Malicious PDF — malware analysis report

Static analysis result for SHA-256 69bf69f8c3e3f949…

MALICIOUS

PDF

50.9 KB
MD5: 5753788031df8db82bd03c28f5950598 SHA-1: a3511a8bfab52f4a61f85a34ef3c9d3c926db041 SHA-256: 69bf69f8c3e3f949ca35e40e3788fefc8a4a923d80da20655d3362b857d5dff8
216 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

The PDF file contains an embedded script payload and triggers the CVE-2010-0188 exploit for Adobe Reader. This exploit is known to be used for arbitrary code execution, typically to download and run additional malicious content. While specific URLs were not found to be malicious, the presence of the exploit and embedded script strongly indicates a malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 7

  • Adobe Reader LibTIFF XFA image exploit — CVE-2010-0188 critical CVE likely CVE_2010_0188
    PDF contains the CVE-2010-0188 exploit template: XFA JavaScript heap-spray setup, a generated TIFF image payload, and assignment of that TIFF data to an XFA image field rawValue to trigger Adobe Reader's LibTIFF parser.
  • XFA form contains risky executable script high CVE related PDF_XFA_SCRIPT
    PDF embeds an XFA form whose script block contains exploit, submission/launch, or shell-execution primitives. Ordinary LiveCycle print/update scripts are left as generic XFA/JS signals unless stronger behavior is present.
  • ClamAV: Pdf.Exploit.Dropped-93 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Dropped-93
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded script payload in PDF stream low PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0008.bin
f6fb1757fa4500fc7dfbfa78a6bd5673be07c89eb9b26476557c971976a46822
pdf-embedded-file PDF EmbeddedFile object 8 at offset 0xC6 51409 bytes