Malicious PDF — malware analysis report

Static analysis result for SHA-256 3c97c84d529ed2bf…

MALICIOUS

PDF

5.3 KB Created: 2002-02-02 59:55:01 Authoring application: e
MD5: 08060f84b8337fcfe7fd59779d52e853 SHA-1: 8356b514eb2d18b733856f79d984a6f886fcf786 SHA-256: 3c97c84d529ed2bff63d31cee914d256ac24fbfc23733fc1de43b59f20ddbb18
100 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.001 PowerShell

The sample is a PDF document that exploits CVE-2010-0188, a vulnerability in Adobe Reader related to LibTIFF XFA image parsing. A JavaScript payload was extracted from a decompressed stream, indicating the likely intent to download and execute a secondary payload. The embedded file and the JavaScript stream are the primary indicators of compromise.

Heuristics 6

  • Adobe Reader LibTIFF XFA image exploit — CVE-2010-0188 critical CVE likely CVE_2010_0188
    PDF contains the CVE-2010-0188 exploit template: XFA JavaScript heap-spray setup, a generated TIFF image payload, and assignment of that TIFF data to an XFA image field rawValue to trigger Adobe Reader's LibTIFF parser.
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: PDFSyntaxError. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0029.bin
bd1107a66576a2b7858d07d93691d0f82f2b266be217667e751b540647b74a43
pdf-embedded-file PDF EmbeddedFile object 29 at offset 0x334 144 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).
stream_003_off0000040e.js
142a3afa1a879d8fb56272b6f80be1b2bac0ad4cfe6b4c9a409f88280838d126
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x40E 52588 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).