Malicious PDF — malware analysis report

Static analysis result for SHA-256 8d7c87023df78758…

MALICIOUS

PDF

89.7 KB
MD5: ec93d52520535cb6652ff51d4e066723 SHA-1: 05815d499f76daeeac5327c5dbac352389fe1116 SHA-256: 8d7c87023df787583cf2a98cc4ba27a429abaf744b506204cfec8097d1aaf460
190 Risk Score

Malware Insights

MITRE ATT&CK
T1203 Exploitation for Client Execution T1059.001 PowerShell

The file is a PDF document that exploits CVE-2010-0188, a vulnerability in Adobe Reader related to XFA forms and LibTIFF. The embedded script payload within the XFA form is indicative of an attempt to execute arbitrary code. This is further supported by ClamAV detecting it as Pdf.Exploit.Agent-6136306-0. The primary attack vector is the exploitation of a known vulnerability in PDF rendering software.

Heuristics 6

  • Adobe Reader LibTIFF XFA image exploit — CVE-2010-0188 critical CVE likely CVE_2010_0188
    PDF contains the CVE-2010-0188 exploit template: XFA JavaScript heap-spray setup, a generated TIFF image payload, and assignment of that TIFF data to an XFA image field rawValue to trigger Adobe Reader's LibTIFF parser.
  • XFA form contains executable script high CVE related PDF_XFA_SCRIPT
    PDF embeds an XFA form whose dataset contains a <script> or <xfa:script> block — XFA scripting has been the exploit primitive for several Adobe Reader RCEs (CVE-2010-0188 family, CVE-2018-4901, and others). Plain XFA without scripts is far less risky.
  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_0000023c.bin
e4bf446d7aad2130a86311f25e08efc50f8a5498ce8bccf6084405953cf3012f
pdf-embedded-script PDF raw stream script payload at offset 0x23C 91147 bytes