Malicious PDF — malware analysis report

Static analysis result for SHA-256 d465c32fdf5da864…

MALICIOUS

PDF

99.8 KB
MD5: fe076cdffb3d4a5cc7295fbb03ad9e9d SHA-1: 954a98a2e023feeccaf56efc8bb0891153cd18ab SHA-256: d465c32fdf5da864645ec1f87bc17d3f3d7e3b6d88853a6a331fe8d878f962d7
96 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: User Execution T1566.001 Phishing: Spearphishing Attachment T1203 Exploitation for Client Execution

This PDF file exploits CVE-2010-0188, a vulnerability in Adobe Reader related to LibTIFF XFA image processing. The critical heuristic firing indicates that the sample attempts to leverage this known exploit for code execution. The presence of embedded file artifacts further supports the malicious nature of the document, likely intended to deliver a secondary payload upon opening.

Heuristics 5

  • Adobe Reader LibTIFF XFA image exploit — CVE-2010-0188 critical CVE likely CVE_2010_0188
    PDF contains the CVE-2010-0188 exploit template: XFA JavaScript heap-spray setup, a generated TIFF image payload, and assignment of that TIFF data to an XFA image field rawValue to trigger Adobe Reader's LibTIFF parser.
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0008.bin
360ce41917cb9c4d538e99f7db32f8d24f54d254dd2b336dfba484fc23adf5be
pdf-embedded-file PDF EmbeddedFile object 8 at offset 0xC6 101440 bytes