Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Medium
A phishing campaign is detected, luring its targets with fake job scams. The campaign is being linked to Iranian APT33. Indicators of compromise are given below, some of which have previously been used in other phishing campaigns as well. The motive of the campaign is still not known. Similar phishing campaigns have been previously launched to deploy Remote Access Trojans.
Domain Name
www[.]global-careers[.]org
dyn-intl[.]world-careers[.]org
global-careers[.]org
raytheonjobs.serveblog[.]net
Filename
JobDescription.zip
JobDescription.vbe
MD5
SHA-256
Source IP
208.91.197[.]91
URL
http[:]//fineksus[.]com/delp[.]exe