Rewterz
Rewterz Threat Alert – Lazarus APT Group Targeting China – IOCs
May 27, 2021
Rewterz
Rewterz Threat Advisory – CVE-2021-22543 – Linux Kernel Privilege Escalation
May 27, 2021

Rewterz Threat Alert – Microsoft Outlook and SharePoint Web Phishing – IOCs

Severity

Medium

Analysis Summary

Threat actors are actively dropping phishing emails impersonating Microsoft Outlook app and robbing off credentials of the users with their tactics. This has been the latest ongoing phishing campaign actively targeting multiple organizations by impersonating Microsoft Outlook and Sharepoint. When the targeted victims click on links attached in the emails, they are redirected to fake login pages from where their credentials are stolen and sent to the threat actors. Like previous campaigns, this one is also aimed at credential theft.

Impact

  • Credential Theft
  • Information Disclosure

Affected Vendors

Microsoft

Affected Products

  • Microsoft Outlook
  • Microsoft SharePoint

Indicators of Compromise

URL

https[:]//jazonbucket564[.]s3[.]eu-de[.]cloud-object-storage[.]appdomain[.]cloud/avoue/index[.]php
https[:]//drive[.]google[.]com/file/d/1YKP4Uq2jjXZbuKaZqmU4YwyG5O499DP5/view

Remediation

  • Block the threat indicators at their respective controls.
  • Do not download files attached in untrusted emails.
  • Do not click on links given in untrusted emails.
  • Verify familiar domains and URLs and look for typos, before clicking on them.