Rewterz Threat Advisory – PDF documents that exploit unpatched flaw in Chrome to harvest user data
March 1, 2019Rewterz Threat Advisory – Industrial Control Moxa – IKS & EDS Multiple Vulnerabilities
March 1, 2019Rewterz Threat Advisory – PDF documents that exploit unpatched flaw in Chrome to harvest user data
March 1, 2019Rewterz Threat Advisory – Industrial Control Moxa – IKS & EDS Multiple Vulnerabilities
March 1, 2019Severity
Medium
Analysis Summary
Multiple e-mail campaigns have been observed using spoofed email addresses that use the legitimacy of SWIFT to successfully target unsuspecting victims. The emails contain malicious links to zip files which contain malicious VBScripts, as well as malicious files containing backdoors.
The emails are either sent from a spoofed email address or use the subject of SWIFT transactions.
Collective IoCs are given below.
Indicators of Compromise
IP(s) / Hostname(s)
- 178.51.107[.]77
- 49.248.125[.]75
- 46.183.222[.]105
- 212.227.17[.]10
- 217.72.192[.]74
- 212.227.17[.]24
- 217.72.192[.]73
- 217.72.192[.]75
- 212.227.17[.]13
- 173.203.187[.]64
- 173.203.187[.]117
- 173.203.187[.]115
- 173.203.187[.]112
- 173.203.187[.]91
- 173.203.187[.]92
- 173.203.187[.]71
- 173.203.187[.]66
Ports
3465
URLs
- hxxp://owa.wpmunetwork[.]com/Invalid_Swift_Code_jpg.zip
- mout.kundenserver[.]de
- smtp64.iad3a[.]emailsrvr[.]com
- smtp117.iad3a.emailsrvr[.]com
- smtp115.iad3a.emailsrvr[.]com
- smtp112.iad3a.emailsrvr[.]com
- smtp91.iad3a.emailsrvr[.]com
- smtp92.iad3a.emailsrvr[.]com
- smtp71.iad3a.emailsrvr[.]com
- smtp66.iad3a.emailsrvr[.]com
Filename
- Invalid_Swift_Code_jpg.zip
- Invalid_Swift_Code_jpg.vbs
- %TEMP%\Invalid_Swift_Code_jpg.vbs
Email Address
- Sohan_Peron@swift[.]com
- charleston.g@tagoffshore[.]net
- Treasury.generic@swift[.]com
- swiftcustomer.service.centre@swift[.]com
- jose@viporders[.]com
Email Subject
- Information
- INVALID SWIFT CODE
- Money Transfer Flagged! Report Back
- TT COPY
Malware Hash (MD5/SHA1/SH256)
- 037bd31a6245e42910e09c8a6465dee8
- 61a975f03e845dcb024d6dc0417b43bf04a7366d
- 909fc87e0cf83d9574b6f420773c47e28e79eed2a404fc48c882a7ed2e44e889
- 065a3068d034db10b27e6c628d675c59
- 14c2926b19dda3b344133ee5c78817248576311c
- 0e31f542bd6b8072b050ea7ce476a40c55482f26ce50f4d655c38b392ad1ed05
Remediation
Block the threat indicators at their respective controls.