PerSwaysion | office 365´¹µö¹¥»÷ÊÂÎñ¹«¸æ

°ä²¼¹¦·ò 2020-05-01

0x00 ÊÂÎñ¸ÅÊö


½üÈÕ£¬£¬£¬£¬£¬ÐÂ¼ÓÆÂÍøÂ簲ȫ¹«Ë¾IB¼¯ÍÅ·¢ÏÖÁËÒ»¸öеÄÍøÂç´¹µö»î¶¯£¬£¬£¬£¬£¬ÃûΪPerSwaysion£¬£¬£¬£¬£¬Õâ´Î¹¥»÷»î¶¯ÀûÓÃMicrosoftµÄÎļþ¹²Ïí·þÎñ£¬£¬£¬£¬£¬ÒѾ­³É¹¦¶ÔÈ«Çò¶à¼Ò¹«Ë¾µÄ150¶àλÖÎÀí²ãÔ±¹¤ÌáÒéÁËÍøÂç´¹µö¹¥»÷£¬£¬£¬£¬£¬ÖØÒªÉæ¼°µÄÊǽðÈÚ¡¢Ë¾·¨ºÍ·¿µØ²úÁìÓòµÄÆóÒµ¡£¡£¡£¡£¡£¡£¡£


0x01 ÊÂÎñÏêÇé


Õâ´Î¹¥»÷ÊÇÓÉÔ½ÄϵĺڿÍ×éÖ¯ÌáÒéµÄ£¬£¬£¬£¬£¬´Ó2019ÄêÄêÖÐÆðÍ·½øÐУ¬£¬£¬£¬£¬ÒòÀûÓÃÁËMicrosoft Sway¶ø±»³ÆÎªPerSwaysion¡£¡£¡£¡£¡£¡£¡£¸ÃºÚ¿Í×éÖ¯Ê×ÏÈÏòÊܺ¦Õß·¢ËÍÒ»·â´¹µöÓʼþ£¬£¬£¬£¬£¬¸ÃÓʼþÖвåÈëÁËαÔìµÄOffice 365Îļþ¹²ÏíµÄ֪ͨ£¬£¬£¬£¬£¬ÒÔÔö³¤ÆäÕæÊµÐÔ£¬£¬£¬£¬£¬»¹Ô̺¬Ò»¸ö¡°Á¢¼´ÔĶÁ¡±µÄÁ´½Ó¡£¡£¡£¡£¡£¡£¡£µ±Êܺ¦Õßµã»÷Á´½Óºó£¬£¬£¬£¬£¬Êܺ¦Õ߱㱻³Á¶¨Ïòµ½ÁËÍйÜÔÚMicrosoft Swayƽ̨ÉϵÄÎļþ¡£¡£¡£¡£¡£¡£¡£¸ÃÒ³Ãæ»á֪ͨÊܺ¦Õß·¢¼þÈËÒѾ­´ú±í¹«Ë¾¹²ÏíÁËÒ»¸öÎĵµ£¬£¬£¬£¬£¬²¢ÒªÇóÆäµã»÷Á´½ÓÔĶÁ¡£¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬¸ÃÁ´½Ó½«Êܺ¦Õß³Á¶¨Ïòµ½×îºóµÄÍøÂç´¹µöµÇÂ¼Ò³Ãæ£¬£¬£¬£¬£¬¸ÃÒ³Ãæ¿´ÆðÀ´ÊÇOutlookµÄMicrosoftµ¥Ò»µÇ¼£¨SSO£©Ò³Ã棬£¬£¬£¬£¬²¢ÒªÇóÊܺ¦ÕßÊäÈëÆäƾ֤£¬£¬£¬£¬£¬ÒÔÖ´ÐÐ͵ÇÔ¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍÒ»µ©ÍµÇԳɹ¦£¬£¬£¬£¬£¬±ã»áʹÓÃIMAP API´Ó·þÎñÆ÷ÏÂÔØÊܺ¦Õߵĵç×ÓÓʼþÖеÄÊý¾Ý£¬£¬£¬£¬£¬¶øºó¼ÙÒâÆäÉí·ÝÓëÆäËûÈËͨѶ¡£¡£¡£¡£¡£¡£¡£×îºó£¬£¬£¬£¬£¬ËüÃÇ»¹»áʹÓÃÊܺ¦ÕßµÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·ºÍ¹«Ë¾Ãû³ÆÀ´ÌìÉúеĴ¹µöÓʼþ£¬£¬£¬£¬£¬¶ÔÏÂÒ»¸öÊܺ¦ÕßÌáÒé¹¥»÷¡£¡£¡£¡£¡£¡£¡£²¢ÇÒ£¬£¬£¬£¬£¬¸ÃÍŻﻹ»áÔÚ¹¥»÷ʵÏÖºó´ÓÊܺ¦Õߵķ¢¼þÏäÖÐɾ³ýαÔìµÄ´¹µöÓʼþ£¬£¬£¬£¬£¬ÒÔÃâÒýÆðÒɻ󡣡£¡£¡£¡£¡£¡£


Ŀǰ£¬£¬£¬£¬£¬¸ÃÊÂÎñÒѾ­³É¹¦µØ¹¥»÷Á˵¹ú¡¢Ó¢¹ú¡¢ºÉÀ¼¡¢Ïã¸ÛºÍÐÂ¼ÓÆÂµÄ¶à¼Ò¹«Ë¾µÄÖÁÉÙ156λ¸ß¼¶¹ÙÔ±µÄ¹«Ë¾µç×ÓÓʼþÕÊ»§£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔµÄÊǽðÈÚ·þÎñ¹«Ë¾£¨Ô¼50£¥£©£¬£¬£¬£¬£¬ÂÉʦÊÂÎñËùºÍ·¿µØ²ú¹«Ë¾¡£¡£¡£¡£¡£¡£¡£


Group-IB³ÉÁ¢ÁËÒ»¸öÔÚÏßÍøÒ³£¬£¬£¬£¬£¬Óû§Äܹ»Í¨¹ý¸ÃÍøÒ³²é³­Æäµç×ÓÓʼþµØÖ·ÊÇ·ñΪPerSwaysion¹¥»÷Ò»²¿ÃÅ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Group-IBDFIRÍŶӱ»Ô¼Çë²é³­Ò»¼ÒÑÇÖÞ¹«Ë¾µÄÊÂÎñ£¬£¬£¬£¬£¬¸Ã¹«Ë¾È·¶¨PerSwaysionÊǸ´ÔÓµÄÈýÏàÍøÂç´¹µö²Ù×÷£¬£¬£¬£¬£¬ËüʹÓÃÌØÊâµÄÕ½ÊõºÍ¼¼ÊõÀ´Ô¤·À±»·¢ÏÖ¡£¡£¡£¡£¡£¡£¡£Íþв²Î¼ÓÕßͨ¹ý¡°Ëµ·þ¡±µ£ÈγÁÒª¹«Ë¾Ö°Î»µÄÈËÔ±´ò¿ªÀ´×ÔÆäÁªÏµÈËÕæÊµµØÖ·µÄ·Ç¶ñÒâPDFµç×ÓÓʼþ¸½¼þ£¬£¬£¬£¬£¬´Ó¶ø³ä·ÖÀûÓÃÁ˾«ÐÄÉè¼ÆµÄÉç»á¹¤³Ì¼¼Êõ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


PDF¸½¼þÊǶÔOffice 365Îļþ¹²ÏíµÄ¾«ÐÄÉè¼ÆµÄ֪ͨ£¬£¬£¬£¬£¬·ÂÕÕÁ˺Ϸ¨ÌåʽµÄÊܺ¦Õß¡£¡£¡£¡£¡£¡£¡£µ¥»÷¡°Á¢¼´ÔĶÁ¡±ºó£¬£¬£¬£¬£¬ÔÚÕâÖÖÇé¿öÏ£¬£¬£¬£¬£¬Êܺ¦Õߣ¨´óÎÞÊýÇé¿öÏÂÊǸ߼¶¹ÙÔ±£©±»´øµ½MS SwayÉÏÍйܵÄÎļþÖÓ×£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÑ¡ÔñºÏ·¨µÄ»ùÓÚÔÆµÄÄÚÈݹ²Ïí·þÎñ£¬£¬£¬£¬£¬ÀýÈçMicrosoft Sway£¬£¬£¬£¬£¬Microsoft SharePointºÍOneNote£¬£¬£¬£¬£¬ÒÔÔ¤·ÀÁ÷Á¿¼ì²â¡£¡£¡£¡£¡£¡£¡£¸ÃÒ³ÃæÀàËÆÓÚÕæÊµµÄMicrosoft Office 365Îļþ¹²ÏíÒ³Ãæ¡£¡£¡£¡£¡£¡£¡£µ«ÊÇ£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öÌØÔìµÄÑÝʾÎĸåÒ³Ãæ£¬£¬£¬£¬£¬ËüÀÄÓÃÁËSwayĬÈϵÄÎ޼ʽçÊÓͼ¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


´Ó´ËÒ³Ãæ½«Ö¸±êÓ×ÎÒ³Á¶¨Ïòµ½×îÖÕÖ¸±ê£¬£¬£¬£¬£¬¼´ÏÖʵµÄÍøÂç´¹µöÕ¾µã£¬£¬£¬£¬£¬Æä¼ÙװΪMicrosoft Single Sign-OnÒ³ÃæµÄ2017Äê°æ±¾¡£¡£¡£¡£¡£¡£¡£´Ë´¦£¬£¬£¬£¬£¬ÍøÂç´¹µö¹¤¾ßΪÊܺ¦Õß·ÖÅäÁËΨһµÄÐòÁкţ¬£¬£¬£¬£¬¸ÃÐòÁкÅÊǸù»ùµÄÖ¸ÎÆ¼ø±ð¼¼Êõ¡£¡£¡£¡£¡£¡£¡£³Á¸´ÒªÇóÆëȫһÑùµÄURL½«±»»Ø¾ø¡£¡£¡£¡£¡£¡£¡£ËüÖÕ³¡¶ÔÖ¸±ê½Ó¼ûµÄURLµÄÈκÎ×Ô¶¯Íþв¼ì²â¹¤×÷¡£¡£¡£¡£¡£¡£¡£µ±¸ß¼¶Ô±¹¤Ìá½»¹«Ë¾Office 365Í´´¦Ê±£¬£¬£¬£¬£¬¸ÃÐÅÏ¢½«Í¨¹ý°µ²ØÔÚÒ³ÃæÉϵĶî±íµç×ÓÓʼþµØÖ··¢Ë͵½µ¥¶ÀµÄÊý¾Ý·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£Õâ·âÓÐÓàµÄµç×ÓÓʼþÓÃ×÷ʵʱ֪ͨ²½Ö裬£¬£¬£¬£¬ÒÔÈ·±£¹¥»÷Õß¶ÔнüÊճɵį¾Ö¤×ö³ö·´Ó³¡£¡£¡£¡£¡£¡£¡£


0x02 ²Î¿¼Á´½Ó


https://securityaffairs.co/wordpress/102539/hacking/perswaysion-sophisticated-phishing-campaign.html

https://threatpost.com/microsoft-sway-abused-office-365-phishing-attack/155366/

https://thehackernews.com/2020/04/targeted-phishing-attacks-successfully.html


0x03 ¹¦·òÏß


2020-05-01  VSRC°ä²¼ÊÂÎñ¹«¸æ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website