• Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
AnonyViet - English Version
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
No Result
View All Result
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
No Result
View All Result
AnonyViet - English Version
No Result
View All Result

Phishing method by attaching malicious files on Office 365

AnonyViet by AnonyViet
August 11, 2023
in Security
0

Abusing the way Office 365 Outlook allows file attachments on the Cloud to disguise malicious code as a harmless file. In this article, we will explore how to abuse the Cloud file attachment feature Office 365 to make the executable (or any other file type) appear as a harmless attachment.

Join the channel Telegram belong to AnonyViet ???? Link ????

File attachment method

Office 365 allows you to upload attachments in one of two ways:

  • Direct Attachments – Traditional way of uploading files. Severe restrictions on allowed file types.
  • Cloud Attachments – Attach files available on the Cloud (OneDrive/SharePoint). File types are not restricted.

The image below shows how attachments appear to target users. The difference between these 2 types of attachments is the icon and link of the Cloud attachment below

Phishing method by attaching malicious files on Office 365 11

We have seen the difference between the two methods above, now we will use the technique of attaching malicious files to the Cloud.

Condition

There are a few things you should do before proceeding:

1. Set up the domain and HTTP server. Since Cloud attachments show a partial association, you should create a subdomain like onedrive.microsoft. * To make attachments look less suspicious.

2. Store files on the server

3. Set up HTTP to redirect a path ending with a harmless extension (.txt, .pdf, .docx, etc.) to your malicious executable. This is extremely important because as we will see Office 365 chooses the icon of the attachment based on the file extension of the link. In my case, I will set up a redirect from /test/testfile.pdf to /evil.exe.

Phishing method by attaching malicious files on Office 365 12

Attach malicious files

Compose an email to the victim, click the attachment icon > Browse Cloud Locations.

Phishing method by attaching malicious files on Office 365 13

Next, choose any random file to attach. This file can be anything.Phishing method by attaching malicious files on Office 365 14

Make sure you select the ‘Share as a OneDrive link’ option. This is the option to attach files as cloud attachments.

Phishing method by attaching malicious files on Office 365 15

Immediately intercept requests and modify location URLs. Set it as a harmless extension URL that redirects to a malicious file, in this case /test/testfile.pdf.

Phishing method by attaching malicious files on Office 365 16

When the email is sent to the victim, all they see is a PDF attachment and they will have no reason to assume it’s malicious. But when the attachment is clicked, the malicious file is downloaded.

Phishing method by attaching malicious files on Office 365 17

Phishing by attaching malicious cloud files

Conclude

This is a really useful technique when trying to gain initial access. An added benefit of using this technique is that the link is not scanned and thus increases the likelihood of the email reaching the victim’s inbox.

In addition, you can also attach the Virus contract to the Word file here.

Rate this post

Tags: attachingfilesmaliciousMethodOfficePhishing
Previous Post

Create funny cat paw prints on Google on International Cat Day

Next Post

2 ways to turn sketches into 3D color images

AnonyViet

AnonyViet

Related Posts

How to implement Shellcode Injection attack technique with Autoit
Security

How to implement Shellcode Injection attack technique with Autoit

March 14, 2025
How to exploit the holy hole of Hijacking on Windows
Security

How to exploit the holy hole of Hijacking on Windows

March 8, 2025
Hamamal: Shellcode execution technique from afar to overcome Antivirus's discovery
Security

Hamamal: Shellcode execution technique from afar to overcome Antivirus's discovery

February 10, 2025
Snov.io Email Finder: Search emails with only company name/domain name/LinkedIn profile
Security

Snov.io Email Finder: Search emails with only company name/domain name/LinkedIn profile

December 14, 2024
Capsolver: Automatic solution solution for business
Security

Capsolver: Automatic solution solution for business

December 12, 2024
Seekr: Collect & manage OSINT data
Security

Seekr: Collect & manage OSINT data

November 22, 2024
Next Post
2 ways to turn sketches into 3D color images

2 ways to turn sketches into 3D color images

0 0 votes
Article Rating
Subscribe
Login
Notify of
guest

guest

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Recent News

Discover Supermix – Smart playlist on YouTube Music

Discover Supermix – Smart playlist on YouTube Music

May 20, 2025
The 10 best Torrent websites today – 100% still operate

The 10 best Torrent websites today – 100% still operate

May 20, 2025
Share Code Shop Selling Acc game extremely lightweight written in bootstrap

Share Code Shop Selling Acc game extremely lightweight written in bootstrap

May 19, 2025
Instructions for downloading all photos and story from Instagram

Instructions for downloading all photos and story from Instagram

May 19, 2025
Discover Supermix – Smart playlist on YouTube Music

Discover Supermix – Smart playlist on YouTube Music

May 20, 2025
The 10 best Torrent websites today – 100% still operate

The 10 best Torrent websites today – 100% still operate

May 20, 2025
Share Code Shop Selling Acc game extremely lightweight written in bootstrap

Share Code Shop Selling Acc game extremely lightweight written in bootstrap

May 19, 2025
AnonyViet - English Version

AnonyViet

AnonyViet is a website share knowledge that you have never learned in school!

We are ready to welcome your comments, as well as your articles sent to AnonyViet.

Follow Us

Contact:

Email: anonyviet.com[@]gmail.com

Main Website: https://anonyviet.com

Recent News

Discover Supermix – Smart playlist on YouTube Music

Discover Supermix – Smart playlist on YouTube Music

May 20, 2025
The 10 best Torrent websites today – 100% still operate

The 10 best Torrent websites today – 100% still operate

May 20, 2025
  • Home
  • Home 2
  • Home 3
  • Home 4
  • Home 5
  • Home 6
  • Next Dest Page
  • Sample Page

©2024 AnonyVietFor Knowledge kqxs hôm nay xem phim miễn phí SHBET bongdaso

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply
No Result
View All Result
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office

©2024 AnonyVietFor Knowledge kqxs hôm nay xem phim miễn phí SHBET bongdaso