Malicious PDF — malware analysis report

Static analysis result for SHA-256 036c46cfa4bce00a…

MALICIOUS

PDF

220.5 KB Created: 2010-03-03 03:42:28 +08:00
MD5: 436e094f4a5ac4940fb61991bd877245 SHA-1: e6d47b90cb3cded2a2fd1f90369eb0c034e75934 SHA-256: 036c46cfa4bce00adef6c7a08e93869429b9a02fa077a8bdc3bf784e7754b8de
216 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.007 JavaScript T1566.001 Spearphishing Attachment

This PDF document exploits CVE-2010-0188, a vulnerability in Adobe Reader related to XFA forms and TIFF images, to achieve code execution. The embedded JavaScript, though obfuscated, likely facilitates the exploitation and may attempt to download additional content, as suggested by the embedded 'bin_adobeupdate.wav' file and the heuristic indicating an embedded script payload. The document's structure and the presence of an image lure further support a malicious intent, likely delivered via spearphishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9634

Heuristics 11

  • Adobe Reader LibTIFF XFA image exploit — CVE-2010-0188 critical CVE likely CVE_2010_0188
    PDF contains the CVE-2010-0188 exploit template: XFA JavaScript heap-spray setup, a generated TIFF image payload, and assignment of that TIFF data to an XFA image field rawValue to trigger Adobe Reader's LibTIFF parser.
  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 2 image(s), only 1 text block(s), carries a click-outward action, and is only 220 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic (matched inside decoded stream)
  • Embedded script payload in PDF stream low PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/pdf/1.3/
    • http://www.xfa.org/schema/xci/1.0/
    • http://www.xfa.org/schema/xfa-template/2.4/
    • http://www.xfa.org/schema/xfa-locale-set/2.7/
    • http://www.xfa.org/schema/xfa-locale-set/2.1/
    • http://ns.adobe.com/xtd/
    • http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-data/1.0/
    • http://www.xfa.org/schema/xfa-form/2.8/
    • http://cgi.adobe.com/special/acrobat/update

Extracted artifacts 15

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0002.bin
52f043a6fc7df55209bb983ed6c7d2cbf223d70807f647258f3320e58aef00a9
pdf-embedded-file PDF EmbeddedFile object 2 at offset 0xFC8 1465 bytes
embedded_file_obj0003.bin
75b1b32ce086dcfb46ad5ad812bcac90dbc30017591e95d16cc14e8406c61fbf
pdf-embedded-file PDF EmbeddedFile object 3 at offset 0x1283 986 bytes
embedded_file_obj0005.bin
226eeacc5eecef2a05ca480f144ff6936594e20b5c7672e8f29f25c8bea65a56
pdf-embedded-file PDF EmbeddedFile object 5 at offset 0x14D1 2928 bytes
embedded_file_obj0006.bin
4cb349134bdb5f1a1c03281df9b53128ebe947f235398a912a4f0a9f638b24d5
pdf-embedded-file PDF EmbeddedFile object 6 at offset 0x183E 200 bytes
embedded_file_obj0007.bin
1e96d28fce4fbbc1f0f529e2266e0d503636f29111a4ea3cb8464bc9f6b5250a
pdf-embedded-file PDF EmbeddedFile object 7 at offset 0x1931 835 bytes
bin_adobeupdate.wav
88d83b5b31aba79f8a649ed61f7ce345feb78828a4472c9e9de2e19755a0b538
pdf-embedded-file PDF EmbeddedFile object 117 at offset 0x3D5A 3582 bytes
embedded_file_obj0121.bin
c06dcd026a7ea0536b63e07ce688691b585339a3ab7ff59065e546b56308c7bb
pdf-embedded-file PDF EmbeddedFile object 121 at offset 0x146D2 85 bytes
embedded_file_obj0122.bin
dbbbfdd785e9d2b256dd4ac2faa0002c3d0c522765699437326e7216e03af174
pdf-embedded-file PDF EmbeddedFile object 122 at offset 0x14787 11882 bytes
embedded_file_obj0123.bin
bb76e51bb8b760432fa497d467a6211dbad4e19a09c332250c9ac2b240d23f80
pdf-embedded-file PDF EmbeddedFile object 123 at offset 0x14C5C 291 bytes
bin_adobeupdate_1.wav
4c92fa78e09cab2a358daac5ceffdf9346faa05ad5524c474f53ba256037c0df
pdf-embedded-file PDF EmbeddedFile object 135 at offset 0x15F79 135183 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.
javascript_obj0092_000.js
97e6c8fb70f6fedab160a41095c99dce3c9d53a0086d3a8d4e6d47cbe03dce61
pdf-javascript-stream PDF /JS object 92 at offset 0x323A 1946 bytes
stream_013_off000029ca.js
f574e4d51594d1a8fd22e125b109b827c437aa898edc78babb62dbb93f8744f8
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x29CA 1532 bytes
stream_014_off00002bb5.js
4a1aca004cf20431c9a66dce85404a6411a54d881a6c257882260ffc972a13eb
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2BB5 870 bytes
stream_028_off0000323a.js
5c1ab2af46eef55b0d162c3a84464633475df9b138b64aa21a36ffaffbdffa88
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x323A 1336 bytes
objstm_0126_00.bin
ba08ce675f5a4edd23a5e7004fab9b39cd9f4a22a78e3315f0f79ca8628e5b98
pdf-objstm-decoded PDF /ObjStm 126 0 obj (inflated) 1974 bytes