Rewterz
Rewterz Threat Alert – Agent Tesla Malware – IOCs
July 6, 2020
Rewterz
Rewterz Threat Alert – Latest AZORult Malware – IOC’s
July 6, 2020

Rewterz Threat Alert – Phishing Emails Containing Calendar Invitations

Severity

Medium

Analysis Summary

A recently active phishing campaign targeting multiple enterprise email environments, has been sending emails, some from apparently compromised accounts, that use typical subject lines related to financial services such as, “Fraud Detection from Message Center”. The emails advise of suspicious activity related to the recipients bank account. Researchers says that the emails have a calendar invite file attached (.ics) that the recipient is asked to open. The invite contains a link to page on a Sharepoint.com site which claims to be information from Wells Fargo advising the recipient of new security measures being introduced. Clicking anywhere on that page finally directs the user to the actual phishing page which is hosted by Google. And no surprises, a Wells Fargo themed page provides fields in which to enter account details to login. Lastly if the victim enters the required information in the form, they will be redirected to an actual Wells Fargo login page. 

WM_Image-1.jpg.wm.jpg

Impact

  • Credential theft
  • Exposure of sensitive data 

Indicators of Compromise

Email Subject

Fraud Detection from Message Center

Remediation

  • Block all threat indicators at your respective controls.
  • Always be suspicious about emails sent by unknown senders.
  • Never click on the links/attachments sent by unknown senders.