PerSwaysion | office 365´¹ÂÚ¹¥»÷ÊÂÎñͨ¸æ

Ðû²¼Ê±¼ä 2020-05-01

0x00 ÊÂÎñ¸ÅÊö


¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬ÐÂ¼ÓÆÂÍøÂçÇå¾²¹«Ë¾IB¼¯ÍÅ·¢Ã÷ÁËÒ»¸öеÄÍøÂç´¹Âڻ£¬£¬£¬£¬£¬£¬£¬ÃûΪPerSwaysion£¬£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷»î¶¯Ê¹ÓÃMicrosoftµÄÎļþ¹²ÏíЧÀÍ£¬£¬£¬£¬£¬£¬£¬ÒѾ­ÀֳɶÔÈ«Çò¶à¼Ò¹«Ë¾µÄ150¶àλÖÎÀí²ãÔ±¹¤ÌᳫÁËÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ö÷񻃾¼°µÄÊǽðÈÚ¡¢Ö´·¨ºÍ·¿µØ²úÁìÓòµÄÆóÒµ¡£¡£¡£


0x01 ÊÂÎñÏêÇé


´Ë´Î¹¥»÷ÊÇÓÉÔ½ÄϵĺڿÍ×éÖ¯ÌᳫµÄ£¬£¬£¬£¬£¬£¬£¬´Ó2019ÄêÄêÖÐ×îÏȾÙÐУ¬£¬£¬£¬£¬£¬£¬ÒòʹÓÃÁËMicrosoft Sway¶ø±»³ÆÎªPerSwaysion¡£¡£¡£¸ÃºÚ¿Í×éÖ¯Ê×ÏÈÏòÊܺ¦Õß·¢ËÍÒ»·â´¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬£¬¸ÃÓʼþÖвåÈëÁËαÔìµÄOffice 365Îļþ¹²ÏíµÄ֪ͨ£¬£¬£¬£¬£¬£¬£¬ÒÔÔöÌíÆäÕæÊµÐÔ£¬£¬£¬£¬£¬£¬£¬»¹°üÀ¨Ò»¸ö¡°Á¬Ã¦ÔĶÁ¡±µÄÁ´½Ó¡£¡£¡£µ±Êܺ¦Õßµã»÷Á´½Óºó£¬£¬£¬£¬£¬£¬£¬Êܺ¦Õß±ã±»ÖØ¶¨Ïòµ½ÁËÍйÜÔÚMicrosoft Swayƽ̨ÉϵÄÎļþ¡£¡£¡£¸ÃÒ³Ãæ»á¸æËßÊܺ¦Õß·¢¼þÈËÒѾ­´ú±í¹«Ë¾¹²ÏíÁËÒ»¸öÎĵµ£¬£¬£¬£¬£¬£¬£¬²¢ÒªÇóÆäµã»÷Á´½ÓÔĶÁ¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬£¬£¬¸ÃÁ´½Ó½«Êܺ¦ÕßÖØ¶¨Ïòµ½×îºóµÄÍøÂç´¹ÂÚµÇÂ¼Ò³Ãæ£¬£¬£¬£¬£¬£¬£¬¸ÃÒ³Ãæ¿´ÆðÀ´ÊÇOutlookµÄMicrosoft¼òµ¥µÇ¼£¨SSO£©Ò³Ã棬£¬£¬£¬£¬£¬£¬²¢ÒªÇóÊܺ¦ÕßÊäÈëÆäƾ֤£¬£¬£¬£¬£¬£¬£¬ÒÔʵÑé͵ÇÔ¡£¡£¡£ºÚ¿ÍÒ»µ©ÍµÇÔÀֳɣ¬£¬£¬£¬£¬£¬£¬±ã»áʹÓÃIMAP API´ÓЧÀÍÆ÷ÏÂÔØÊܺ¦Õߵĵç×ÓÓʼþÖеÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬È»ºóð³äÆäÉí·ÝÓëÆäËûÈËͨѶ¡£¡£¡£×îºó£¬£¬£¬£¬£¬£¬£¬ËüÃÇ»¹»áʹÓÃÊܺ¦ÕßµÄÐÕÃû¡¢µç×ÓÓʼþµØµãºÍ¹«Ë¾Ãû³ÆÀ´ÌìÉúеĴ¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬£¬¶ÔÏÂÒ»¸öÊܺ¦ÕßÌᳫ¹¥»÷¡£¡£¡£²¢ÇÒ£¬£¬£¬£¬£¬£¬£¬¸ÃÍŻﻹ»áÔÚ¹¥»÷¿¢Êºó´ÓÊܺ¦Õߵķ¢¼þÏäÖÐɾ³ýαÔìµÄ´¹ÂÚÓʼþ£¬£¬£¬£¬£¬£¬£¬ÒÔÃâÒýÆðÏÓÒÉ¡£¡£¡£


ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñÒѾ­Àֳɵع¥»÷Á˵¹ú¡¢Ó¢¹ú¡¢ºÉÀ¼¡¢Ïã¸ÛºÍÐÂ¼ÓÆÂµÄ¶à¼Ò¹«Ë¾µÄÖÁÉÙ156λ¸ß¼¶¹ÙÔ±µÄ¹«Ë¾µç×ÓÓʼþÕÊ»§£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔµÄÊǽðÈÚЧÀ͹«Ë¾£¨Ô¼50£¥£©£¬£¬£¬£¬£¬£¬£¬×´Ê¦ÊÂÎñËùºÍ·¿µØ²ú¹«Ë¾¡£¡£¡£


Group-IB½¨ÉèÁËÒ»¸öÔÚÏßÍøÒ³£¬£¬£¬£¬£¬£¬£¬Óû§¿ÉÒÔͨ¹ý¸ÃÍøÒ³¼ì²éÆäµç×ÓÓʼþµØµãÊÇ·ñΪPerSwaysion¹¥»÷Ò»²¿·Ö¡£¡£¡£


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Group-IBDFIRÍŶӱ»Ô¼Çë¼ì²éÒ»¼ÒÑÇÖÞ¹«Ë¾µÄÊÂÎñ£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾È·¶¨PerSwaysionÊÇÖØ´óµÄÈýÏàÍøÂç´¹ÂÚ²Ù×÷£¬£¬£¬£¬£¬£¬£¬ËüʹÓÃÌØÊâµÄÕ½ÂÔºÍÊÖÒÕÀ´×èÖ¹±»·¢Ã÷¡£¡£¡£Íþв¼ÓÈëÕßͨ¹ý¡°Ëµ·þ¡±µ£µ±Ö÷Òª¹«Ë¾Ö°Î»µÄÖ°Ô±·­¿ªÀ´×ÔÆäÁªÏµÈËÕæÊµµØµãµÄ·Ç¶ñÒâPDFµç×ÓÓʼþ¸½¼þ£¬£¬£¬£¬£¬£¬£¬´Ó¶ø³ä·ÖʹÓÃÁËÈ«ÐÄÉè¼ÆµÄÉç»á¹¤³ÌÊÖÒÕ¡£¡£¡£


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


PDF¸½¼þÊǶÔOffice 365Îļþ¹²ÏíµÄÈ«ÐÄÉè¼ÆµÄ֪ͨ£¬£¬£¬£¬£¬£¬£¬Ä£ÄâÁËÕýµ±ÃûÌõÄÊܺ¦Õß¡£¡£¡£µ¥»÷¡°Á¬Ã¦ÔĶÁ¡±ºó£¬£¬£¬£¬£¬£¬£¬ÔÚÕâÖÖÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬Êܺ¦Õߣ¨´ó´ó¶¼ÇéÐÎÏÂÊǸ߼¶¹ÙÔ±£©±»´øµ½MS SwayÉÏÍйܵÄÎļþÖС£¡£¡£¹¥»÷ÕßÑ¡ÔñÕýµ±µÄ»ùÓÚÔÆµÄÄÚÈݹ²ÏíЧÀÍ£¬£¬£¬£¬£¬£¬£¬ÀýÈçMicrosoft Sway£¬£¬£¬£¬£¬£¬£¬Microsoft SharePointºÍOneNote£¬£¬£¬£¬£¬£¬£¬ÒÔ×èÖ¹Á÷Á¿¼ì²â¡£¡£¡£¸ÃÒ³ÃæÀàËÆÓÚÕæÊµµÄMicrosoft Office 365Îļþ¹²ÏíÒ³Ãæ¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öÌØÖÆµÄÑÝʾÎĸåÒ³Ãæ£¬£¬£¬£¬£¬£¬£¬ËüÀÄÓÃÁËSwayĬÈϵÄÎÞ½çÏßÊÓͼ¡£¡£¡£


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÒÔºóÒ³Ãæ½«Ä¿µÄСÎÒ˽¼ÒÖØ¶¨Ïòµ½×îÖÕÄ¿µÄ£¬£¬£¬£¬£¬£¬£¬¼´ÏÖʵµÄÍøÂç´¹ÂÚÕ¾µã£¬£¬£¬£¬£¬£¬£¬ÆäαװΪMicrosoft Single Sign-OnÒ³ÃæµÄ2017Äê°æ±¾¡£¡£¡£´Ë´¦£¬£¬£¬£¬£¬£¬£¬ÍøÂç´¹ÂÚ¹¤¾ßΪÊܺ¦Õß·ÖÅÉÁËΨһµÄÐòÁкţ¬£¬£¬£¬£¬£¬£¬¸ÃÐòÁкÅÊÇ»ù±¾µÄÖ¸ÎÆÊ¶±ðÊÖÒÕ¡£¡£¡£Öظ´ÇëÇóÍêÈ«ÏàͬµÄURL½«±»¾Ü¾ø¡£¡£¡£Ëü×èÖ¹¶ÔÄ¿µÄ»á¼ûµÄURLµÄÈκÎ×Ô¶¯Íþв¼ì²âÊÂÇé¡£¡£¡£µ±¸ß¼¶Ô±¹¤Ìá½»¹«Ë¾Office 365ƾ֤ʱ£¬£¬£¬£¬£¬£¬£¬¸ÃÐÅÏ¢½«Í¨¹ýÒþ²ØÔÚÒ³ÃæÉϵÄÌØÊâµç×ÓÓʼþµØµã·¢Ë͵½µ¥¶ÀµÄÊý¾ÝЧÀÍÆ÷¡£¡£¡£Õâ·â¶àÓàµÄµç×ÓÓʼþÓÃ×÷ʵʱ֪ͨҪÁ죬£¬£¬£¬£¬£¬£¬ÒÔÈ·±£¹¥»÷Õß¶ÔнüÊÕ»ñµÄƾ֤×ö³ö·´Ó¦¡£¡£¡£


0x02 ²Î¿¼Á´½Ó


https://securityaffairs.co/wordpress/102539/hacking/perswaysion-sophisticated-phishing-campaign.html

https://threatpost.com/microsoft-sway-abused-office-365-phishing-attack/155366/

https://thehackernews.com/2020/04/targeted-phishing-attacks-successfully.html


0x03 ʱ¼äÏß


2020-05-01  VSRCÐû²¼ÊÂÎñͨ¸æ


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾