Rewterz
Rewterz Threat Advisory – Microsoft Windows Server 2016 / Windows 10 Multiple Vulnerabilities
December 18, 2018
Rewterz
Rewterz Threat Advisory – A Second Sample of the Shamoon V3 Wiper
December 19, 2018

Rewterz Threat Advisory – Phishing Attack faking an Office 365 Non-Delivery Email

SEVERITY: HIGH

 

 

CATEGORY: PHISHING

 

 

PUBLISH DATE: DECEMBER 18, 2018

 

 

ANALYSIS SUMMARY

 

 

A phishing email campaign has been discovered that pretends to be a non delivery notification from Microsoft Office 365 in an attempt to steal you login credentials. The user will see a message of “Several Messages Undelivered” and prompts the user to click on the “Send Again” link in an order to try to send the emails again.

 

The phishing email would look like this.

 

 

 

 

After clicking on the “Send Again” link it’ll redirect you to a phishing site that look alike a legitimate Office 365 login page. The link will end with #[emailaddress], for example #@john@doe.com, which will cause the email address to auto-populate.

The phishing site would look like this.

 

 

 

 

When a user enters their password, a JavaScript function called sendmails() will send the email address and entered
password to the sendx.php script and then redirect you to the legitimate https://outlook.office365.com/owa/?real Office 365 login URL.

 

 

IMPACT:

 

 

Exposure of credentials

 

 

AFFECTED PRODUCTS:

 

 

Microsoft Office 365

 

 

THREAT INDICATORS:

 

 

Email subject: Several Undelivered Messages

 

 

REMEDIATION:

 

 

As end users, always look out for the correct site. A URL would be the most stand out thing when you’re entering your credentials because phishing are more common, deceptive and potentially harder to notice and users would enter their credentials by seeing a look-alike login page.