Malicious PDF — malware analysis report

Static analysis result for SHA-256 bc684f369be50003…

MALICIOUS

PDF

24.0 KB
MD5: 64efb32f2947dc883120f3e3506925a8 SHA-1: 2bcff98cb720e595f3e1dc75c72e1ffc4abccba8 SHA-256: bc684f369be50003884d6099e9a56c335c5d532b5fec5a9ceca3091015f8ceef
128 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1566.001 Spearphishing Attachment

The sample is a PDF file that contains an XFA form, which is a known vector for exploiting Adobe Reader vulnerabilities. Specifically, the 'CVE_2010_0188' heuristic firing indicates exploitation of the LibTIFF component. The embedded URL, while seemingly benign, is present within the document structure. The ClamAV detection further confirms its malicious nature. The exploit likely leads to the execution of a secondary payload, although the exact mechanism is not detailed in the provided heuristics.

Heuristics 4

  • Adobe Reader LibTIFF XFA image exploit — CVE-2010-0188 critical CVE likely CVE_2010_0188
    PDF contains the CVE-2010-0188 exploit template: XFA JavaScript heap-spray setup, a generated TIFF image payload, and assignment of that TIFF data to an XFA image field rawValue to trigger Adobe Reader's LibTIFF parser.
  • ClamAV: Pdf.Exploit.Agent-36821 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36821
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.xfa.org/schema/xfa-template/2.5/