Malicious PDF — malware analysis report

Static analysis result for SHA-256 0101e3932a6f5c8b…

MALICIOUS

PDF

12.6 KB
MD5: be680ca8b3063678643443e31738342e SHA-1: f8b4c33baa6ed5890db84761edec924daa186b8d SHA-256: 0101e3932a6f5c8ba3da97b10a72dab382e60138de579f51e95d4bd4f86ec67c
180 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious Link T1204.002 Malicious File T1059.001 PowerShell T1059.003 Windows Command Shell T1059.007 JavaScript

The PDF document contains embedded JavaScript that is obfuscated and appears to be designed to exploit CVE-2010-0188, a known vulnerability in Adobe Reader related to LibTIFF processing within XFA forms. The embedded script likely downloads and executes a second-stage payload. The ML classifier and ClamAV detection strongly indicate malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • Adobe Reader LibTIFF XFA image exploit — CVE-2010-0188 critical CVE likely CVE_2010_0188
    PDF contains the CVE-2010-0188 exploit template: XFA JavaScript heap-spray setup, a generated TIFF image payload, and assignment of that TIFF data to an XFA image field rawValue to trigger Adobe Reader's LibTIFF parser.
  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.xfa.org/schema/xfa-template/2.5/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_00000359.bin
4d571c19b345caecb1687507913f3ac6a8f67b62d28130b47b54050fd89e4bee
pdf-embedded-script PDF raw stream script payload at offset 0x359 12209 bytes