Skip to content
Syne's Cyber Corner

A Very Cool and Serious Website

  • Home
  • About
  • Home
  • About

PERFECTDATA SOFTWARE Rebrands to Mail_Backup

Posted by By syne0 April 10, 2025
The well-known abused Entra ID/Azure AD OAuth application PERFECTDATA SOFTWARE has now been renamed to Mail_Backup. The app ID and associated permissions have also changed. The prior article I wrote…
Read More

Common Oauth Apps Used in Business Email Compromise

Posted by By syne0 August 29, 2024
This article serves as another place to document some common (and not so common) Oauth applications that are abused for malicious purposes during a BEC. Some are well documented, while…
Read More

Malicious Usage of eM Client In Business Email Compromise

Posted by By syne0 January 31, 2024
If you've found your way to this article, it's likely because you have found a suspicious application content for eM Client. This is an application that is similar in it's…
Read More

The Million Dollar CEO Fraud: Anatomy of a Business Email Compromise

Posted by By syne0 September 27, 2023
This is the article version of my talk from BSides Edmonton & Calgary 2023. While the actual presentation is probably better, this one can serve as a decent overview. Some…
Read More

Gripes About Microsoft Expanding Audit Premium Availability

Posted by By syne0 September 13, 2023
The last few blog posts I've made have been more informative or educational, but this is my cybercorner so I will post what I want. I mentioned in my last…
Read More

Syne’s Declassified O365 Email Compromise Investigation Guide

Posted by By syne0 September 3, 2023
AKA newb's guide to investigating an email compromise. (Yes, I did spend 3x the amount of time making that image then I did writing the article, what about it??) Disclaimer…
Read More

Malicious Azure Application PERFECTDATA SOFTWARE and Microsoft 365 Business Email Compromise

Posted by By syne0 July 10, 2023
Edit 04/13/25: The newest version of the software behind this application has changed. Now, the application's name within a tenant will be Mail_Backup. The app id is now 2ef68ccc-8a4d-42ff-ae88-2d7bb89ad139. Most…
Read More

Recent Posts

  • PERFECTDATA SOFTWARE Rebrands to Mail_Backup
  • Osprey – An Alternative to the Hawk PowerShell Module for Email Compromise Investigations
  • Common Oauth Apps Used in Business Email Compromise
  • Redditor Gets Malware From Vibrator (& Why I think It’s a Hoax)
  • Malicious Usage of eM Client In Business Email Compromise

Supporters

Interested in having your name and your blog/project/social here? Join the membership on Ko-Fi.

Categories

  • Azure AD
  • Conferences
  • Featured
  • Forensics
  • Incident Response
  • Malware
  • Office 365
  • Shodan
Copyright 2025 — Syne's Cyber Corner. All rights reserved. Bloglo WordPress Theme
Scroll to Top