• Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Transform
      • SOC Consultancy
      •     SOC Maturity Assessment
      •     SOC Model Evaluation
      •     SOC Gap Analysis
      •     SIEM Gap Analysis
      •     SIEM Optimization
      •     SOC Content Pack
    • Train
      • Security Awareness and Training
      • Tabletop Exercise
      • Simulated Cyber Attack Exercises
    • Respond
      • Incident Response
      • Incident Analysis
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
Rewterz Threat Alert – TA2101 Plays Government Imposter to Distribute Ransomware
November 15, 2019
Rewterz Threat Alert – More Than a Dozen Obfuscated APT33 Botnets Used for Extreme Narrow Targeting
November 15, 2019

Rewterz Threat Alert – Android Malware – IMobile-VERIFY Leverages Financially Motivated Cyber Attacks

November 15, 2019

Severity

High

Analysis Summary

IMobile-VERIFY is Android malware that Sucuri detected being used as part of an income tax themed phishing scheme believed to be targeting India. Potential victims would need to be lured to a webpage where the malicious app resides and is forcibly downloaded onto the victim device using JavaScript. The victim would need to have allowed installation of apps from third-party sites and agree to allowing the app permissions, including making it the default app for SMS messages. The app is used in an attempt to have the user provide banking details. If the victim has allowed the app to become the default SMS app, it could intercept any SMS messages including those such as 2FA messages used in banking transactions, potentially allowing the attackers controlling the app to steal funds from bank accounts.

Impact

Financial loss

Indicators of Compromise

MD5

6271c05865bfb38f29b1b5bf425ed7e8

SH256

8da0016f9da5d595521c4a07e1d00b58dacaede1a86219eef54a76ae612647b7

SHA1

c6f59e5e95986ba23fe3f6c18d42743761b2e837

URL

http[:]//stylecollections[.]ru/admin/controller/extension/manz[.]php

Remediation

  • Block all threat indicators at your respective controls.
  • Always be suspicious about emails sent by unknown senders.
  • Never click on the links/attachments sent by unknown senders.
  • Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Respond
      • Incident Response
      • Incident Analysis
  • Transform
    • SOC Consultancy
    •     SOC Maturity Assessment
    •     SOC Model Evaluation
    •     SOC Gap Analysis
    •     SIEM Gap Analysis
    •     SIEM Optimization
    •     SOC Content Pack
  • Train
    • Security Awareness and Training
    • Tabletop Exercise
    • Simulated Cyber Attack Exercises
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
COPYRIGHT © REWTERZ. ALL RIGHTS RESERVED.