ»á¸æËßÊܺ¦Õß·¢¼þÈËÒѾ­´ú±í¹«Ë¾¹²ÏíÁËÒ»¸öÎĵµ£¬£¬£¬£¬£¬£¬²¢ÒªÇóÆäµã»÷Á´½ÓÔĶÁ¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬¸ÃÁ´½Ó½«Êܺ¦ÕßÖØ¶¨Ïòµ½×îºóµÄÍøÂç´¹ÂÚµÇÂ¼Ò³Ãæ£¬£¬£¬£¬£¬£¬¸ÃÒ³Ãæ¿´ÆðÀ´ÊÇOutlookµÄMicrosoft¼òµ¥µÇ¼£¨SSO£©Ò³Ã棬£¬£¬£¬£¬£¬²¢ÒªÇóÊܺ¦ÕßÊäÈëÆäƾ֤£¬£¬£¬£¬£¬£¬ÒÔʵÑé͵ÇÔ¡£¡£ºÚ¿ÍÒ»µ©ÍµÇÔÀֳɣ¬£¬£¬£¬£¬£¬±ã»áʹÓÃIMAP API´ÓЧÀÍÆ÷ÏÂÔØÊܺ¦Õߵĵç×ÓÓʼþÖеÄÊý¾Ý£¬£¬£¬£¬£¬£¬È»ºóð³äÆäÉí·ÝÓëÆäËûÈËͨѶ¡£¡£×îºó£¬£¬£¬£¬£¬£¬ËüÃÇ»¹»áʹÓÃÊܺ¦ÕßµÄÐÕÃû¡¢µç×ÓÓʼþµØµãºÍ¹«Ë¾Ãû³ÆÀ´ÌìÉúеĴ¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬¶ÔÏÂÒ»¸öÊܺ¦ÕßÌᳫ¹¥»÷¡£¡£²¢ÇÒ£¬£¬£¬£¬£¬£¬¸ÃÍŻﻹ»áÔÚ¹¥»÷¿¢Êºó´ÓÊܺ¦Õߵķ¢¼þÏäÖÐɾ³ýαÔìµÄ´¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬ÒÔÃâÒýÆðÏÓÒÉ¡£¡£


ÏÖÔÚ£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñÒѾ­Àֳɵع¥»÷Á˵¹ú¡¢Ó¢¹ú¡¢ºÉÀ¼¡¢Ïã¸ÛºÍÐÂ¼ÓÆÂµÄ¶à¼Ò¹«Ë¾µÄÖÁÉÙ156λ¸ß¼¶¹ÙÔ±µÄ¹«Ë¾µç×ÓÓʼþÕÊ»§£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔµÄÊǽðÈÚЧÀ͹«Ë¾£¨Ô¼50£¥£©£¬£¬£¬£¬£¬£¬×´Ê¦ÊÂÎñËùºÍ·¿µØ²ú¹«Ë¾¡£¡£


Group-IB½¨ÉèÁËÒ»¸öÔÚÏßÍøÒ³£¬£¬£¬£¬£¬£¬Óû§¿ÉÒÔͨ¹ý¸ÃÍøÒ³¼ì²éÆäµç×ÓÓʼþµØµãÊÇ·ñΪPerSwaysion¹¥»÷Ò»²¿·Ö¡£¡£


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Group-IBDFIRÍŶӱ»Ô¼Çë¼ì²éÒ»¼ÒÑÇÖÞ¹«Ë¾µÄÊÂÎñ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾È·¶¨PerSwaysionÊÇÖØ´óµÄÈýÏàÍøÂç´¹ÂÚ²Ù×÷£¬£¬£¬£¬£¬£¬ËüʹÓÃÌØÊâµÄÕ½ÂÔºÍÊÖÒÕÀ´×èÖ¹±»·¢Ã÷¡£¡£Íþв¼ÓÈëÕßͨ¹ý¡°Ëµ·þ¡±µ£µ±Ö÷Òª¹«Ë¾Ö°Î»µÄÖ°Ô±·­¿ªÀ´×ÔÆäÁªÏµÈËÕæÊµµØµãµÄ·Ç¶ñÒâPDFµç×ÓÓʼþ¸½¼þ£¬£¬£¬£¬£¬£¬´Ó¶ø³ä·ÖʹÓÃÁËÈ«ÐÄÉè¼ÆµÄÉç»á¹¤³ÌÊÖÒÕ¡£¡£


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


PDF¸½¼þÊǶÔOffice 365Îļþ¹²ÏíµÄÈ«ÐÄÉè¼ÆµÄ֪ͨ£¬£¬£¬£¬£¬£¬Ä£ÄâÁËÕýµ±ÃûÌõÄÊܺ¦Õß¡£¡£µ¥»÷¡°Á¬Ã¦ÔĶÁ¡±ºó£¬£¬£¬£¬£¬£¬ÔÚÕâÖÖÇéÐÎÏ£¬£¬£¬£¬£¬£¬Êܺ¦Õߣ¨´ó´ó¶¼ÇéÐÎÏÂÊǸ߼¶¹ÙÔ±£©±»´øµ½MS SwayÉÏÍйܵÄÎļþÖС£¡£¹¥»÷ÕßÑ¡ÔñÕýµ±µÄ»ùÓÚÔÆµÄÄÚÈݹ²ÏíЧÀÍ£¬£¬£¬£¬£¬£¬ÀýÈçMicrosoft Sway£¬£¬£¬£¬£¬£¬Microsoft SharePointºÍOneNote£¬£¬£¬£¬£¬£¬ÒÔ×èÖ¹Á÷Á¿¼ì²â¡£¡£¸ÃÒ³ÃæÀàËÆÓÚÕæÊµµÄMicrosoft Office 365Îļþ¹²ÏíÒ³Ãæ¡£¡£¿ÉÊÇ£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öÌØÖÆµÄÑÝʾÎĸåÒ³Ãæ£¬£¬£¬£¬£¬£¬ËüÀÄÓÃÁËSwayĬÈϵÄÎÞ½çÏßÊÓͼ¡£¡£


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÒÔºóÒ³Ãæ½«Ä¿µÄСÎÒ˽¼ÒÖØ¶¨Ïòµ½×îÖÕÄ¿µÄ£¬£¬£¬£¬£¬£¬¼´ÏÖʵµÄÍøÂç´¹ÂÚÕ¾µã£¬£¬£¬£¬£¬£¬ÆäαװΪMicrosoft Single Sign-OnÒ³ÃæµÄ2017Äê°æ±¾¡£¡£´Ë´¦£¬£¬£¬£¬£¬£¬ÍøÂç´¹ÂÚ¹¤¾ßΪÊܺ¦Õß·ÖÅÉÁËΨһµÄÐòÁкţ¬£¬£¬£¬£¬£¬¸ÃÐòÁкÅÊÇ»ù±¾µÄÖ¸ÎÆÊ¶±ðÊÖÒÕ¡£¡£Öظ´ÇëÇóÍêÈ«ÏàͬµÄURL½«±»¾Ü¾ø¡£¡£Ëü×èÖ¹¶ÔÄ¿µÄ»á¼ûµÄURLµÄÈκÎ×Ô¶¯Íþв¼ì²âÊÂÇé¡£¡£µ±¸ß¼¶Ô±¹¤Ìá½»¹«Ë¾Office 365ƾ֤ʱ£¬£¬£¬£¬£¬£¬¸ÃÐÅÏ¢½«Í¨¹ýÒþ²ØÔÚÒ³ÃæÉϵÄÌØÊâµç×ÓÓʼþµØµã·¢Ë͵½µ¥¶ÀµÄÊý¾ÝЧÀÍÆ÷¡£¡£Õâ·â¶àÓàµÄµç×ÓÓʼþÓÃ×÷ʵʱ֪ͨҪÁ죬£¬£¬£¬£¬£¬ÒÔÈ·±£¹¥»÷Õß¶ÔнüÊÕ»ñµÄƾ֤×ö³ö·´Ó¦¡£¡£


0x02 ²Î¿¼Á´½Ó


https://securityaffairs.co/wordpress/102539/hacking/perswaysion-sophisticated-phishing-campaign.html

https://threatpost.com/microsoft-sway-abused-office-365-phishing-attack/155366/

https://thehackernews.com/2020/04/targeted-phishing-attacks-successfully.html


0x03 ʱ¼äÏß


2020-05-01  VSRCÐû²¼ÊÂÎñͨ¸æ


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾