Rewterz

Rewterz Threat Advisory – CVE-2019-5842 – Google Chrome Blink Use-After-Free Vulnerability

June 17, 2019
Rewterz

Rewterz Threat Advisory – Linux Kernel Multiple Denial of Service Vulnerabilities

June 18, 2019

Rewterz Threat Alert – Agent Tesla Email Campaign Stealing Information

Severity

Medium

Analysis Summary


An email campaign discovered distributing the Agent Tesla malware. A potential victim receives an email with a subject of “Re: Revised INV/ GF76370-7478-465”. The sender was observed as “Weifang Huaxing admin[@]infozcn[.]com”. Within the body of the email, the adversary attempts to entice a user to open the attachment “INV-GF76370-7478-465.cab” to review the order. The infection process begins once the .cab attachment is opened (which extracts to INV-GF76370-7478-465.exe) ultimately leading to the Agent Tesla keylogger / infostealer being installed on the victim’s system. It is interesting to note that the email server (infozcn.com) does match where the sender claimed to have sent the message from, according to analysis of the email headers. This helped the email to pass through most authentication checks undetected.

Impact

Infostealer keylogger

Indicators of Compromise

Filename

INV-GF76370-7478-465.cab

Email Address

admin@infozcn[.]com

Email Subject

Re: Revised INV/ GF76370-7478-465

Malware Hash (MD5/SHA1/SH256)

  • 8e69c2cc66803246bc16bba746b17afa08aacc37d751857fa8ad0653b08f0771
  • b6dcffb6187476b0bfcc3bea59b56155ff0d0e02fd8aca6ae1d2d9baa02b1031
  • 88187071e1f8b6f17b093888a03ed574a39bb84f
  • 80217c27c16ed71c1d9f29b4d456f9f2

Remediation

  • Block all threat indicators at your respective controls
  • Always be suspicious about emails sent by unknown senders
  • Never click on the link/ attachments sent by the unknown senders

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.