Malicious PDF — malware analysis report

Static analysis result for SHA-256 b815b04c42c705aa…

MALICIOUS

PDF

90.0 KB
MD5: fe3b1fa7ff80ffd7274cdd42b43e2119 SHA-1: 1e8856ac43aeb5472a1cbd07e07ab7dc11c7c0c0 SHA-256: b815b04c42c705aab34be89aefd61ff848788a4f61acd3238275cd4f1f61927a
248 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: User Execution T1059.001 Command and Scripting Interpreter: PowerShell

The PDF file contains XFA (XML Forms Architecture) which is known to be a vector for exploits. Specifically, the heuristics indicate the presence of heap spray and exploit code targeting CVE-2010-0188, a vulnerability in Adobe Reader's LibTIFF component. This exploit code is embedded within the XFA form and is designed to execute arbitrary code upon opening the document. No specific malware family was identified, but the exploit's purpose is to deliver a malicious payload.

Heuristics 7

  • Adobe Reader LibTIFF XFA image exploit — CVE-2010-0188 critical CVE likely CVE_2010_0188
    PDF contains the CVE-2010-0188 exploit template: XFA JavaScript heap-spray setup, a generated TIFF image payload, and assignment of that TIFF data to an XFA image field rawValue to trigger Adobe Reader's LibTIFF parser.
  • XFA form contains risky executable script high CVE related PDF_XFA_SCRIPT
    PDF embeds an XFA form whose script block contains exploit, submission/launch, or shell-execution primitives. Ordinary LiveCycle print/update scripts are left as generic XFA/JS signals unless stronger behavior is present.
  • XFA JavaScript heap-spray exploit code critical PDF_XFA_HEAP_SPRAY
    PDF contains XFA script content with heap-spray or shellcode-like JavaScript markers such as large encoded word sequences, util.pack, large arrays, or spray variable names. This is a weaponised Adobe Reader exploit pattern, not a normal interactive form.
  • ClamAV: Pdf.Exploit.Agent-6136306-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-6136306-0
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_pdf_script_0000023c.bin
4c4389ebd6975cf5766063f0f80c94b7b6ae5ff3551017b73bb92d1b94b40d6d
pdf-embedded-script PDF raw stream script payload at offset 0x23C 91488 bytes