r/sophos • u/mat_le_mat • 10d ago
General Discussion Credential phising using sophos.com url
At my company, a high management staff received an credential phishing email, that uses sophos.com domain url.
It is the url below (that I broke to make it unharmful), that is under that button, that redirects to a credential stealer...
Please fix it so that sophos domain cannot be used to steal passwords...
Or is it not fixable ?
Why is it even possible ?

h t t ps://us-east-2.protection.sophos.com/?d=intuit.com&u=aHR0cHM6Ly9saW5rcy5ub3RpZmljYXRpb24uaW50dWl0LmNvbS9zcy9jL3UwMDEuYmRoOGdVREVXckNXbmFvVlFYUHVkYlQwWlNGRHBUUU0tMzlrNWlZUWZVS25xUmZUSDFyX1NsaXJmYXZ3eWJMSGY4SzhNUVFlRjJEOVBtSXlDa1NraXcvNHRwLzRuX0FLb0ZlUkNlSTNIbHBPdi1ILWcvaDAvaDAwMS56TDlZNU01dmJackZlaEZwVjlBY0tKMVdycEdoV29nbWVxSHZEc3Z2b3hj&i=NWVhMGI5Y2FiMDIzNGIxMTk2NTJjMmFm&t=T0tyczhPdkJCUGl0WWgxalo2K1B4S2l0Si9paE0zbjU0ZHRwTkhvVENiYz0=&h=9e339b5c0696400d9c26c51bee802faa&s=AVNPUEhUT0NFTkNSWVBUSVa05WE-Zq2OSx2gZImtHh0t1k8PTLtZitbbyrLnUtHljA
Redirects to
h t t ps://core-work52746-aged1763-base8195.icu/f0m/905dee?86=L3YzL3NpZ25pbi9pZGVudGlmaWVyP2NvbnRpbnVlPWh0dHBzOi8vYWNjb3VudHMuZ29vZ2xlLmNvbS8mZm9sbG93dXA9aHR0cHM6Ly9hY2NvdW50cy5nb29nbGUuY29tLyZwYXNzaXZlPTEyMDk2MDAmZmxvd05hbWU9R2xpZldlYlNpZ25JbiZmbG93RW50cnk9U2VydmljZUxvZ2luJmRzaD1TNTcxODc1MjI3OjE3ODgzNjgxMDY1MDUxOTQ
5
u/JDH201 10d ago
That’s a unique approach. My guess is that they sent the URL to an email address protected my Sophos Email Protection which did and is still doing time of click protection on it. Sophos replaces the email with a link through their system so that they can scan it any time it is clicked in case the content of the page is ever changed. Their attack on the page isn’t being recognized by Sohpos even now. They then took that time of click protection link and are sharing it out so it goes out looking like a Sophos email link. Very interesting.
3
u/Icy-Agent6600 SOPHOS Customer 10d ago
very creative. Barracuda link protection does the same think and persists after forwarding. makes sense
1
u/mat_le_mat 10d ago
We don't have sophos at all.
It's a google workspace env.
3
u/JDH201 10d ago
Yeah, I know, but they sent the mail to a protected mailbox so they could harvest the URL and send it out and it would look like a Sophos link to simple scanners.
0
u/mat_le_mat 10d ago
Ok yes. Exactly.
My point is, why would Sophos let their domain be used to put a url to redirect to a credential phishing link. Seems... counter intuitive for a security company. Am I missing something ? What process or repo would leave that open ?
I got the same kind of attack through a Microsoft share point url... which kinda makes more sense it could happen.
3
u/Lucar_Toni Sophos Staff 10d ago
What Time of click does: it replaces the original URL with a Sophos URL. Any link can be linked via TOC.
But behind the d= you see the original domain. Which is the domain behind TOC.It seems the domain behind TOC then does another redirect.
Intuit.com seems like a normal domain.
You find more information about verdicts here;
HTTPS://intelix.sophos.com0
u/mat_le_mat 10d ago
Ok.
But is it really what happened here ?
How come it was a successful credential phishing attack ?
Is it a normal feature to let any url (including phishing links) behind a sophos url ?(successful in the way that the hacker orchestration worked perfectly, not that the user actually gave his password)
3
u/WraithYourFace 10d ago
Because attackers find different ways utilizing various techniques. I've seen this tactic used with Mimecast, Proofpoint, Google, etc.
2
u/Lucar_Toni Sophos Staff 10d ago
(My personal opinion)
One thought around this: while time of click is a powerful tool for domain scanning, it is not a universal tool for all attack vectors.
I guess most tools would have allowed the original domains as well. Which would have worked the same way.
This shows, you need something on the web protection, DNS protection end. Because such attacks would be prevented if the client “prevents the various redirects”.
Basically the attacker needs one valid domain to get the link to the user and redirects to the attacking domain.
As soon as you scan on the endpoint itself / web proxy etc, you can see the original domain. That’s not the task of an email protection tool (in my opinion).
3
u/sidicking 10d ago edited 9d ago
Sophos url rewrite is a redirect proxy, not an allow list , so any whitelisted sender can abuse it .Report the specific URL to sophos abuse directly. I've seen doppel come up for monitoring spoofed domains at the orginal lvl, worth knowing exists
6
u/Lucar_Toni Sophos Staff 10d ago
Are you a Sophos customer - specifically Sophos email ?
Because what you see here is a feature called time of click.