• Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Transform
      • SOC Consultancy
      •     SOC Maturity Assessment
      •     SOC Model Evaluation
      •     SOC Gap Analysis
      •     SIEM Gap Analysis
      •     SIEM Optimization
      •     SOC Content Pack
    • Train
      • Security Awareness and Training
      • Tabletop Exercise
      • Simulated Cyber Attack Exercises
    • Respond
      • Incident Response
      • Incident Analysis
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
Rewterz Threat Advisory – CVE-2019-5842 – Google Chrome Blink Use-After-Free Vulnerability
June 17, 2019
Rewterz Threat Advisory – Linux Kernel Multiple Denial of Service Vulnerabilities
June 18, 2019

Rewterz Threat Alert – Agent Tesla Email Campaign Stealing Information

June 17, 2019

Severity

Medium

Analysis Summary


An email campaign discovered distributing the Agent Tesla malware. A potential victim receives an email with a subject of “Re: Revised INV/ GF76370-7478-465”. The sender was observed as “Weifang Huaxing admin[@]infozcn[.]com”. Within the body of the email, the adversary attempts to entice a user to open the attachment “INV-GF76370-7478-465.cab” to review the order. The infection process begins once the .cab attachment is opened (which extracts to INV-GF76370-7478-465.exe) ultimately leading to the Agent Tesla keylogger / infostealer being installed on the victim’s system. It is interesting to note that the email server (infozcn.com) does match where the sender claimed to have sent the message from, according to analysis of the email headers. This helped the email to pass through most authentication checks undetected.

Impact

Infostealer keylogger

Indicators of Compromise

Filename

INV-GF76370-7478-465.cab

Email Address

admin@infozcn[.]com

Email Subject

Re: Revised INV/ GF76370-7478-465

Malware Hash (MD5/SHA1/SH256)

  • 8e69c2cc66803246bc16bba746b17afa08aacc37d751857fa8ad0653b08f0771
  • b6dcffb6187476b0bfcc3bea59b56155ff0d0e02fd8aca6ae1d2d9baa02b1031
  • 88187071e1f8b6f17b093888a03ed574a39bb84f
  • 80217c27c16ed71c1d9f29b4d456f9f2

Remediation

  • Block all threat indicators at your respective controls
  • Always be suspicious about emails sent by unknown senders
  • Never click on the link/ attachments sent by the unknown senders
  • Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Respond
      • Incident Response
      • Incident Analysis
  • Transform
    • SOC Consultancy
    •     SOC Maturity Assessment
    •     SOC Model Evaluation
    •     SOC Gap Analysis
    •     SIEM Gap Analysis
    •     SIEM Optimization
    •     SOC Content Pack
  • Train
    • Security Awareness and Training
    • Tabletop Exercise
    • Simulated Cyber Attack Exercises
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
COPYRIGHT © REWTERZ. ALL RIGHTS RESERVED.