• Services
    • Assess
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Transform
      • SOC Consultancy
      •     SOC Maturity Assessment
      •     SOC Model Evaluation
      •     SOC Gap Analysis
      •     SIEM Gap Analysis
      •     SIEM Optimization
      •     SOC Content Pack
    • Train
      • Security Awareness and Training
      • Tabletop Exercise
      • Simulated Cyber Attack Exercises
    • Respond
      • Incident Response
      • Incident Analysis
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Press Release
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
Rewterz Threat Advisory – CVE-2019-13345 – Squid Multiple Cross Site Scripting Vulnerabilities
July 19, 2019
How to Avoid Cyber Threats by Disgruntled Employees
July 19, 2019

Rewterz Threat Alert – Trickbot Trojan Pushed By Fake Office 365 Sites as Browser Update

July 19, 2019

Severity

Medium

Analysis Summary

Attackers have created a fake Office 365 site that is distributing the TrickBot password-stealing Trojan disguised as Chrome and Firefox browser updates.

Fake Office 365 Page

If you wait a few seconds, though, the site will present you with a alert that states your browser needs to be updated. This alert is slightly different for Chrome and Firefox users.

For example, when using Google Chrome to visit the page, it will show an alert titled “Chrome Update Center” and state that you are using an older version of Chrome that could lead to loss of data and browser errors.

Fake Chrome Update

Similarly, Firefox users will see an alert titled “Firefox Update Center” that states you need to update the browser.

Fake Firefox Update

If you click on the Update button, an executable named upd365_58v01.exe will be downloaded that will install the TrickBot information-stealing Trojan on the computer. When executed, the Trojan will being injected into a svchost.exe process, so it is not readily visible or suspicious in Task Manager.

Injected DLL into svchost.exe

It will then immediately begin to communicate with the C2 server where it will execute a variety of modules. For example, the systeminfo64 will upload information about a victim’s computer, installed programs, and Windows services.

Impact

Exposure of sensitive information

Remediation

  • Always be suspicious about emails sent by unknown senders.
  • Never click on the links/attachments sent by unknown senders.
  • Services
    • Assess
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Respond
      • Incident Response
      • Incident Analysis
  • Transform
    • SOC Consultancy
    •     SOC Maturity Assessment
    •     SOC Model Evaluation
    •     SOC Gap Analysis
    •     SIEM Gap Analysis
    •     SIEM Optimization
    •     SOC Content Pack
  • Train
    • Security Awareness and Training
    • Tabletop Exercise
    • Simulated Cyber Attack Exercises
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
COPYRIGHT © REWTERZ. ALL RIGHTS RESERVED.