huntresslabs / rogueapps

When good OAuth apps go rogue. Documents observed OAuth application tradecraft
https://huntresslabs.github.io/rogueapps/
Mozilla Public License 2.0
77 stars 9 forks source link

[New RogueApp]: Zoominfo Login #9

Open HuskyHacks opened 10 months ago

HuskyHacks commented 10 months ago

⚠️ Please include as much detail as possible. Please do not submit any private, sensitive, and/or proprietary information.

Reference

The RogueApp specification is defined in types.ts. Please submit as much information as you can for each field (it does not have to be 100% complete but please submit everything you can!)

syne0 commented 5 months ago

Contributor Name: Syne0 RogueApp Name: ZoomInfo Login RogueApp Description: ZoomInfo is a business intelligence platform that contains a large database of company and contact information. It is possible to use ZoomInfo via SSO with a Microsoft365 account, which creates this service principal within a tenant. App ID: 858d7e42-35f0-44b7-9033-df309239a4f7 App Owner Organization ID: 945a9641-35c7-435c-a5a0-c8753e6dff88 App Publisher Name: App Publisher ID: Permissions: Microsoft Graph: User.Read (Delegated) Microsoft Graph: email (Delegated) Microsoft Graph: openid (Delegated) Microsoft Graph: profile (Delegated) Tags: persistence MITRE ATT&CK IDs: T1136.003 References: https://cybercorner.tech/common-oauth-apps-used-in-business-email-compromise/#ZoomInfo, https://abnormalsecurity.com/blog/cybercriminals-exploit-b2b-lead-generation-tools Date Added: [the date when the RogueApp was added to the repository]