

Rewterz Threat Advisory – Microsoft Windows Server 2016 / Windows 10 Multiple Vulnerabilities
December 18, 2018
Rewterz Threat Advisory – A Second Sample of the Shamoon V3 Wiper
December 19, 2018
Rewterz Threat Advisory – Microsoft Windows Server 2016 / Windows 10 Multiple Vulnerabilities
December 18, 2018
Rewterz Threat Advisory – A Second Sample of the Shamoon V3 Wiper
December 19, 2018SEVERITY: HIGH
CATEGORY: PHISHING
PUBLISH DATE: DECEMBER 18, 2018
ANALYSIS SUMMARY
A phishing email campaign has been discovered that pretends to be a non delivery notification from Microsoft Office 365 in an attempt to steal you login credentials. The user will see a message of “Several Messages Undelivered” and prompts the user to click on the “Send Again” link in an order to try to send the emails again.
The phishing email would look like this.
After clicking on the “Send Again” link it’ll redirect you to a phishing site that look alike a legitimate Office 365 login page. The link will end with #[emailaddress], for example #@john@doe.com, which will cause the email address to auto-populate.
The phishing site would look like this.
When a user enters their password, a JavaScript function called sendmails() will send the email address and entered
password to the sendx.php script and then redirect you to the legitimate https://outlook.office365.com/owa/?real Office 365 login URL.
IMPACT:
Exposure of credentials
AFFECTED PRODUCTS:
Microsoft Office 365
THREAT INDICATORS:
Email subject: Several Undelivered Messages
REMEDIATION:
As end users, always look out for the correct site. A URL would be the most stand out thing when you’re entering your credentials because phishing are more common, deceptive and potentially harder to notice and users would enter their credentials by seeing a look-alike login page.