

Rewterz Threat Alert – Recent QakBot Malspam Activity
December 10, 2020
Rewterz Threat Alert – SideWinder APT Active in South Asia
December 10, 2020
Rewterz Threat Alert – Recent QakBot Malspam Activity
December 10, 2020
Rewterz Threat Alert – SideWinder APT Active in South Asia
December 10, 2020Severity
Medium
Analysis Summary
A new phishing campaign has been detected that uses malspam to lure victims. The email content of this malspam campaign tries to scare the user that their mailbox is almost full. It further asserts that the webmaster Incoming and outgoing messages of the user will be placed on hold if no further action is taken. The email also offers the users to increase their mailbox size. Attached in the email is a URL that is to be used in order to increase the size of the mailbox to avoid being shutdown. The page is likely to be a fake login page to harvest credentials.
Impact
Credential Theft
Indicators of Compromise
Domain Name
- wondryve[.]web[.]app
Email Subject
- Warning – Email storage Low
From Email
- support@astoria-pl[.]com
URL
- https[:]//wondryve[.]web[.]app/in/index[.]html/webmaster[.]georgialibraries[.]org
Remediation
- Block the threat indicators at their respective controls.
- Do not click on URLs attached in untrusted emails.
- Enable multi-factor authentication where possible.