éèŠãªãã€ã³ã
- æ»æè ã¯ãMicrosoft 365ã®ãã€ã¬ã¯ãéä¿¡æ©èœãæªçšããçµç¹å éšããéä¿¡ãããããã«èŠãããã£ãã·ã³ã°ã¡ãŒã«ãé ä¿¡ããŠããŸããããã«ããå éšã®ä¿¡é ŒãæãªããããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°æ»æã®æåãªã¹ã¯ãé«ãŸããŸãã
- ãã£ãã·ã³ã°ã¡ãŒã«ã¯Microsoftã®è€åèªèšŒãã§ãã¯ã§ãã©ã°ãç«ãŠãããŠããŠããçµã¿èŸŒã¿ã®é²åŸ¡ãããæããŠãŠãŒã¶ãŒã®è¿·æã¡ãŒã«ãã©ã«ãã«å±ãããšããããããŸãã
- èªå°ææ³ã¯éåžžã«å¹æçãã€ããžãã¹ãè£ ã£ããã®ã§ãããã¿ã¹ã¯ã®ãªãã€ã³ããŒãééæ¿èªããã€ã¹ã¡ãŒã«ãªã©ãè£ ã£ãŠãŠãŒã¶ãŒã®æäœãä¿ããŸãã
- ãã®æ»æãã£ã³ããŒã³ã¯ãæ»æè
ãæ£èŠã®ã¯ã©ãŠããµãŒãã¹ãæªçšããŠã»ãã¥ãªãã£å¶åŸ¡ãåé¿ãããšãããããåºç¯ãªåŸåãåæ ããŠããŸããçµç¹ã¯ã¡ãŒã«èªèšŒããªã¬ãŒèšå®ãåè©äŸ¡ããããšãäžå¯æ¬ ã§ãã
æŠèŠ
ãã«ãŒããã€ã³ãã¯ãMicrosoft 365 ã®ãã€ã¬ã¯ãéä¿¡æ©èœãæªçšããŠããã£ãã·ã³ã°ã¡ãŒã«ãé ä¿¡ããã¢ã¯ãã£ããªæ»æãã£ã³ããŒã³ã確èªããŸããããã®æ»æã§ã¯ããªãããŸãã¡ãã»ãŒãžãå éšã¡ãŒã«ã®ããã«èŠãã圢ã§é ä¿¡ãããŸããã
æ»æè
ã¯ãæªä¿è·ã®ãµãŒãããŒãã£è£œã¡ãŒã«ã»ãã¥ãªãã£ã¢ãã©ã€ã¢ã³ã¹ãSMTPãªã¬ãŒãšããŠå©çšããVPSè³ç£ããã¡ãã»ãŒãžãæ¿å
¥ããŠããŸãããå€ãã®å ŽåãMicrosoftã¯è€åèªèšŒã®å€±æã«åºã¥ããŠã¡ãã»ãŒãžããªãããŸããšå€å®ããŸããããããã§ãã¡ãã»ãŒãžã¯ãŠãŒã¶ãŒã®è¿·æã¡ãŒã«ãã©ã«ãã«å±ãããã€ããŒããæçµçã«ãšã³ããŠãŒã¶ãŒã«å°éããŠããŸããŸããã
ã¯ããã«
ãã€ã¬ã¯ãéä¿¡ïŒDirect SendïŒã¯Microsoft 365ã®æ©èœã§ãèªèšŒãªãã§ããã€ã¹ãã¢ããªãã¡ãã»ãŒãžãMicrosoftã®ããã³ãã«ãªã¬ãŒããããšãå¯èœã«ããŸãïŒåä¿¡è ãçµç¹å ã®å ŽåïŒããã®æ©èœã¯ã倿©èœããªã³ã¿ãŒãã¬ã¬ã·ãŒã¢ããªã±ãŒã·ã§ã³åãã«èšèšããããã®ã§ããããããèªèšŒãããŠããªãã¡ãã»ãŒãžãå éšã¡ãŒã«ã®ããã«èŠããããŠé ä¿¡ããææ®µãšããŠæªçšãããå¯èœæ§ããããŸããã€ãŸããå€éšã®æ»æè ãæå¹ãªã¢ã«ãŠã³ãããã¹ã¯ãŒããå¿ èŠãšããã«ãããããçµç¹å ããéä¿¡ããããã®ãããªã¡ãŒã«ãéä¿¡ã§ããŠããŸãã®ã§ãã
æè¿ã®ã¡ãŒã«ã»ãã¥ãªãã£ã®æŠå¿µå®èšŒã«ãããŠãæ»æè
ããã®æ©èœãå©çšããŠéä¿¡è
èªèšŒå¶åŸ¡ãåé¿ãããªãããŸãã®ãã£ãã·ã³ã°ã¡ãŒã«ã泚å
¥ããŠãã蚌æ ã芳枬ããŸããããã®ææ³ã«ãããæ»æè
ã¯Microsoft 365ã®ãŠãŒã¶ãŒã«å¯ŸããŠãä¿¡é Œæ§ã®é«ãããã«èŠããæªæãããã€ããŒããéã蟌ãããšãã§ããå€ãã®å ŽåãèªèšŒãã§ãã¯ã«å€±æããŠããŠãé
ä¿¡ã«æåããŠããŸãã
é ä¿¡ææ³
ãã«ãŒããã€ã³ãã¯ãæªä¿è·ã®ãµãŒãããŒãã£è£œã¡ãŒã«ã»ãã¥ãªãã£ã¢ãã©ã€ã¢ã³ã¹ãSMTPãªã¬ãŒãšããŠäœ¿çšããMicrosoft 365ããã³ãã«ã¡ãã»ãŒãžã泚å
¥ããŠããäºäŸãè€æ°ç¢ºèªããŸãããéä¿¡ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ãDigiCertã®æå¹ãªSSLèšŒææžãšãSTARTTLSããµããŒãããAUTH PLAIN LOGIN察å¿SMTPãµãŒãã¹ãæç€ºããŠããŸããããããã®ã¢ãã©ã€ã¢ã³ã¹ã§ã¯ãèªå·±çœ²åãŸãã¯æéåãã®èšŒææžã䜿çšãããããŒã8008ã8010ã8015ãéãããŠããŸããã
ã¡ãã»ãŒãžæ³šå ¥ã®æµã
- æ»æè
ã¯ãããŒã3389ã䜿ã£ãŠWindows Server 2022äžã®ä»®æ³ãã¹ãã«RDPã§æ¥ç¶ããŸãã
- ãããã®ãã¹ããããå°åã®IaaSãããã€ããŒããã¹ãã£ã³ã°ããæªä¿è·ã®ãµãŒãããŒãã£è£œã¡ãŒã«ã»ãã¥ãªãã£ã¢ãã©ã€ã¢ã³ã¹ã«SMTPæ¥ç¶ãè¡ãããŸãã
- ãããã®ã¢ãã©ã€ã¢ã³ã¹ãçµç±ããŠãæšççµç¹ã®Microsoft 365ããã³ãã«ã¡ãã»ãŒãžããªã¬ãŒãããŸãã
- Direct Sendã䜿ãããªãããŸãã®å éšFromã¢ãã¬ã¹ãçšããŠãMicrosoft 365ã«ã¡ãã»ãŒãžãé ä¿¡ãããŸãã

çµè«
Microsoft 365ã®ãã€ã¬ã¯ãéä¿¡æ©èœã®æªçšã¯ãåãªãæè¡çãªæ¬ é¥ã§ã¯ãªããçµç¹ã®ä¿¡é Œãšè©å€ã«å¯ŸããæŠç¥çãªã¹ã¯ã§ãããã®æ»æãã£ã³ããŒã³ã¯ãæ»æè ãæ£èŠã®Microsoft 365æ©èœãæŠåšåããçµç¹ãè ãããŠããããšã瀺ããŠããŸããæªä¿è·ã®ã¡ãŒã«ã€ã³ãã©ãä»ããŠãªã¬ãŒããå éšãã¡ã€ã³ããªãããŸãããšã§ãèªèšŒã«å€±æããŠããŠãé«ãä¿¡é Œæ§ãè£ ããåä¿¡ç®±ãžã®é ä¿¡ã«æåããŠããŸããå éšã¡ãŒã«ãä¿¡é Œã§ããªããªããšãçç£æ§ã¯äœäžãããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°æ»æãæåãããªã¹ã¯ãåçã«å¢å ããŸãã
ãã®æ»æãã£ã³ããŒã³ã¯ãæ»æè
ãä¿¡é ŒãããŠããã¯ã©ãŠããµãŒãã¹ãæªçšããŠæ»æã仿ããæ€ç¥ãåé¿ãããšããåºç¯ãªåŸåã®äžéšã§ããçµç¹ãMicrosoft 365ãå€§èŠæš¡ã«å°å
¥ãããªãã§ããããããªã¹ã¯ãçè§£ãã察çãè¬ããããšããå®å
šãªããžã¿ã«è·å Žãç¶æããããã§äžå¯æ¬ ã§ããCISOãITãªãŒããŒã¯ããã€ã¬ã¯ãéä¿¡æ©èœã®æªçšã«å¯Ÿããèªçµç¹ã®è匱æ§ãç©æ¥µçã«è©äŸ¡ããå®å
šãªã¡ãŒã«ãªã¬ãŒã®å®è£
ãæšé²ããŠãå
éšã®ä¿¡é Œæ§ãšçµç¹ã®ã¬ãžãªãšã³ã¹ãå®ãå¿
èŠããããŸãããã€ã¬ã¯ãéä¿¡æ©èœããªã¹ã¯èŠå ãšæããProofpoint Secure Email Relayã®ãããªã¢ããªã±ãŒã·ã§ã³çæã¡ãŒã«åãã®å®å
šãªèªèšŒã·ã¹ãã ã®å°å
¥ãæ€èšãã¹ãã§ãã
Microsoft 365ãŠãŒã¶ãŒåãæšå¥šã¢ã¯ã·ã§ã³
çµç¹ãä¿è·ããããã®ãã³ãã以äžã«ç€ºããŸãïŒ
- èªçµç¹ã§Direct SendãçŸåšå©çšããŠãããã確èªããäžèŠã§ããã°PowerShellã§ãReject Direct Sendããæå¹åïŒSet-OrganizationConfig -RejectDirectSend $true
- æªèªèšŒã®ãªã¬ãŒIPãèš±å¯ããŠããã¡ãŒã«ãããŒã«ãŒã«ãç£æ»ããMicrosoftãcompauth=failãšãã©ã°ä»ããããªãããŸã詊è¡ã®ã¡ãã»ãŒãžããããŒãç£èŠãã
- ã¡ãŒã«èªèšŒïŒSPFãDKIMãDMARCïŒã匷å¶ããå¯èœã§ããã°å³æ ŒãªDMARCæåŠããªã·ãŒãšSPFããŒããã§ã€ã«ããªã·ãŒãèšå®ãæ£åœãªã¡ãŒã«ã®é ä¿¡ãä¿èšŒããããã«ã¯ãProofpoint Email Fraud Defenseãªã©ã®ä¿¡é Œã§ãããµãŒãã¹ãšã®é£æºãæå¹
- Proofpoint Core Email Protectionãªã©ã®é«åºŠãªã¡ãŒã«ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãå°å
¥ããMicrosoftã®æšæºä¿è·æ©èœã匷åãã
IoCïŒIndicator of Compromise / äŸµå®³ææšïŒ
|
Self-Signed SSL Certificate |
Notes |
|
CN=WIN-BUNS25TD77J |
CN used by attacker-controlled Windows Server 2022 hosts |
|
|
|
|
IP Address |
Notes |
|
163.5.112[.]86 |
Attacker-controlled Windows Server 2022 host used to initiate SMTP connection |
|
163.5.160[.]28 |
Attacker-controlled Windows Server 2022 host used to initiate SMTP connection |
|
163.5.160[.]119 |
Attacker-controlled Windows Server 2022 host used to initiate SMTP connection |
|
163.5.160[.]143 |
Attacker-controlled Windows Server 2022 host used to initiate SMTP connection |
|
163.5.169[.]53 |
Attacker-controlled Windows Server 2022 host used to initiate SMTP connection |
|
|
|
|
Observed Lures |
|
|
âYour-to-do-List/MM/DD/YYYYâ |
|
|
âWire-eAuthorization approvalMM/DD/YYYYâ |
|
|
âPayment ACH-Wire Authorizationâ |
|
|
âDaily Reminder: Todayâs Tasks â MM/DD/YYYYâ |
|
|
âReminder â To Do â MM/DD/YYYYâ |
|
|
âWIRELESSCALLER(XXX)YYY-ZZZZ-MM/DD/YYYYâ |
|