

Rewterz Threat Alert – BITTER – Targeted Attack Against Pakistan
September 11, 2019
Rewterz Threat Alert – GandCrab Ransomware – IoCs
September 12, 2019
Rewterz Threat Alert – BITTER – Targeted Attack Against Pakistan
September 11, 2019
Rewterz Threat Alert – GandCrab Ransomware – IoCs
September 12, 2019Severity
Medium
Analysis Summary
Indicators of Compromise have been identified for a campaign using captcha boxes to hide a fake Microsoft account login page from secure email gateways (SEGs). The attackers were after credentials for Microsoft accounts and created a page that mimics the original for selecting an account and logging in. The phishing link is delivered from a compromised email account from ‘avis.ne.jp’ which looks like a notification for voicemail message. A button promising to provide a preview of the alleged communication is embedded in the email; when clicked, it takes the victim to the page with the captcha code. The SEG cannot proceed to and scan the malicious page, only the Captcha code site. This webpage doesn’t contain any malicious items, thus leading the SEG to mark it as safe and allow the user through.
Impact
Credential Theft
Indicators of Compromise
IP(s) / Hostname(s)
- 52[.]239[.]224[.]36
- 52[.]173[.]84[.]157
- 66[.]117[.]16[.]17
- 62[.]210[.]161[.]21
- 66[.]117[.]16[.]17
URLs
- t[.]mid[.]accor-mail[.]com
- accor-mail[.]com
- phospate02[.]blob[.]core[.]windows[.]net
Remediation
- Block the threat indicators at their respective controls.
- Do not follow URLs/hyperlinks attached in emails coming from unknown sources.
- If you have to login, type the legitimate URL for Microsoft yourself instead of following any links.