Malicious Azure Application PERFECTDATA SOFTWARE and Microsoft 365 Business Email Compromise – Syne's Cyber Corner
If you have found your way to this page, you likely discovered a suspicious application consent within your Azure AD tenant for an app called PERFECTDATA SOFTWARE. Concerned, you googled the application (and perhaps even its Application ID ff8d92dc-3d82-41d6-bcbd-b9174d163620) looking for information. As of the time of writing, two other results on Google involve this software and BEC. If you haven’t, I encourage you to read this darktrace.com article which goes further in-depth into a Microsoft 365 business email compromise (BEC). Unfortunately, Darktrace was unable to conclusively determine the purpose of the application consent. Luckily I have been able to find the application and examine its behavior. First, if you are seeing this application in your tenant and it’s not approved, I have some bad news. This application is used to take a backup of the entire mailbox from the cloud and export it to PST. Assume that everything within the mailbox is lost, and any useful information will
Posted in Azure AD Forensics Incident Response Office 365 Posted by By syne0 July 10, 2023 22 Comments Edit 04/13/25: The newest version of the software behind this application has changed. Now, the application’s name within a tenant will be Mail_Backup. The app id is now 2ef68ccc-8a4d-42ff-ae88-2d7bb89ad139. Most of the information contained in this article is still accurate. Please view this post for up-to-date IOCs and permissions for this app. If you have found your way to this page, you likely discovered a suspicious application consent within your Azure AD tenant for an app called
Explore this link on the map →saved by
related reading
- Common Oauth Apps Used in Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- Malicious Usage of eM Client In Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- PerfectData Software Abuse and Account Takeover Risksdarktrace.com
- Entra ID service principals in business email compromise schemes | Red Canaryredcanary.com
- Cloud coverage: Detecting an email payroll diversion attackredcanary.com
- Exposing and shutting down an inbox heist in actionredcanary.com
- When MFA isn’t an option: The legacy of ROPC | Red Canaryredcanary.com
- Legacy authentication: The curious case of BAV2ROPCredcanary.com
- Email Compromise To Mass Phishing Campaigndarktrace.com
- The Soze Syndicate - Business Email Compromise Campaign | Todyltodyl.com
- Revoke user access in an emergency in Microsoft Entra ID - Microsoft Entra ID | Microsoft Learnlearn.microsoft.com
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com