Severity: Medium
Analysis Summary
MalSpam Phishing campaigns have been observed targeting financial organizations to drop malware. The campaigns include:
Emotet Phishing: This campaign drops the emotet malware which is capable of network-wide infection and has advanced features to evade detection.
AMEX themed Phishing This campaign has been going on for a while and resurfaces with new variants every now and then. This phishing email contains an HTML attachment which loads a script from a remote site. Decoding this JavaScript, a phishing form appears requesting the recipients to enter sensitive information like their online account credentials, card number, security code, expiration date, mother’s maiden name, mother’s birth date, birth year, first elementary school name, their security pin, etc.
Impact
Indicators of Compromise
URLs
https[:]//emiuk[.]org/
Filename
myvtfile.exe
Email Subject
New invoice from Himanshu Khurana
Invoice Attached for Payment
Malware Hash (MD5/SHA1/SH256)
Remediation