Rewterz
Rewterz Threat Advisory – BlueKeep (CVE 2019-0708) Exploitation Spotted in the Wild
November 4, 2019
Rewterz
Rewterz Threat Alert – Hawkeye Keylogger too Exploits CVE-2017-11882 after Rattlesnake
November 4, 2019

Rewterz Threat Alert – Office 365 Phishing Campaign Baits Employees with Pay Raises

Severity

Medium

Analysis Summary

Pay raises were used by scammers to bait employees in a recent phishing campaign that tried to trick them into handing out their Microsoft Office 365 account credentials. The attackers posed as their targets’ Human Resources department and asked them to open an Excel spreadsheet with a salary-increase-sheet-November-2019.xls filename hosted online and supposedly containing a list of salary increases. The email body says:

As already announced, The Years Wage increase will start in November 2019 and will be paid out for the first time in December, with recalculation as of November.”

Phishing email sample

However, instead of opening the spreadsheet with payment raises, the link will redirect the potential victims to the attackers’ phishing landing page hosted at hxxps://salary365[.]web[.]app/#/auth-pass-form/. Once the phishing page loads, the targets will see a fake Office 365 login page customized to display their email address and only asking them to input the password to sign in.

Impact

  • Credential Theft
  • Unauthorized Access

Indicators of Compromise

Filename

salary-increase-sheet-November-2019.xls

Source IP

151.101.65[.]195

URL

hxxps://salary365[.]web[.]app/#/auth-pass-form/

Remediation

  • Block the threat indicators at their respective controls.
  • Do not click on URLs attached in untrusted emails.
  • Do not enter credentials on websites that you’re redirected to via random links.
  • Enable multi-factor authentication via Office 365 or a third-party solution for all employees.