[1] https://docs.microsoft.com/en-us/onedrive/developer/rest-api...
contained in driveItems and other responses:
https://docs.microsoft.com/en-us/onedrive/developer/rest-api...
I have. It hasn't been what you suggest.
You're not wrong you could host somewhere encrypted and escape detection. But that means you still need to point to a scam site to execute the package.
But the way this works is that you're sent an email with a legit Microsoft domain. Sometimes even a legit Microsoft Share email that points to a onedrive stored file.
The whole point is that your payload is hosted on a legit service that Apple, Dropbox, Microsoft, etc really do own. So that if you're trained to look at the URL, you see something legit, not share.filez-mikrozoft.kom
I've had to instruct my employees to look at the context, not just the hosting link. Do you know this person? Where you expecting a file? If you aren't sure can you contact them via some other form than email?
I think I remember reading something about how dropbox was being used by security researchers where they were storing known-bad files, and how Dropbox mitigated this risk
I guess it's good news for Microsoft, though: people are aware of OneDrive!
Its saying, for the selected quarters, what percentage of traffic was malicious.
Ex:
* In Q4 2018, less than 20% (out of 100%) of wetransfer's traffic was marked as malicious.
* In Q1 2019, over 60% (out of 100%) of OneDrive's traffic was marked as malicious.
Etc.
That said the title doesn't really make sense "File share services being used to host attacks" should probably be something more like "percentage of increase in files that are malicious" or some such.
If you want to trick someone into running an executable, you need to put it on a whitelisted site, otherwise they will have to slog through 5 different very scary warnings before they are allowed to run it.
The funny thing: most of HN is against this kind of browser protection, I wouldn't be surprised if they disable uncommon software warnings.
I might expect them to be whitelisted by firewalls, but why browsers?
1> Microsoft sees successful tool and decides to copy it 2> truck loads of marketing money is spent 3> the product captures 5-10% of the market 4> most people either don't care or mock it 5> at some point articles come out about how the product is mostly malware 6> Microsoft quietly kills the product 2 years later