• Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Transform
      • SOC Consultancy
      •     SOC Maturity Assessment
      •     SOC Model Evaluation
      •     SOC Gap Analysis
      •     SIEM Gap Analysis
      •     SIEM Optimization
      •     SOC Content Pack
    • Train
      • Security Awareness and Training
      • Tabletop Exercise
      • Simulated Cyber Attack Exercises
    • Respond
      • Incident Response
      • Incident Analysis
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
Rewterz Threat Alert – Recent QakBot Malspam Activity
December 10, 2020
Rewterz Threat Alert – SideWinder APT Active in South Asia
December 10, 2020

Rewterz Threat Alert – Phishing Email Using ‘Low Storage Warning’ as Lure

December 10, 2020

Severity

Medium

Analysis Summary

A new phishing campaign has been detected that uses malspam to lure victims. The email content of this malspam campaign tries to scare the user that their mailbox is almost full. It further asserts that the webmaster Incoming and outgoing messages of the user will be placed on hold if no further action is taken. The email also offers the users to increase their mailbox size. Attached in the email is a URL that is to be used in order to increase the size of the mailbox to avoid being shutdown. The page is likely to be a fake login page to harvest credentials.

Impact

Credential Theft

Indicators of Compromise

Domain Name

  • wondryve[.]web[.]app

Email Subject

  • Warning – Email storage Low

From Email

  • support@astoria-pl[.]com

URL

  • https[:]//wondryve[.]web[.]app/in/index[.]html/webmaster[.]georgialibraries[.]org

Remediation

  • Block the threat indicators at their respective controls.
  • Do not click on URLs attached in untrusted emails.
  • Enable multi-factor authentication where possible.
  • Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Respond
      • Incident Response
      • Incident Analysis
  • Transform
    • SOC Consultancy
    •     SOC Maturity Assessment
    •     SOC Model Evaluation
    •     SOC Gap Analysis
    •     SIEM Gap Analysis
    •     SIEM Optimization
    •     SOC Content Pack
  • Train
    • Security Awareness and Training
    • Tabletop Exercise
    • Simulated Cyber Attack Exercises
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
COPYRIGHT © REWTERZ. ALL RIGHTS RESERVED.