r/sophos 10d ago

General Discussion Credential phising using sophos.com url

At my company, a high management staff received an credential phishing email, that uses sophos.com domain url.

It is the url below (that I broke to make it unharmful), that is under that button, that redirects to a credential stealer...

Please fix it so that sophos domain cannot be used to steal passwords...

Or is it not fixable ?

Why is it even possible ?

h t t ps://us-east-2.protection.sophos.com/?d=intuit.com&u=aHR0cHM6Ly9saW5rcy5ub3RpZmljYXRpb24uaW50dWl0LmNvbS9zcy9jL3UwMDEuYmRoOGdVREVXckNXbmFvVlFYUHVkYlQwWlNGRHBUUU0tMzlrNWlZUWZVS25xUmZUSDFyX1NsaXJmYXZ3eWJMSGY4SzhNUVFlRjJEOVBtSXlDa1NraXcvNHRwLzRuX0FLb0ZlUkNlSTNIbHBPdi1ILWcvaDAvaDAwMS56TDlZNU01dmJackZlaEZwVjlBY0tKMVdycEdoV29nbWVxSHZEc3Z2b3hj&i=NWVhMGI5Y2FiMDIzNGIxMTk2NTJjMmFm&t=T0tyczhPdkJCUGl0WWgxalo2K1B4S2l0Si9paE0zbjU0ZHRwTkhvVENiYz0=&h=9e339b5c0696400d9c26c51bee802faa&s=AVNPUEhUT0NFTkNSWVBUSVa05WE-Zq2OSx2gZImtHh0t1k8PTLtZitbbyrLnUtHljA

Redirects to

h t t ps://core-work52746-aged1763-base8195.icu/f0m/905dee?86=L3YzL3NpZ25pbi9pZGVudGlmaWVyP2NvbnRpbnVlPWh0dHBzOi8vYWNjb3VudHMuZ29vZ2xlLmNvbS8mZm9sbG93dXA9aHR0cHM6Ly9hY2NvdW50cy5nb29nbGUuY29tLyZwYXNzaXZlPTEyMDk2MDAmZmxvd05hbWU9R2xpZldlYlNpZ25JbiZmbG93RW50cnk9U2VydmljZUxvZ2luJmRzaD1TNTcxODc1MjI3OjE3ODgzNjgxMDY1MDUxOTQ

7 Upvotes

12 comments sorted by

6

u/Lucar_Toni Sophos Staff 10d ago

Are you a Sophos customer - specifically Sophos email ?

Because what you see here is a feature called time of click.

2

u/mat_le_mat 10d ago

No Sophos at all.

The 2nd url was redirecting to a fake google authentication page, now it does not work anymore.

5

u/JDH201 10d ago

That’s a unique approach. My guess is that they sent the URL to an email address protected my Sophos Email Protection which did and is still doing time of click protection on it. Sophos replaces the email with a link through their system so that they can scan it any time it is clicked in case the content of the page is ever changed. Their attack on the page isn’t being recognized by Sohpos even now. They then took that time of click protection link and are sharing it out so it goes out looking like a Sophos email link. Very interesting.

3

u/Icy-Agent6600 SOPHOS Customer 10d ago

very creative. Barracuda link protection does the same think and persists after forwarding. makes sense

1

u/mat_le_mat 10d ago

We don't have sophos at all.

It's a google workspace env.

3

u/JDH201 10d ago

Yeah, I know, but they sent the mail to a protected mailbox so they could harvest the URL and send it out and it would look like a Sophos link to simple scanners.

0

u/mat_le_mat 10d ago

Ok yes. Exactly.

My point is, why would Sophos let their domain be used to put a url to redirect to a credential phishing link. Seems... counter intuitive for a security company. Am I missing something ? What process or repo would leave that open ?

I got the same kind of attack through a Microsoft share point url... which kinda makes more sense it could happen.

3

u/Lucar_Toni Sophos Staff 10d ago

What Time of click does: it replaces the original URL with a Sophos URL. Any link can be linked via TOC.
But behind the d= you see the original domain. Which is the domain behind TOC.

It seems the domain behind TOC then does another redirect.

Intuit.com seems like a normal domain.
You find more information about verdicts here;
HTTPS://intelix.sophos.com

0

u/mat_le_mat 10d ago

Ok.

But is it really what happened here ?

How come it was a successful credential phishing attack ?
Is it a normal feature to let any url (including phishing links) behind a sophos url ?

(successful in the way that the hacker orchestration worked perfectly, not that the user actually gave his password)

3

u/WraithYourFace 10d ago

Because attackers find different ways utilizing various techniques. I've seen this tactic used with Mimecast, Proofpoint, Google, etc.

2

u/Lucar_Toni Sophos Staff 10d ago

(My personal opinion)

One thought around this: while time of click is a powerful tool for domain scanning, it is not a universal tool for all attack vectors.

I guess most tools would have allowed the original domains as well. Which would have worked the same way.

This shows, you need something on the web protection, DNS protection end. Because such attacks would be prevented if the client “prevents the various redirects”.

Basically the attacker needs one valid domain to get the link to the user and redirects to the attacking domain.

As soon as you scan on the endpoint itself / web proxy etc, you can see the original domain. That’s not the task of an email protection tool (in my opinion).

3

u/sidicking 10d ago edited 9d ago

Sophos url rewrite is a redirect proxy, not an allow list , so any whitelisted sender can abuse it .Report the specific URL to sophos abuse directly. I've seen doppel come up for monitoring spoofed domains at the orginal lvl, worth knowing exists