Analyzing Steal Bank Account with Malicious PDF
Hi everyone, as have time I don't post anything, I decided to write one more analysis about stolen bank accounts and malicious PDFs used for it.
Normally I receive daily many of these kinds of e-mails, sometimes I like to spend time verifying if the attacker improved the strategy to make the target. Let's do it, in practice.
Below is the email received.
The email used is random/unknown,?this doesn't represent the legitimate company, and it has a PDF attachment.
Analysis Static
I downloaded the file in my Kali Linux and started the analysis using Peframe.
Was possible to validate that the file is a PDF, and it has a suspicious URL. After I used the PDF-PARSE to double-check if the URL really is inside the PDF file..
After discovering the suspicious URL, I made an analysis using? https://urlscan.io and found a history of other suspicious URLs linked to the same, a redirect to resgatarponto[.]me.
Bellow is the other URLs connected with the initial URL.
By the way, I checked how the domain Livelo was registered and which DNS server is responsible for it.
The false domain has other DNS servers
领英推荐
Dynamic Analysis
Now I used the https://urlquery.net to check what's happens when I try to open the URL found inside the PDF.
The same makes two redirects for other URLs:
After, I opened the PDF in my Flare-VM to make a dynamics analysis.
In the "Clique Aqui" (click here) I found the initial link. When I clicked on the same, I was redirected to other sites, to according the screenshot below.
As we can see above, the site asks to fill in CPF, document unique and used to identification in Brazil. After I was redirected to other pages to fill with my bank account. At this moment the bank account is stolen to according the image below.
This a simple attack that has victimized a lot of users for don't pay attention to the details of e-mail..
Recommendations
Tools used
Head of Information Security
1 年Muito bom! Parabéns Zoziel F. Go Hard!!!
Cyber Security Manager | BlueTeam | ITIL | CHFI
1 年Muito bom mano, excelente análise.
Director of Purple Team, Offensive & Application Security
1 年Muito boa análise zozi! Estou esperando as proximas! ????
Especialista em Cyber Security na Vivo (Telef?nica Brasil)
1 年é desse tipo de conteúdo que merece sempre muitos reposts! Show!
Cyber Security Manager | Spearheading Advanced Threat Mitigation & Strategic IT Defenses | Innovator in AI-Enhanced Security Solutions | Threat Hunting and Intel | Social Enginner Specialist | LPI3 Specialist
1 年good job