Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Severity
Medium
Analysis Summary
An email campaign discovered distributing the Agent Tesla malware. A potential victim receives an email with a subject of “Re: Revised INV/ GF76370-7478-465”. The sender was observed as “Weifang Huaxing admin[@]infozcn[.]com”. Within the body of the email, the adversary attempts to entice a user to open the attachment “INV-GF76370-7478-465.cab” to review the order. The infection process begins once the .cab attachment is opened (which extracts to INV-GF76370-7478-465.exe) ultimately leading to the Agent Tesla keylogger / infostealer being installed on the victim’s system. It is interesting to note that the email server (infozcn.com) does match where the sender claimed to have sent the message from, according to analysis of the email headers. This helped the email to pass through most authentication checks undetected.
Impact
Infostealer keylogger
Indicators of Compromise
Filename
INV-GF76370-7478-465.cab
Email Address
admin@infozcn[.]com
Email Subject
Re: Revised INV/ GF76370-7478-465
Malware Hash (MD5/SHA1/SH256)
Remediation