MALICIOUS
184
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
The PDF document contains heuristics indicating it presents a fake CAPTCHA and instructions to run commands, specifically mentioning 'wget' and a URL. It impersonates Facebook, directing users to 'ebookleaks.org', which is a strong indicator of a credential phishing or social engineering attack. The presence of external URIs and the fake CAPTCHA lure suggest an attempt to execute malicious commands or redirect users to a malicious site.
Machine Learning
- Nyx PDF Classifier clean score 0.0043
Heuristics 6
-
Fake CAPTCHA with command-running instructions critical SE_FAKE_CAPTCHA_CLICKFIXDocument combines fake CAPTCHA or human-verification language with instructions to paste or run a command — a high-confidence ClickFix pattern
-
LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMANDExtracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
-
Fake CAPTCHA / human verification prompt high SE_FAKE_CAPTCHADocument displays a fake CAPTCHA or human-verification prompt — used to trick users into running commands or pressing keyboard shortcuts
-
Brand-impersonation credential phishing lure high SE_BRAND_CREDENTIAL_PHISHDocument impersonates a well-known consumer brand and uses account-security / verification language ('unusual activity', 'account on hold', 'verify your account') to steer the reader to a credential-harvesting link. Corroborated by: call-to-action link host does not match the impersonated brand: http://ebookleaks.org.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://ebookleaks.org PDF link annotation
- http://hackforums.net/member.php?action=profile&uid=2582112In PDF document text
- http://1lineart.kulaone.com/#/In PDF document text
- http://grabify.link/In PDF document text
- http://skidtools.net/login.phpIn PDF document text
- https://pipl.com/In PDF document text
- http://com.lullar.com/In PDF document text
- https://namechk.com/In PDF document text
- http://email.addresssearch.com/In PDF document text
- http://10digits.us/In PDF document text
- http://www.pipl.com/In PDF document text
- http://webmii.com/In PDF document text
- http://www.dgs.dk/In PDF document text
- https://find-person-germany.com/In PDF document text
- http://www.10digits.us/In PDF document text
- http://www.reversemobile.com/index.php/In PDF document text
- http://www.numberway.com/In PDF document text
- http://www.phonenumber.com/In PDF document text
- https://www.goyellow.da/In PDF document text
- http://www.infosniper.net/In PDF document text
- http://ssndob.so/loginIn PDF document text
- http://www.advancedbackgroundchecks.com/In PDF document text
- http://www.findmypast.com/In PDF document text
- http://www.archives.com/search/ancestor/In PDF document text
- http://www.familytreesearcher.com/In PDF document text
- http://www.geoimgr.com/In PDF document text
- http://exifdata.com/In PDF document text
- http://leakedsource.com/In PDF document text
- http://siph0n.net/In PDF document text
- https://leakforums.net/In PDF document text
- https://citadel.sx/In PDF document text
- http://skidpaste.org/In PDF document text
- http://paste4btc.com/In PDF document text
- http://hackforums.net/showthread.php?tid=5231265In PDF document text
- http://hackforums.net/showthread.php?tid=4692270In PDF document text
- http://hackforums.net/showthread.php?tid=4892146In PDF document text
- http://wizblogger.com/get-fake-mobile-numbers-to-bypass-verification/In PDF document text
- http://hackforums.net/[/urlIn PDF document text
- http://webmii.com/���In PDF document text
- http://www.dgs.dk/���In PDF document text
- https://find��person��germany.com/���In PDF document text
- https://www.goyellow.da/���In PDF document text
- http://www.infosniper.net/���In PDF document text
- http://ssndob.so/login���In PDF document text
- http://leakedsource.com/���In PDF document text
- http://hackforums.net/showthread.php?tid=5231265���In PDF document text
- http://wizblogger.com/get��fake��mobile��numbers��to��bypass��verification/In PDF document text
- http://www.monotype.comMonotypeIn PDF document text
- http://www.monotypeimaging.com/http://www.monotypeimaging.com/ProductsServices/TypeDesignerShowcaseNOTIFICATIONIn PDF document text
- http://www.monotypeimaging.com/html/license.aspxIn PDF document text
+51 more URL(s)
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0007cdf0.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7CDF0 | 58116 bytes |
SHA-256: 3c839247b313c15315f0117fa9e95382bfe3993b266006877e70765938f2b685 |
|||
font_01_sfnt_off000854ed.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x854ED | 68092 bytes |
SHA-256: 920182096a0603d7b9a49dc054b3b704ba6ea39594651f1f6684cf68333e4752 |
|||
font_02_sfnt_off0008fb00.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8FB00 | 16780 bytes |
SHA-256: 7e974e49a975874d8722d969220a9ea10cedaa1dd14f43f995d6868ca8134c06 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.