flâneur — a map of the web's best reading

Malicious Azure Application PERFECTDATA SOFTWARE and Microsoft 365 Business Email Compromise – Syne's Cyber Corner

cybercorner.tech · 1,482 words · saved by 1 readers

If you have found your way to this page, you likely discovered a suspicious application consent within your Azure AD tenant for an app called PERFECTDATA SOFTWARE. Concerned, you googled the application (and perhaps even its Application ID ff8d92dc-3d82-41d6-bcbd-b9174d163620) looking for information. As of the time of writing, two other results on Google involve this software and BEC. If you haven’t, I encourage you to read this darktrace.com article which goes further in-depth into a Microsoft 365 business email compromise (BEC). Unfortunately, Darktrace was unable to conclusively determine the purpose of the application consent. Luckily I have been able to find the application and examine its behavior. First, if you are seeing this application in your tenant and it’s not approved, I have some bad news. This application is used to take a backup of the entire mailbox from the cloud and export it to PST. Assume that everything within the mailbox is lost, and any useful information will

Posted in Azure AD Forensics Incident Response Office 365 Posted by By syne0 July 10, 2023 22 Comments Edit 04/13/25: The newest version of the software behind this application has changed. Now, the application’s name within a tenant will be Mail_Backup. The app id is now 2ef68ccc-8a4d-42ff-ae88-2d7bb89ad139. Most of the information contained in this article is still accurate. Please view this post for up-to-date IOCs and permissions for this app. If you have found your way to this page, you likely discovered a suspicious application consent within your Azure AD tenant for an app called

Explore this link on the map →

saved by

related reading