Rewterz Threat Advisory – Adobe Acrobat and Reader Multiple Vulnerabilities
November 4, 2020Rewterz Threat Advisory – IBM App Connect Enterprise clickjacking
November 4, 2020Rewterz Threat Advisory – Adobe Acrobat and Reader Multiple Vulnerabilities
November 4, 2020Rewterz Threat Advisory – IBM App Connect Enterprise clickjacking
November 4, 2020Severity
Medium
Analysis Summary
Phishing is the fraudulent attempt to obtain sensitive information or data, such as usernames, passwords and credit card details. This is done by disguising oneself as trustworthy communication to obtain information which can be used against the user. Phishing activities are almost ongoing across the world and is the most common source of attack used against the victims to lure them to click on the malicious attachments. The URLs, email subjects, filenames are made in such manner where the user would feel the domain is legitimate and has no hesitation clicking on the attachment. This would lead the victim to land on the phishing page where the threat actor would gather the information and later on use against the victim.
Impact
- Credential theft
- Exposure of sensitive data
Indicators of Compromise
URL
- http[:]//orangecaraibes[.]fr[.]u90491507g[.]ha004[.]t[.]justns[.]ru/
- https[:]//villahidalgo[.]mx/verify/mailbox/index[.]php?email=
- https[:]//newslogins[.]webnode[.]cr/
- https[:]//ee-digitalupdates[.]com/account/index/?ac=ee
- https[:]//ee-supportservice[.]com/account/index/?ac=ee
- https[:]//de[.]darkandshiny[.]com[.]au/wl/?i=i&0=
- https[:]//katherinegesell[.]com/loading[.]php/
- https[:]//www[.]coalesceresearchgroup[.]com/foodscience/[.]well-known/pki-validation/logs/update-your-accountinformation/security-measure/log-in/
- http[:]//uk-ee[.]20cree[.]com/
- http[:]//emticorp[.]com/reswisscoms/
- https[:]//devwebtechnology[.]com/crop/
- https[:]//swiss-poset[.]blogspot[.]com/?m=1
- https[:]//tiny[.]com/y49e3j2l
- http[:]//bahcokes[.]hu/wp-includes/Requests/Auth/
- https[:]//laposte-fr-colissimo[.]u901154zhs[.]ha004[.]t[.]justns[.]ru/compte/
- http[:]//thermoformliner[.]com/wells-fargo[.]com-login/wellsfargo/login[.]php
- https[:]//umiyafabrication[.]com/connect/public/login?sslmode=true&access_token
Remediation
- Block all threat indicators at your respective controls.
- Always be suspicious about emails sent by unknown senders.
- Never click on links/attachments sent by unknown senders.