Rewterz Threat Advisory – BlueKeep (CVE 2019-0708) Exploitation Spotted in the Wild
November 4, 2019Rewterz Threat Alert – Hawkeye Keylogger too Exploits CVE-2017-11882 after Rattlesnake
November 4, 2019Rewterz Threat Advisory – BlueKeep (CVE 2019-0708) Exploitation Spotted in the Wild
November 4, 2019Rewterz Threat Alert – Hawkeye Keylogger too Exploits CVE-2017-11882 after Rattlesnake
November 4, 2019Severity
Medium
Analysis Summary
Pay raises were used by scammers to bait employees in a recent phishing campaign that tried to trick them into handing out their Microsoft Office 365 account credentials. The attackers posed as their targets’ Human Resources department and asked them to open an Excel spreadsheet with a salary-increase-sheet-November-2019.xls filename hosted online and supposedly containing a list of salary increases. The email body says:
As already announced, The Years Wage increase will start in November 2019 and will be paid out for the first time in December, with recalculation as of November.”
However, instead of opening the spreadsheet with payment raises, the link will redirect the potential victims to the attackers’ phishing landing page hosted at hxxps://salary365[.]web[.]app/#/auth-pass-form/. Once the phishing page loads, the targets will see a fake Office 365 login page customized to display their email address and only asking them to input the password to sign in.
Impact
- Credential Theft
- Unauthorized Access
Indicators of Compromise
Filename
salary-increase-sheet-November-2019.xls
Source IP
151.101.65[.]195
URL
hxxps://salary365[.]web[.]app/#/auth-pass-form/
Remediation
- Block the threat indicators at their respective controls.
- Do not click on URLs attached in untrusted emails.
- Do not enter credentials on websites that you’re redirected to via random links.
- Enable multi-factor authentication via Office 365 or a third-party solution for all employees.