Rewterz

Rewterz Threat Advisory – Siemens SCALANCE W700 and W1700 Information Exposure Vulnerability

December 11, 2019
Rewterz

Rewterz Threat Alert – Phishing Campaign Linked to Cobalt Group

December 12, 2019

Rewterz Threat Alert – Office 365 App Phishing Campaign

Severity

Medium

Analysis Summary

A phishing campaign gained access to victim accounts when the victims granted the app access to their Office 365 account. Phishing emails were sent to potential victims and contained a link to what was advertised as a legitimate SharePoint or OneDrive file share. When the victim clicks on the link, they are sent to a legitimate Microsoft login page. After the victim logged in (or if they were previously logged in), they were presented with a “Permissions requested” page that the app in the URL required. Clicking the Accept button essentially granted the app (and therefore the attackers) full access to the Office 365 account. In addition, any single sign on (SSO) service that leveraged the victim’s Office 365 credentials could then be accessed by the attackers. PhishLabs indicated that just changing the account password does not close this window into the account – the victim must disassociate the app from the account.

Impact

Credential theft

Indicators of Compromise

URL

  • https://login.microsoftonline.com/common/oauth2/v2.0/authorize?%20client_id=fc5d3843-d0e8-4c3f-b0ee-6d407f667751&response_type=id_token+code&redirect_uri=https%3A%2F%2Foffice

mtr.com%3A8081%2Foffice&scope=offline_access%20contacts.read%20user.read%20mail.read

%20notes.read.all%20mailboxsettings.readwrite%20Files.ReadWrite.All%20openid%20profile&state

=12345Ajtwmd&response_mode=%20form_post&nonce=YWxsYWh1IGFrYmFy

  • https://officemtr.com:8081/office

Remediation

  • Block all threat indicators at your respective controls.
  • Always be suspicious about emails sent by unknown senders.
  • Never click on the links/attachments sent by unknown senders.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.