Rewterz Threat Advisory – CVE-2020-4336 – IBM WebSphere eXtreme Scale information disclosure
January 7, 2021Rewterz Threat Alert – Emotet is Back – Fresh IOCs
January 7, 2021Rewterz Threat Advisory – CVE-2020-4336 – IBM WebSphere eXtreme Scale information disclosure
January 7, 2021Rewterz Threat Alert – Emotet is Back – Fresh IOCs
January 7, 2021Severity
Medium
Analysis Summary
Phishing is the fraudulent attempt to obtain sensitive information or data, such as usernames, passwords and credit card
details. This is done by disguising oneself as trustworthy communication to obtain information which can be used against the user. Phishing activities are almost ongoing across the world and is the most common source of attack used against the victims to lure them to click on the malicious attachments. The URLs, email subjects, filenames are made in such manner where the user would feel the domain is legitimate and has no hesitation clicking on the attachment. This would lead the victim to land on the phishing page where the threat actor would gather the information and later on use against the victim.
Impact
- Credential theft
- Exposure of sensitive data
Indicators of Compromise
URL
- https[:]//espacemessagerie[.]wixsite[.]com/vocalmms
- http[:]//a0502525[.]xsph[.]ru/
- https[:]//orangegouv[.]weebly[.]com/
- https[:]//eloginonnecteplus[.]wixsite[.]com/monsite
- https[:]//bc28n[.]weblium[.]site/
- https[:]//alerts-eesupport[.]com/
- https[:]//paypalsupport-id-3587[.]com/
- https[:]//paypalsupportid-3587[.]com/users/userID-71994/en/season[.]php?country[.]x=b61dd72cf417e3ae3edac330d2e7f1dfb61dd72cf417e3ae3edac330d2e7f1df
- http[:]//u973315c4i[.]ha005[.]t[.]justns[.]ru/CH/i
- http[:]//u973315c4i[.]ha005[.]t[.]justns[.]ru/CH/e/?https[:]//account[.]post[.]ch/idp/?login&appb3bfa98bb68cb122e3027a8bfc3552d9?b3bfa98bb68cb122e3027a8bfc3552d9
- http[:]//a0502173[.]xsph[.]ru/activeaccount/EN/dc2JI22nEFfymcFtI0Ni3xO6AsddYBwd
Remediation
- Block all threat indicators at your respective controls.
- Always be suspicious about emails sent by unknown senders.
- Never click on links/attachments sent by unknown senders.