• Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Transform
      • SOC Consultancy
      •     SOC Maturity Assessment
      •     SOC Model Evaluation
      •     SOC Gap Analysis
      •     SIEM Gap Analysis
      •     SIEM Optimization
      •     SOC Content Pack
    • Train
      • Security Awareness and Training
      • Tabletop Exercise
      • Simulated Cyber Attack Exercises
    • Respond
      • Incident Response
      • Incident Analysis
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
Rewterz Threat Advisory – CVE-2019-15684 -Kaspersky Protection extension for Google Chrome security bypass
November 27, 2019
Rewterz Threat Alert – Payment Service Platform Phishing
November 28, 2019

Rewterz Threat Alert – Phishers Create Fake Sites as Bait for Holiday Shopping Deals

November 27, 2019

Severity

Medium

Analysis Summary

While most users are familiar with phishing scams that attempt to steal a user’s login credentials, phishers also use emails to lure consumers to fake retail sites in order to steal their money or sell cheap knockoffs.

There’s been a significant increase in  phishing scams promoting e-commerce related phishing sites. And this year we can already see a similar trend. With only half of November over and even before the peak of Black Friday and Cyber Monday, use of e-commerce phishing URLs has more than doubled since last November’s peak – in fact, it’s up by 233%, researchers stated. 

Increase since November 2018

This lookalike site was hosted on a domain named xwrbs[.]com, which was created on November 6th, 2019. Just one day later, Check Point observed it being used in phishing emails sent to thousands of users.

These phishing emails pretended to be a Black Friday promotion where consumers can purchase custom Ray-Ban sunglasses at 80% off the normal price.

Ray-Ban Phishing Email

Impact

  • Financial loss
  • Exposure of sensitive information

Indicators of Compromise

Domain Name

www.xwrbs[.]com

URL

  • http[:]//www[.]xwrbs[.]com/un.html
  • http[:]//www.xwrbs[.]com/

Remediation

  • Block the threat indicators at their respective controls.
  • Always be aware of the lookalike domains that look similar to the brand’s normal name.
  • Look out for spelling errors or mistakes in the brand’s name.
  • Always be suspicious about emails sent by unknown senders.
  • Never click on the links/attachments sent by unknown senders.
  • Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Respond
      • Incident Response
      • Incident Analysis
  • Transform
    • SOC Consultancy
    •     SOC Maturity Assessment
    •     SOC Model Evaluation
    •     SOC Gap Analysis
    •     SIEM Gap Analysis
    •     SIEM Optimization
    •     SOC Content Pack
  • Train
    • Security Awareness and Training
    • Tabletop Exercise
    • Simulated Cyber Attack Exercises
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
COPYRIGHT © REWTERZ. ALL RIGHTS RESERVED.