Malicious PDF — malware analysis report

Static analysis result for SHA-256 05ee8389bda05042…

MALICIOUS

PDF

639.1 KB First seen: 2020-08-25
MD5: b7a2d716502812125d27386ed31359e3 SHA-1: fb916b96045be29d7e87865702b6c24de8f8fe8d SHA-256: 05ee8389bda050421c7705dc8f9bad998812f2a1fa16c14ff84b7bd863bd2ec7
184 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains heuristics indicating it presents a fake CAPTCHA and instructions to run commands, specifically mentioning 'wget' and a URL. It impersonates Facebook, directing users to 'ebookleaks.org', which is a strong indicator of a credential phishing or social engineering attack. The presence of external URIs and the fake CAPTCHA lure suggest an attempt to execute malicious commands or redirect users to a malicious site.

Machine Learning

  • Nyx PDF Classifier clean score 0.0043

Heuristics 6

  • Fake CAPTCHA with command-running instructions critical SE_FAKE_CAPTCHA_CLICKFIX
    Document combines fake CAPTCHA or human-verification language with instructions to paste or run a command — a high-confidence ClickFix pattern
  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Fake CAPTCHA / human verification prompt high SE_FAKE_CAPTCHA
    Document displays a fake CAPTCHA or human-verification prompt — used to trick users into running commands or pressing keyboard shortcuts
  • Brand-impersonation credential phishing lure high SE_BRAND_CREDENTIAL_PHISH
    Document impersonates a well-known consumer brand and uses account-security / verification language ('unusual activity', 'account on hold', 'verify your account') to steer the reader to a credential-harvesting link. Corroborated by: call-to-action link host does not match the impersonated brand: http://ebookleaks.org.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ebookleaks.org PDF link annotation
    • http://hackforums.net/member.php?action=profile&uid=2582112In PDF document text
    • http://1lineart.kulaone.com/#/In PDF document text
    • http://grabify.link/In PDF document text
    • http://skidtools.net/login.phpIn PDF document text
    • https://pipl.com/In PDF document text
    • http://com.lullar.com/In PDF document text
    • https://namechk.com/In PDF document text
    • http://email.addresssearch.com/In PDF document text
    • http://10digits.us/In PDF document text
    • http://www.pipl.com/In PDF document text
    • http://webmii.com/In PDF document text
    • http://www.dgs.dk/In PDF document text
    • https://find-person-germany.com/In PDF document text
    • http://www.10digits.us/In PDF document text
    • http://www.reversemobile.com/index.php/In PDF document text
    • http://www.numberway.com/In PDF document text
    • http://www.phonenumber.com/In PDF document text
    • https://www.goyellow.da/In PDF document text
    • http://www.infosniper.net/In PDF document text
    • http://ssndob.so/loginIn PDF document text
    • http://www.advancedbackgroundchecks.com/In PDF document text
    • http://www.findmypast.com/In PDF document text
    • http://www.archives.com/search/ancestor/In PDF document text
    • http://www.familytreesearcher.com/In PDF document text
    • http://www.geoimgr.com/In PDF document text
    • http://exifdata.com/In PDF document text
    • http://leakedsource.com/In PDF document text
    • http://siph0n.net/In PDF document text
    • https://leakforums.net/In PDF document text
    • https://citadel.sx/In PDF document text
    • http://skidpaste.org/In PDF document text
    • http://paste4btc.com/In PDF document text
    • http://hackforums.net/showthread.php?tid=5231265In PDF document text
    • http://hackforums.net/showthread.php?tid=4692270In PDF document text
    • http://hackforums.net/showthread.php?tid=4892146In PDF document text
    • http://wizblogger.com/get-fake-mobile-numbers-to-bypass-verification/In PDF document text
    • http://hackforums.net/[/urlIn PDF document text
    • http://webmii.com/���In PDF document text
    • http://www.dgs.dk/���In PDF document text
    • https://find��person��germany.com/���In PDF document text
    • https://www.goyellow.da/���In PDF document text
    • http://www.infosniper.net/���In PDF document text
    • http://ssndob.so/login���In PDF document text
    • http://leakedsource.com/���In PDF document text
    • http://hackforums.net/showthread.php?tid=5231265���In PDF document text
    • http://wizblogger.com/get��fake��mobile��numbers��to��bypass��verification/In PDF document text
    • http://www.monotype.comMonotypeIn PDF document text
    • http://www.monotypeimaging.com/http://www.monotypeimaging.com/ProductsServices/TypeDesignerShowcaseNOTIFICATIONIn PDF document text
    • http://www.monotypeimaging.com/html/license.aspxIn PDF document text
    +51 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0007cdf0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7CDF0 58116 bytes
SHA-256: 3c839247b313c15315f0117fa9e95382bfe3993b266006877e70765938f2b685
font_01_sfnt_off000854ed.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x854ED 68092 bytes
SHA-256: 920182096a0603d7b9a49dc054b3b704ba6ea39594651f1f6684cf68333e4752
font_02_sfnt_off0008fb00.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8FB00 16780 bytes
SHA-256: 7e974e49a975874d8722d969220a9ea10cedaa1dd14f43f995d6868ca8134c06