Malicious PDF — malware analysis report

Static analysis result for SHA-256 8222675121a86b8b…

MALICIOUS

PDF

904.6 KB
MD5: 7b35aca494422675cbc267b613fb9a45 SHA-1: 88ac4fae59f1b90a60f758bd820545e2f86bc481 SHA-256: 8222675121a86b8b284ffb0a358b592cb7785d3fbc01895d59fd0db39460e008
116 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: User Execution T1059.001 Command and Scripting Interpreter: PowerShell

The PDF file contains a critical heuristic indicating exploitation of CVE-2010-0188, a known vulnerability in Adobe Reader related to XFA forms. Additionally, embedded JavaScript actions and embedded script payloads were detected. The presence of these elements strongly suggests the document is designed to exploit this vulnerability to download and execute a secondary payload, likely for further malicious activity.

Heuristics 9

  • Adobe Reader LibTIFF XFA image exploit — CVE-2010-0188 critical CVE likely CVE_2010_0188
    PDF contains the CVE-2010-0188 exploit template: XFA JavaScript heap-spray setup, a generated TIFF image payload, and assignment of that TIFF data to an XFA image field rawValue to trigger Adobe Reader's LibTIFF parser.
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • JavaScript action low PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • PDF paints image(s) but contains no text operators info PDF_IMAGE_ONLY_LURE
    PDF has 1 image XObject(s) and the content stream contains no text-emitting operators (BT/ET, Tj, TJ, ', ") in either raw bytes or decompressed streams — this is the screenshot-as-PDF pattern used to bypass text-based scanners and to deliver instructions purely through rendered pixels. It is informational unless paired with invisible links or risky URI context.
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xfa/promoted-desc/

Extracted artifacts 13

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0001.bin
87046216f468ff022a004c6f1b2643de71a2ace822950268c7e8803523369f32
pdf-embedded-file PDF EmbeddedFile object 1 at offset 0xD43AC 163 bytes
embedded_file_obj0002.bin
741130904cf17122a0a558d2152514ab50ca39f560c266697198ca04be2693c4
pdf-embedded-file PDF EmbeddedFile object 2 at offset 0xD449D 1596 bytes
embedded_file_obj0003.bin
50d697636168263ad570ee61a90349e5b7422a2d38e0f9831bee2b1a339a58fe
pdf-embedded-file PDF EmbeddedFile object 3 at offset 0xD4794 24975 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 long base64-like blob(s).
embedded_file_obj0004.bin
560dcced2df6f65386a395771a4721a00980be4d89cc752639746882322da5c3
pdf-embedded-file PDF EmbeddedFile object 4 at offset 0xD8C0F 2518 bytes
embedded_file_obj0005.bin
500856001a9edb17a299f41c8b34871c12c85d56ec8eff03ef181fca24bb96b5
pdf-embedded-file PDF EmbeddedFile object 5 at offset 0xD8F0B 200 bytes
embedded_file_obj0006.bin
ce9178a56f9138f5a48e518587c7ff14b65860f1d5be3a8b76dbf047b708a4fb
pdf-embedded-file PDF EmbeddedFile object 6 at offset 0xD8FFF 199 bytes
embedded_file_obj0007.bin
d04ddabff40e4cd9a4a8def00715e01bdeda6a320bf22769bebd07eb116378fa
pdf-embedded-file PDF EmbeddedFile object 7 at offset 0xD90F2 1533 bytes
embedded_file_obj0008.bin
2ebdd7efeaa1190ff6bad8cbd649b313e3969564018f204e7385b97c2fab1e19
pdf-embedded-file PDF EmbeddedFile object 8 at offset 0xD93AD 80 bytes
embedded_file_obj0009.bin
4a60a9864cdf7382475d51051a03fdc43b32c31eb508893ccfccece34957f9f1
pdf-embedded-file PDF EmbeddedFile object 9 at offset 0xD9456 56 bytes
stream_002_off00000363.js
f8721569904600df33f536ddc9f4942717077f9d6c3c4253a8f4de5650fc6531
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x363 1367 bytes
stream_003_off00000549.js
91ea259764c68d27b8981a339c02d8ea92224ae5c0d0cd0a7c8f3d645d599090
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x549 902 bytes
objstm_0044_00.bin
882dbe8f645af46cefc5e2695c3912cf111c9293da733274a1504212921b2c2d
pdf-objstm-decoded PDF /ObjStm 44 0 obj (inflated) 1006 bytes
font_00_sfnt_off000d955b.bin
3a47365ba29be93b97be381e34ec3c7ef0a10e0f82cdb3dadd6fb11f2800fdb3
pdf-font-stream PDF embedded font (sfnt) at offset 0xD955B 36717 bytes