Rewterz
Rewterz Threat Advisory – CVE-2019-5842 – Google Chrome Blink Use-After-Free Vulnerability
June 17, 2019
Rewterz
Rewterz Threat Advisory – Linux Kernel Multiple Denial of Service Vulnerabilities
June 18, 2019

Rewterz Threat Alert – Agent Tesla Email Campaign Stealing Information

Severity

Medium

Analysis Summary


An email campaign discovered distributing the Agent Tesla malware. A potential victim receives an email with a subject of “Re: Revised INV/ GF76370-7478-465”. The sender was observed as “Weifang Huaxing admin[@]infozcn[.]com”. Within the body of the email, the adversary attempts to entice a user to open the attachment “INV-GF76370-7478-465.cab” to review the order. The infection process begins once the .cab attachment is opened (which extracts to INV-GF76370-7478-465.exe) ultimately leading to the Agent Tesla keylogger / infostealer being installed on the victim’s system. It is interesting to note that the email server (infozcn.com) does match where the sender claimed to have sent the message from, according to analysis of the email headers. This helped the email to pass through most authentication checks undetected.

Impact

Infostealer keylogger

Indicators of Compromise

Filename

INV-GF76370-7478-465.cab

Email Address

admin@infozcn[.]com

Email Subject

Re: Revised INV/ GF76370-7478-465

Malware Hash (MD5/SHA1/SH256)

  • 8e69c2cc66803246bc16bba746b17afa08aacc37d751857fa8ad0653b08f0771
  • b6dcffb6187476b0bfcc3bea59b56155ff0d0e02fd8aca6ae1d2d9baa02b1031
  • 88187071e1f8b6f17b093888a03ed574a39bb84f
  • 80217c27c16ed71c1d9f29b4d456f9f2

Remediation

  • Block all threat indicators at your respective controls
  • Always be suspicious about emails sent by unknown senders
  • Never click on the link/ attachments sent by the unknown senders