MALICIOUS
60
Risk Score
Machine Learning
- Nyx PDF Classifier clean score 0.0266
Heuristics 1
-
CoolType Type 1 Multiple-Master font overflow — CVE-2010-1797 (jailbreakme) critical CVE likely CVE_2010_1797PDF embeds a Type 1 (PostScript) font that carries Multiple Master Blend keys (BlendDesignPositions/BlendAxisTypes/BlendDesignMap) together with an over-long clear-text overflow filler (a giant repeated-token array, a 1 KB+ contiguous junk token, or a 'blatantly invalid' self-label). Multiple Master is a deprecated Type 1 sub-format whose Blend handling drives a stack buffer overflow in the FreeType / Adobe CoolType font parser — the static shape of the 2010 'jailbreakme' PDF font 0-day (CVE-2010-1797), the /FontFile (Type 1) counterpart to the CVE-2010-2883 SING exploit. The malicious bytes live inside a FlateDecoded /FontFile, so JS, heap-spray and raw-byte rules never see them; rendering one glyph in the font forces the vulnerable parse.
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_type1_off000003eb.bin |
pdf-font-stream | PDF embedded font (type1) at offset 0x3EB | 421102 bytes |
SHA-256: 16ac2b57fe6e55a3dba77e6c6c27b36127789d9d07bdd85abf170e89ff0b3738 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.