Rewterz
Rewterz Threat Alert – Recent QakBot Malspam Activity
December 10, 2020
Rewterz
Rewterz Threat Alert – SideWinder APT Active in South Asia
December 10, 2020

Rewterz Threat Alert – Phishing Email Using ‘Low Storage Warning’ as Lure

Severity

Medium

Analysis Summary

A new phishing campaign has been detected that uses malspam to lure victims. The email content of this malspam campaign tries to scare the user that their mailbox is almost full. It further asserts that the webmaster Incoming and outgoing messages of the user will be placed on hold if no further action is taken. The email also offers the users to increase their mailbox size. Attached in the email is a URL that is to be used in order to increase the size of the mailbox to avoid being shutdown. The page is likely to be a fake login page to harvest credentials.

Impact

Credential Theft

Indicators of Compromise

Domain Name

  • wondryve[.]web[.]app

Email Subject

  • Warning – Email storage Low

From Email

  • support@astoria-pl[.]com

URL

  • https[:]//wondryve[.]web[.]app/in/index[.]html/webmaster[.]georgialibraries[.]org

Remediation

  • Block the threat indicators at their respective controls.
  • Do not click on URLs attached in untrusted emails.
  • Enable multi-factor authentication where possible.