Malicious PDF — malware analysis report

Static analysis result for SHA-256 00d01f462bb6cbe6…

MALICIOUS

PDF

99.5 KB
MD5: 080af7fd24e246a25243bbdac06b8fb5 SHA-1: 249bb3212d3b2074d52b141669dac345f4db484a SHA-256: 00d01f462bb6cbe6ff95996ab3d3de2c2948798c75a016aabd913037dd29e817
128 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link T1204.001 Malicious Link: Malicious Link T1204.002 Malicious Link: Malicious File T1059 Command and Scripting Interpreter T1059.007 Command and Scripting Interpreter: JavaScript

The PDF file exploits CVE-2010-0188, a known vulnerability in Adobe Reader related to XFA forms. This exploit is designed to execute arbitrary code, indicating the file's primary purpose is to compromise the user's system. The presence of an embedded script payload further supports the malicious intent, likely for downloading and executing a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • Adobe Reader LibTIFF XFA image exploit — CVE-2010-0188 critical CVE likely CVE_2010_0188
    PDF contains the CVE-2010-0188 exploit template: XFA JavaScript heap-spray setup, a generated TIFF image payload, and assignment of that TIFF data to an XFA image field rawValue to trigger Adobe Reader's LibTIFF parser.
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0008.bin
1b14d88f7346bad77f8218a397987ce55bf92eb210fbe30d56ea43c11455c8cf
pdf-embedded-file PDF EmbeddedFile object 8 at offset 0xC6 101124 bytes