Analyzing Steal Bank Account with Malicious PDF

Analyzing Steal Bank Account with Malicious PDF

Hi everyone, as have time I don't post anything, I decided to write one more analysis about stolen bank accounts and malicious PDFs used for it.

Normally I receive daily many of these kinds of e-mails, sometimes I like to spend time verifying if the attacker improved the strategy to make the target. Let's do it, in practice.

Below is the email received.

No alt text provided for this image

The email used is random/unknown,?this doesn't represent the legitimate company, and it has a PDF attachment.

Analysis Static

I downloaded the file in my Kali Linux and started the analysis using Peframe.

No alt text provided for this image

Was possible to validate that the file is a PDF, and it has a suspicious URL. After I used the PDF-PARSE to double-check if the URL really is inside the PDF file..

No alt text provided for this image

After discovering the suspicious URL, I made an analysis using? https://urlscan.io and found a history of other suspicious URLs linked to the same, a redirect to resgatarponto[.]me.

No alt text provided for this image

Bellow is the other URLs connected with the initial URL.

No alt text provided for this image
No alt text provided for this image

By the way, I checked how the domain Livelo was registered and which DNS server is responsible for it.

No alt text provided for this image

The false domain has other DNS servers

No alt text provided for this image

Dynamic Analysis

Now I used the https://urlquery.net to check what's happens when I try to open the URL found inside the PDF.

No alt text provided for this image

The same makes two redirects for other URLs:

  • lkadkasjdklsa[.]z13[.]web[.]core[.]windows[.]net (initial URL)
  • bbpontosonlinsx[.]z1[.]web[.]core[.]windows[.]net
  • resgateapp[.]top

After, I opened the PDF in my Flare-VM to make a dynamics analysis.

No alt text provided for this image

In the "Clique Aqui" (click here) I found the initial link. When I clicked on the same, I was redirected to other sites, to according the screenshot below.

No alt text provided for this image

As we can see above, the site asks to fill in CPF, document unique and used to identification in Brazil. After I was redirected to other pages to fill with my bank account. At this moment the bank account is stolen to according the image below.

No alt text provided for this image

This a simple attack that has victimized a lot of users for don't pay attention to the details of e-mail..

Recommendations

  • Pay attention all details in the e-mail received like to he sender name, e-mail, domain used, attachmet, links and etc.
  • Carefull with suspecious e-mails and its with attachments, if you aren't sure about the contents, so don't open
  • Normally the banks doesn't send this kind of url.

Tools used

Emerson Nascimento .

Head of Information Security

1 年

Muito bom! Parabéns Zoziel F. Go Hard!!!

Antonio Rolim

Cyber Security Manager | BlueTeam | ITIL | CHFI

1 年

Muito bom mano, excelente análise.

Vitor Esperan?a

Director of Purple Team, Offensive & Application Security

1 年

Muito boa análise zozi! Estou esperando as proximas! ????

Renan Vitor Lima

Especialista em Cyber Security na Vivo (Telef?nica Brasil)

1 年

é desse tipo de conteúdo que merece sempre muitos reposts! Show!

Samanta S.

Cyber Security Manager | Spearheading Advanced Threat Mitigation & Strategic IT Defenses | Innovator in AI-Enhanced Security Solutions | Threat Hunting and Intel | Social Enginner Specialist | LPI3 Specialist

1 年

good job

要查看或添加评论,请登录

Zoziel P.的更多文章

  • From the Zero to Malware Discovery

    From the Zero to Malware Discovery

    Hello people, I was with some time, and I decided to made an analysis using some tools that I commented last post…

    29 条评论
  • Windows Analysis Tips and Tools

    Windows Analysis Tips and Tools

    Hi people, I found some old notes, but useful that I use during an incident, and I decided to share these tools and…

    14 条评论
  • Ransomware is not just a threat, it's a crisis waiting to happen...

    Ransomware is not just a threat, it's a crisis waiting to happen...

    Although I haven't posted anything here, I wanted to share my thoughts on my favorite wicked malware: ransomware. To…

    21 条评论
  • Analise de arquivos maliciosos - Exemplo 01

    Analise de arquivos maliciosos - Exemplo 01

    English Version O intuito dessa série de artigos é exibir analises de exemplos de arquivos maliciosos que apresentei…

    13 条评论
  • Malicious file analysis - Example 01

    Malicious file analysis - Example 01

    My objective with this series of articles is to show an analysis of examples of malicious files that I presented during…

    3 条评论
  • Analisando ataques de phishing que usam PDFs maliciosos

    Analisando ataques de phishing que usam PDFs maliciosos

    Todos os dias nós recebemos muitos ataques de phishing com documentos(Word, Excel) ou PDFs maliciosos. Resolvi dar uma…

    11 条评论
  • Analyzing Phishing attacks that use malicious PDFs

    Analyzing Phishing attacks that use malicious PDFs

    Portuguese version Every day everybody receives many phishing attacks with malicious docs or PDFs. I decided to take a…

    8 条评论
  • PowerShell Introduction

    PowerShell Introduction

    I wrote this article to show a brief introduction about how to use PowerShell daily. Many professionals work…

    9 条评论
  • Carreira em Cybersecurity

    Carreira em Cybersecurity

    English Version Fala galera sempre escrevo artigos, compartilho posts de alguns sites que acompanho e acho relevante…

    10 条评论
  • Cybersecurity career

    Cybersecurity career

    Hey guys, I always write articles, share posts from some sites that I follow and find relevant. Among these various…

    4 条评论

社区洞察

其他会员也浏览了