PerSwaysion | office 365´¹µö¹¥»÷ÊÂÎñ¹«¸æ
°ä²¼¹¦·ò 2020-05-010x00 ÊÂÎñ¸ÅÊö
½üÈÕ£¬£¬£¬£¬£¬ÐÂ¼ÓÆÂÍøÂ簲ȫ¹«Ë¾IB¼¯ÍÅ·¢ÏÖÁËÒ»¸öеÄÍøÂç´¹µö»î¶¯£¬£¬£¬£¬£¬ÃûΪPerSwaysion£¬£¬£¬£¬£¬Õâ´Î¹¥»÷»î¶¯ÀûÓÃMicrosoftµÄÎļþ¹²Ïí·þÎñ£¬£¬£¬£¬£¬ÒѾ³É¹¦¶ÔÈ«Çò¶à¼Ò¹«Ë¾µÄ150¶àλÖÎÀí²ãÔ±¹¤ÌáÒéÁËÍøÂç´¹µö¹¥»÷£¬£¬£¬£¬£¬ÖØÒªÉæ¼°µÄÊǽðÈÚ¡¢Ë¾·¨ºÍ·¿µØ²úÁìÓòµÄÆóÒµ¡£¡£¡£¡£¡£¡£¡£
0x01 ÊÂÎñÏêÇé
Õâ´Î¹¥»÷ÊÇÓÉÔ½ÄϵĺڿÍ×éÖ¯ÌáÒéµÄ£¬£¬£¬£¬£¬´Ó2019ÄêÄêÖÐÆðÍ·½øÐУ¬£¬£¬£¬£¬ÒòÀûÓÃÁËMicrosoft Sway¶ø±»³ÆÎªPerSwaysion¡£¡£¡£¡£¡£¡£¡£¸ÃºÚ¿Í×éÖ¯Ê×ÏÈÏòÊܺ¦Õß·¢ËÍÒ»·â´¹µöÓʼþ£¬£¬£¬£¬£¬¸ÃÓʼþÖвåÈëÁËαÔìµÄOffice 365Îļþ¹²ÏíµÄ֪ͨ£¬£¬£¬£¬£¬ÒÔÔö³¤ÆäÕæÊµÐÔ£¬£¬£¬£¬£¬»¹Ô̺¬Ò»¸ö¡°Á¢¼´ÔĶÁ¡±µÄÁ´½Ó¡£¡£¡£¡£¡£¡£¡£µ±Êܺ¦Õßµã»÷Á´½Óºó£¬£¬£¬£¬£¬Êܺ¦Õ߱㱻³Á¶¨Ïòµ½ÁËÍйÜÔÚMicrosoft Swayƽ̨ÉϵÄÎļþ¡£¡£¡£¡£¡£¡£¡£¸ÃÒ³Ãæ»á֪ͨÊܺ¦Õß·¢¼þÈËÒѾ´ú±í¹«Ë¾¹²ÏíÁËÒ»¸öÎĵµ£¬£¬£¬£¬£¬²¢ÒªÇóÆäµã»÷Á´½ÓÔĶÁ¡£¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬¸ÃÁ´½Ó½«Êܺ¦Õß³Á¶¨Ïòµ½×îºóµÄÍøÂç´¹µöµÇÂ¼Ò³Ãæ£¬£¬£¬£¬£¬¸ÃÒ³Ãæ¿´ÆðÀ´ÊÇOutlookµÄMicrosoftµ¥Ò»µÇ¼£¨SSO£©Ò³Ã棬£¬£¬£¬£¬²¢ÒªÇóÊܺ¦ÕßÊäÈëÆäƾ֤£¬£¬£¬£¬£¬ÒÔÖ´ÐÐ͵ÇÔ¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍÒ»µ©ÍµÇԳɹ¦£¬£¬£¬£¬£¬±ã»áʹÓÃIMAP API´Ó·þÎñÆ÷ÏÂÔØÊܺ¦Õߵĵç×ÓÓʼþÖеÄÊý¾Ý£¬£¬£¬£¬£¬¶øºó¼ÙÒâÆäÉí·ÝÓëÆäËûÈËͨѶ¡£¡£¡£¡£¡£¡£¡£×îºó£¬£¬£¬£¬£¬ËüÃÇ»¹»áʹÓÃÊܺ¦ÕßµÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·ºÍ¹«Ë¾Ãû³ÆÀ´ÌìÉúеĴ¹µöÓʼþ£¬£¬£¬£¬£¬¶ÔÏÂÒ»¸öÊܺ¦ÕßÌáÒé¹¥»÷¡£¡£¡£¡£¡£¡£¡£²¢ÇÒ£¬£¬£¬£¬£¬¸ÃÍŻﻹ»áÔÚ¹¥»÷ʵÏÖºó´ÓÊܺ¦Õߵķ¢¼þÏäÖÐɾ³ýαÔìµÄ´¹µöÓʼþ£¬£¬£¬£¬£¬ÒÔÃâÒýÆðÒɻ󡣡£¡£¡£¡£¡£¡£
Ŀǰ£¬£¬£¬£¬£¬¸ÃÊÂÎñÒѾ³É¹¦µØ¹¥»÷Á˵¹ú¡¢Ó¢¹ú¡¢ºÉÀ¼¡¢Ïã¸ÛºÍÐÂ¼ÓÆÂµÄ¶à¼Ò¹«Ë¾µÄÖÁÉÙ156λ¸ß¼¶¹ÙÔ±µÄ¹«Ë¾µç×ÓÓʼþÕÊ»§£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔµÄÊǽðÈÚ·þÎñ¹«Ë¾£¨Ô¼50£¥£©£¬£¬£¬£¬£¬ÂÉʦÊÂÎñËùºÍ·¿µØ²ú¹«Ë¾¡£¡£¡£¡£¡£¡£¡£
Group-IB³ÉÁ¢ÁËÒ»¸öÔÚÏßÍøÒ³£¬£¬£¬£¬£¬Óû§Äܹ»Í¨¹ý¸ÃÍøÒ³²é³Æäµç×ÓÓʼþµØÖ·ÊÇ·ñΪPerSwaysion¹¥»÷Ò»²¿ÃÅ¡£¡£¡£¡£¡£¡£¡£
Group-IBDFIRÍŶӱ»Ô¼Çë²é³Ò»¼ÒÑÇÖÞ¹«Ë¾µÄÊÂÎñ£¬£¬£¬£¬£¬¸Ã¹«Ë¾È·¶¨PerSwaysionÊǸ´ÔÓµÄÈýÏàÍøÂç´¹µö²Ù×÷£¬£¬£¬£¬£¬ËüʹÓÃÌØÊâµÄÕ½ÊõºÍ¼¼ÊõÀ´Ô¤·À±»·¢ÏÖ¡£¡£¡£¡£¡£¡£¡£Íþв²Î¼ÓÕßͨ¹ý¡°Ëµ·þ¡±µ£ÈγÁÒª¹«Ë¾Ö°Î»µÄÈËÔ±´ò¿ªÀ´×ÔÆäÁªÏµÈËÕæÊµµØÖ·µÄ·Ç¶ñÒâPDFµç×ÓÓʼþ¸½¼þ£¬£¬£¬£¬£¬´Ó¶ø³ä·ÖÀûÓÃÁ˾«ÐÄÉè¼ÆµÄÉç»á¹¤³Ì¼¼Êõ¡£¡£¡£¡£¡£¡£¡£
PDF¸½¼þÊǶÔOffice 365Îļþ¹²ÏíµÄ¾«ÐÄÉè¼ÆµÄ֪ͨ£¬£¬£¬£¬£¬·ÂÕÕÁ˺Ϸ¨ÌåʽµÄÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£µ¥»÷¡°Á¢¼´ÔĶÁ¡±ºó£¬£¬£¬£¬£¬ÔÚÕâÖÖÇé¿öÏ£¬£¬£¬£¬£¬Êܺ¦Õߣ¨´óÎÞÊýÇé¿öÏÂÊǸ߼¶¹ÙÔ±£©±»´øµ½MS SwayÉÏÍйܵÄÎļþÖÓ×£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÑ¡ÔñºÏ·¨µÄ»ùÓÚÔÆµÄÄÚÈݹ²Ïí·þÎñ£¬£¬£¬£¬£¬ÀýÈçMicrosoft Sway£¬£¬£¬£¬£¬Microsoft SharePointºÍOneNote£¬£¬£¬£¬£¬ÒÔÔ¤·ÀÁ÷Á¿¼ì²â¡£¡£¡£¡£¡£¡£¡£¸ÃÒ³ÃæÀàËÆÓÚÕæÊµµÄMicrosoft Office 365Îļþ¹²ÏíÒ³Ãæ¡£¡£¡£¡£¡£¡£¡£µ«ÊÇ£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öÌØÔìµÄÑÝʾÎĸåÒ³Ãæ£¬£¬£¬£¬£¬ËüÀÄÓÃÁËSwayĬÈϵÄÎ޼ʽçÊÓͼ¡£¡£¡£¡£¡£¡£¡£
´Ó´ËÒ³Ãæ½«Ö¸±êÓ×ÎÒ³Á¶¨Ïòµ½×îÖÕÖ¸±ê£¬£¬£¬£¬£¬¼´ÏÖʵµÄÍøÂç´¹µöÕ¾µã£¬£¬£¬£¬£¬Æä¼ÙװΪMicrosoft Single Sign-OnÒ³ÃæµÄ2017Äê°æ±¾¡£¡£¡£¡£¡£¡£¡£´Ë´¦£¬£¬£¬£¬£¬ÍøÂç´¹µö¹¤¾ßΪÊܺ¦Õß·ÖÅäÁËΨһµÄÐòÁкţ¬£¬£¬£¬£¬¸ÃÐòÁкÅÊǸù»ùµÄÖ¸ÎÆ¼ø±ð¼¼Êõ¡£¡£¡£¡£¡£¡£¡£³Á¸´ÒªÇóÆëȫһÑùµÄURL½«±»»Ø¾ø¡£¡£¡£¡£¡£¡£¡£ËüÖÕ³¡¶ÔÖ¸±ê½Ó¼ûµÄURLµÄÈκÎ×Ô¶¯Íþв¼ì²â¹¤×÷¡£¡£¡£¡£¡£¡£¡£µ±¸ß¼¶Ô±¹¤Ìá½»¹«Ë¾Office 365Í´´¦Ê±£¬£¬£¬£¬£¬¸ÃÐÅÏ¢½«Í¨¹ý°µ²ØÔÚÒ³ÃæÉϵĶî±íµç×ÓÓʼþµØÖ··¢Ë͵½µ¥¶ÀµÄÊý¾Ý·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£Õâ·âÓÐÓàµÄµç×ÓÓʼþÓÃ×÷ʵʱ֪ͨ²½Ö裬£¬£¬£¬£¬ÒÔÈ·±£¹¥»÷Õß¶ÔнüÊճɵį¾Ö¤×ö³ö·´Ó³¡£¡£¡£¡£¡£¡£¡£
0x02 ²Î¿¼Á´½Ó
https://securityaffairs.co/wordpress/102539/hacking/perswaysion-sophisticated-phishing-campaign.html
https://threatpost.com/microsoft-sway-abused-office-365-phishing-attack/155366/
https://thehackernews.com/2020/04/targeted-phishing-attacks-successfully.html
0x03 ¹¦·òÏß
2020-05-01 VSRC°ä²¼ÊÂÎñ¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ