Rewterz Threat Advisory – CVE-2019-5842 – Google Chrome Blink Use-After-Free Vulnerability
June 17, 2019Rewterz Threat Advisory – Linux Kernel Multiple Denial of Service Vulnerabilities
June 18, 2019Rewterz Threat Advisory – CVE-2019-5842 – Google Chrome Blink Use-After-Free Vulnerability
June 17, 2019Rewterz Threat Advisory – Linux Kernel Multiple Denial of Service Vulnerabilities
June 18, 2019Severity
Medium
Analysis Summary
An email campaign discovered distributing the Agent Tesla malware. A potential victim receives an email with a subject of “Re: Revised INV/ GF76370-7478-465”. The sender was observed as “Weifang Huaxing admin[@]infozcn[.]com”. Within the body of the email, the adversary attempts to entice a user to open the attachment “INV-GF76370-7478-465.cab” to review the order. The infection process begins once the .cab attachment is opened (which extracts to INV-GF76370-7478-465.exe) ultimately leading to the Agent Tesla keylogger / infostealer being installed on the victim’s system. It is interesting to note that the email server (infozcn.com) does match where the sender claimed to have sent the message from, according to analysis of the email headers. This helped the email to pass through most authentication checks undetected.
Impact
Infostealer keylogger
Indicators of Compromise
Filename
INV-GF76370-7478-465.cab
Email Address
admin@infozcn[.]com
Email Subject
Re: Revised INV/ GF76370-7478-465
Malware Hash (MD5/SHA1/SH256)
- 8e69c2cc66803246bc16bba746b17afa08aacc37d751857fa8ad0653b08f0771
- b6dcffb6187476b0bfcc3bea59b56155ff0d0e02fd8aca6ae1d2d9baa02b1031
- 88187071e1f8b6f17b093888a03ed574a39bb84f
- 80217c27c16ed71c1d9f29b4d456f9f2
Remediation
- Block all threat indicators at your respective controls
- Always be suspicious about emails sent by unknown senders
- Never click on the link/ attachments sent by the unknown senders