Malicious PDF — malware analysis report

Static analysis result for SHA-256 37b974a1185e774f…

MALICIOUS

PDF

977.5 KB
MD5: 1c7ad6809ddb6c26023edc3d811aacda SHA-1: c547ee124fbdf6a1e16bcda13f4022612a02f3f4 SHA-256: 37b974a1185e774fba4ed2a182861d005711774af28ae7be1202b96a52649780
114 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: User Execution T1059.001 Command and Scripting Interpreter: PowerShell T1566.001 Phishing: Spearphishing Attachment

The PDF file contains JavaScript and is flagged for exploiting CVE-2010-0188, a known vulnerability in Adobe Reader related to XFA forms. This indicates the document is designed to trick the user into opening it, leading to the execution of malicious code via the exploit. No specific malware family was identified, but the exploit suggests a downloader or dropper functionality.

Heuristics 8

  • Adobe Reader LibTIFF XFA image exploit — CVE-2010-0188 critical CVE likely CVE_2010_0188
    PDF contains the CVE-2010-0188 exploit template: XFA JavaScript heap-spray setup, a generated TIFF image payload, and assignment of that TIFF data to an XFA image field rawValue to trigger Adobe Reader's LibTIFF parser.
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xfa/promoted-desc/

Extracted artifacts 13

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0001.bin
04b8af10e5b228b5612c950abc133b1a5b6b60eb00e4ff25a64afb363a85a768
pdf-embedded-file PDF EmbeddedFile object 1 at offset 0xE66E3 163 bytes
embedded_file_obj0002.bin
e7b050b4d5f9b000166db6c39fc3cec28e0f559d74566f01b618f030ad2f2e27
pdf-embedded-file PDF EmbeddedFile object 2 at offset 0xE67D3 1587 bytes
embedded_file_obj0003.bin
affe261c3500eacffd2adc8024f5e26b3b729a11069254b580ba2177ffbe0980
pdf-embedded-file PDF EmbeddedFile object 3 at offset 0xE6AC9 25015 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 long base64-like blob(s).
embedded_file_obj0004.bin
560dcced2df6f65386a395771a4721a00980be4d89cc752639746882322da5c3
pdf-embedded-file PDF EmbeddedFile object 4 at offset 0xEAF63 2518 bytes
embedded_file_obj0005.bin
500856001a9edb17a299f41c8b34871c12c85d56ec8eff03ef181fca24bb96b5
pdf-embedded-file PDF EmbeddedFile object 5 at offset 0xEB25F 200 bytes
embedded_file_obj0006.bin
863537ccdffd88224d5b70221bc496b5600aa8beb0feda26a0ac48081644ac35
pdf-embedded-file PDF EmbeddedFile object 6 at offset 0xEB353 237 bytes
embedded_file_obj0007.bin
385ee16f9e56270fc4cd495ba71f508ac4f3a53b1bbd78bc1f8ca79af5d84793
pdf-embedded-file PDF EmbeddedFile object 7 at offset 0xEB469 1533 bytes
embedded_file_obj0008.bin
2ebdd7efeaa1190ff6bad8cbd649b313e3969564018f204e7385b97c2fab1e19
pdf-embedded-file PDF EmbeddedFile object 8 at offset 0xEB726 80 bytes
embedded_file_obj0009.bin
4a60a9864cdf7382475d51051a03fdc43b32c31eb508893ccfccece34957f9f1
pdf-embedded-file PDF EmbeddedFile object 9 at offset 0xEB7CF 56 bytes
stream_001_off00000940.js
91ea259764c68d27b8981a339c02d8ea92224ae5c0d0cd0a7c8f3d645d599090
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x940 902 bytes
stream_007_off000e60ab.bin
785103e079820125430834c8a2f896d512a2c16ee7d224705b6b607f90fec865
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xE60AB 1278 bytes
objstm_0046_00.bin
d487056761a17d11aa7cf24247428a28666ffe8617575aa031ec78325fcaa1f0
pdf-objstm-decoded PDF /ObjStm 46 0 obj (inflated) 1606 bytes
font_01_sfnt_off000eb8d4.bin
3a47365ba29be93b97be381e34ec3c7ef0a10e0f82cdb3dadd6fb11f2800fdb3
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB8D4 36717 bytes