Malicious PDF — malware analysis report

Static analysis result for SHA-256 273d3ca3b0564e55…

MALICIOUS

PDF

24.2 KB
MD5: 903e3c583a7be4b9ef23cd766c2afbdf SHA-1: 458337f88e6f1064e11dfdbce8cfd0848b0d9843 SHA-256: 273d3ca3b0564e5551c962d0036575bf413a62b117d027f4448b4a017cf6cc50
128 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.004 Command and Scripting Interpreter: PowerShell

The sample is a PDF file that triggers critical heuristics for CVE-2010-0188, an Adobe Reader LibTIFF XFA image exploit. This indicates the file is designed to execute arbitrary code upon opening in a vulnerable version of Adobe Reader. The embedded URL, while not directly malicious, is associated with XFA templates, further supporting the exploit vector. No scripts were extracted, but the exploit itself is the primary attack mechanism.

Heuristics 4

  • Adobe Reader LibTIFF XFA image exploit — CVE-2010-0188 critical CVE likely CVE_2010_0188
    PDF contains the CVE-2010-0188 exploit template: XFA JavaScript heap-spray setup, a generated TIFF image payload, and assignment of that TIFF data to an XFA image field rawValue to trigger Adobe Reader's LibTIFF parser.
  • ClamAV: Pdf.Exploit.Agent-36821 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36821
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.xfa.org/schema/xfa-template/2.5/