Malicious PDF — malware analysis report

Static analysis result for SHA-256 12727b3f1d784bb3…

MALICIOUS

PDF

4.0 KB
MD5: bffa73a4de767e7423e5f7c6411082a6 SHA-1: 283965397578de5a3455ed1a18a8b3a17243a446 SHA-256: 12727b3f1d784bb35995f8d90755fc51cee5f48c34a940c79e839af7ddb76323
132 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution

The PDF file contains an embedded XFA form which triggers the CVE-2010-0188 exploit in Adobe Reader. This exploit allows for arbitrary code execution on the victim's machine. No specific malware family could be identified, but the exploit is the primary indicator of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 7

  • Adobe Reader LibTIFF XFA image exploit — CVE-2010-0188 critical CVE likely CVE_2010_0188
    PDF contains XFA image data with an inline crafted TIFF payload and shellcode/delivery markers. This is the data-bound variant of the CVE-2010-0188 Adobe Reader LibTIFF/XFA exploit shape.
  • ASCIIHexDecode filter (with exploit indicators) medium PDF_FILTER_HEX
    Hex-encoding filter present alongside exploit delivery indicators — often used to hide payload or shellcode bytes
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: PSEOF. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xtd/
    • http://www.xfa.org/schema/xfa-form/2.8/
    • http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xci/1.0/
    • http://www.xfa.org/schema/xfa-template/2.4/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0001.bin
47d57cb1862a9223404a70c6cd6568bcd0509935a3f0f1414bf025697ce87e22
pdf-embedded-file PDF EmbeddedFile object 1 at offset 0x6A 12287 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).
embedded_file_obj0010.bin
8af81ed8eb133b8dbc92f16ee731a72b4418c73f308df25baea192d921e616d2
pdf-embedded-file PDF EmbeddedFile object 10 at offset 0x8E1 256 bytes
embedded_file_obj0011.bin
8d60d7a5f1f9f15df52ca6da1f6dbb835fec8443963e1a29e72d4371412754c2
pdf-embedded-file PDF EmbeddedFile object 11 at offset 0xB3F 743 bytes
embedded_file_obj0012.bin
422a5430698c54d7acba092e1350d18143964b54c5496415f1d8f31cbbcf0663
pdf-embedded-file PDF EmbeddedFile object 12 at offset 0xD3C 332 bytes