• Services
    • Assess
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Transform
      • SOC Consultancy
      •     SOC Maturity Assessment
      •     SOC Model Evaluation
      •     SOC Gap Analysis
      •     SIEM Gap Analysis
      •     SIEM Optimization
      •     SOC Content Pack
    • Train
      • Security Awareness and Training
      • Tabletop Exercise
      • Simulated Cyber Attack Exercises
    • Respond
      • Incident Response
      • Incident Analysis
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Press Release
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
Rewterz Threat Alert – Gamaredon Hackers Use Outlook Macros to Spread Malware
July 1, 2020
Rewterz Threat Alert – EvilQuest Wiper Uses Ransomware Cover to Steal Files From Macs
July 1, 2020

Rewterz Threat Alert – Phishing Emails Containing Calendar Invitations

July 1, 2020

Severity

Medium

Analysis Summary

A phishing campaign is seen targeting multiple enterprise environments by sending emails, some from apparently compromised accounts, that use typical subject lines related to financial services such as, “Fraud Detection from Message Center”. The emails advise of suspicious activity related to the recipients bank account. The emails have a calendar invite file attached (.ics) that the recipient is asked to open. The invite contains a link to page on a Sharepoint.com site which claims to be information from Wells Fargo advising the recipient of new security measures being introduced. Clicking anywhere on that page finally directs the user to the actual phishing page which is hosted by Google. This Wells Fargo themed page provides fields in which to enter account details to login. After providing information, victims are redirected to an actual Wells Fargo login page.

Impact

  • Credential Theft
  • Financial loss

Indicators of Compromise

Email Subject

  • Fraud Detection from Message Center

URL

  • https[:]//storage[.]googleapis[.]com/awells-putlogs-308643420/index[.]html
  • https[:]//mko37372112-my[.]sharepoint[.]com/

Remediation

  • Block the threat indicators at their respective controls. 
  • Exercise caution while clicking on invites over email. 
  • Do not enter credentials on unintentionally redirected login pages. 
  • Services
    • Assess
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Respond
      • Incident Response
      • Incident Analysis
  • Transform
    • SOC Consultancy
    •     SOC Maturity Assessment
    •     SOC Model Evaluation
    •     SOC Gap Analysis
    •     SIEM Gap Analysis
    •     SIEM Optimization
    •     SOC Content Pack
  • Train
    • Security Awareness and Training
    • Tabletop Exercise
    • Simulated Cyber Attack Exercises
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
COPYRIGHT © REWTERZ. ALL RIGHTS RESERVED.