Rewterz
Rewterz Threat Advisory -IBM Security Guardium Multiple Vulnerabilities
March 8, 2019
Rewterz
Rewterz Threat Alert – Shipping Themed Malspam – IoCs
March 8, 2019

Rewterz Threat Alert – Three Phishing Campaigns Dropping the Emotet Malware – IoCs

Severity

Medium

Analysis Summary

Multiple Phishing campaigns have been observed. 

One of these is an in-voice themed phishing email from Bell Motors containing a .doc file that drops the Emotet malware. 

Two other Verizon-themed phishing emails have also been observed, being sent to multiple targets. These two campaigns use a slight variation of the email subject. These also drop the Emotet malware.

Impact

Emotet

Indicators of Compromise

Email Subject Bell Motors – Jessie – Invoice No. S8838
Thank you for your payment. – JB2279774781
Thank you for your payment

Remediation

Scan for these email subjects and block the email addresses if found.  

Do not download any files attached in such emails.

Do not click on any URLs provided in these emails.