Malicious PDF — malware analysis report

Static analysis result for SHA-256 d3ee0c539b2f5fb8…

MALICIOUS

PDF

2.8 KB
MD5: 0255880635d80b47533815b0cacb3c3e SHA-1: 05c75a26f9c7074a0ef0188552cb1db88c1c9473 SHA-256: d3ee0c539b2f5fb801f97509f0c9decbd334fc185cca5e94d1b3dacdf66382cb
70 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1559.001 Component Object Model Hijacking

The PDF file contains an XFA form and triggers the CVE-2010-0188 exploit for Adobe Reader. This exploit targets a vulnerability in LibTIFF processing within XFA forms, indicating the file is designed to execute arbitrary code upon opening in a vulnerable application. The exploit payload was identified within an embedded XFA image stream.

Heuristics 3

  • Adobe Reader LibTIFF XFA image exploit — CVE-2010-0188 critical CVE likely CVE_2010_0188
    PDF contains XFA image data with an inline crafted TIFF payload and shellcode/delivery markers. This is the data-bound variant of the CVE-2010-0188 Adobe Reader LibTIFF/XFA exploit shape.
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_000_off000002e6.bin
12e955785c01c817cb421746d13949c6fec591aa2228c04086391d1e53f65f47
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2E6 13410 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 1 long base64-like blob(s).