Rewterz Threat Alert – Amazon Phishing Scam Creates Login Prompts in PDF Docs

Friday, August 9, 2019

Severity

Medium

Analysis Summary

A phishing campaign using JavaScript embedded in PDFs to steal credentials. The campaign began with a German-language email masquerading as a tax invoice notification from Amazon Seller Central. The sender name is spoofed to appear to come from the legitimate Amazon DE marketplace. Attached to the email is a PDF that claims to require you to log into your Seller Central account to view the contents of the document. Within the PDF there is embedded JavaScript attached to the login prompt. The JavaScript is responsible for capturing the provided credentials and sending them in plain text to a remote server. While this is a simple phishing attempt like other traditional phishing emails, using a document-based vector avoids having to trick users into clicking on suspicious links, which is becoming more difficult as user awareness increases.

Impact

Credential theft

Indicators of Compromise

URLs

  • http[:]//sellercentral[.]amazon[.]de[.]56U8GTHDGT4U7YWEWE84GTYS[.]abecklink[.]com/step1[.]php
  • http[:]//sellercentral[.]amazon[.]de[.]56U8GTHDGT4U7YWEWE84GTYS[.]abecklink[.]com


Malware Hash (MD5/SHA1/SH256)

3078674d0a85602c12e70d795c1579f18513fcd1a740c638f49b121b853d07be

Remediation

  • Block all threat indicators at your respective controls.
  • Always be suspicious about emails sent by unknown senders.
  • Never click on the links/attachments sent by unknown senders.

Data Sheets

Corporate Brochure


Our Story


Services


Solutions


Managed Security


Upcoming Rewterz Trainings/Events

Rewterz News

  • 20, November 2019 Rewterz Threat Alert – Malspam Campaigns Spreading Dridex Banking Trojan
  • 20, November 2019 Rewterz Threat Alert – McDonalds-Themed Facebook Malvertising Deploys Mispadu Banking Trojan
  • 19, November 2019 Rewterz Threat Alert – Active Exploitation of Firefox 0-Day Targets Cryptocurrency
  • 19, November 2019 Rewterz Threat Alert – Buran Ransomware Infects PCs via Microsoft Excel Web Queries

Copyright © Rewterz. All rights reserved.