Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
SEVERITY: Medium
ANALYSIS SUMMARY
The Phishing email with the subject “Summit Bank Account Locked” pretends to be coming from the legitimate bank, using the email address ibsupport[@]summitbank[.]pk and targets employees of other banks. It contains a fake URL leading to a login page. While the legitimate URL of Summit Bank’s internet banking log-in page is https://ib.summitbank.com.pk/ib.login.do, the URL received through email was https://latamvapea[.]com/mails/nl/summit/summit[.]html/. The page latamvapea itself is a legitimate but compromised vapeselling site.
The email looks like this:
Moreover, while only port 443 is open on the legitimate site, the fake site has port 80, 443 and 81 open as well. 81 can be used for web services but if it’s idle it can be widely used as a RAT (remote access Trojan).
IMPACT
Credential theft
INDICATORS OF COMPROMISE
URLs
Email Address
Email Subject
Summit Bank Account Locked
Remediation
If you think you’re a victim of a cyber-attack, immediately send an email to soc@rewterz.com for a quick response.