Malicious PDF — malware analysis report

Static analysis result for SHA-256 4ae418d3115dcdce…

MALICIOUS

PDF

24.1 KB
MD5: 766eb9026696fcd6a59b436fa3b9db35 SHA-1: 80ef885e5c40c93be8c918f39f084da0fde04296 SHA-256: 4ae418d3115dcdce1d0a9a9cce08a25a32a49203756aaa19abd539259def0cfa
128 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.002 Spearphishing Attachment T1190 Exploit Public-Facing Application

The sample is a PDF document that contains an XFA form, which is a known vector for exploiting vulnerabilities in Adobe Reader. Specifically, the CVE-2010-0188 heuristic indicates exploitation of the LibTIFF vulnerability within Adobe Reader's XFA processing. The embedded URL, while seemingly benign, is part of the XFA template structure and could potentially be used to download additional malicious content. The ClamAV detection further confirms the malicious nature of the file.

Heuristics 4

  • Adobe Reader LibTIFF XFA image exploit — CVE-2010-0188 critical CVE likely CVE_2010_0188
    PDF contains the CVE-2010-0188 exploit template: XFA JavaScript heap-spray setup, a generated TIFF image payload, and assignment of that TIFF data to an XFA image field rawValue to trigger Adobe Reader's LibTIFF parser.
  • ClamAV: Pdf.Exploit.Agent-36821 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36821
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.xfa.org/schema/xfa-template/2.5/