Rewterz
Rewterz Threat Advisory – CVE-2021-28918 – Critical Netmask Networking Bug Impacts Thousands of Applications
March 29, 2021
Rewterz
Rewterz Threat Alert – Nanocore – IoCs
March 29, 2021

Rewterz Threat Alert – Microsoft Outlook Web Phishing – IoCs

Severity

Medium

Analysis Summary

Threat actors are actively dropping phishing emails impersonating Microsoft Outlook app and robbing off credentials of the users with their tactics. This has been the latest ongoing phishing campaign actively targeting multiple organizations by impersonating Microsoft Outlook. When the targeted victims click on links attached in the emails, they are redirected to fake login pages from where their credentials are stolen and sent to the threat actors. Like previous campaigns, this one is also aimed at credential theft.

Impact

  • Credential Theft
  • Information Disclosure

Indicators of Compromise

From Email

  • scheneider18@hotmail[.]com
  • soporrte-microsofft-2020@outlook[.]com

MD5

  • f15a2fde9ef79d2213c16347a86acfb8
  • f3334dc0fb52217fd710d0e467b26ade
  • b3f7e17ae3124338d187d6ad283c3262

SHA-256

  • a00bc18d3229c7afe7a6792244af2ced420193eb0898b7db41a2d39fd3ccd8b1
  • 2dd252d9a0901bc636236b26503d4bb2e14958025bc8e8284c9d3a8c0b1fe817
  • d3ff86a7924f88cd15ff18ca5073d055c3f7a08ce9459714a81eaee4888942dd

SHA1

  • b2561dc15d46c599229e4bd0efeb31aa73206320
  • 54161a6dccefeb98fba341a87501465dd3d3871c
  • 0a4add693c097e79098ddd8b523c1bf7ca1b2207

URL

  • https[:]//soportluing[.]wixsite[.]com/soport

Remediation

  • Block the threat indicators at their respective controls.
  • Do not download files attached in untrusted emails.
  • Do not click on links given in untrusted emails.
  • Verify familiar domains and URLs and look for typos, before clicking on them.