Malicious PDF — malware analysis report

Static analysis result for SHA-256 ec88a1ad8cd66562…

MALICIOUS

PDF

99.6 KB
MD5: db2412eb701dd2ca3fa4dc5acb3c1a9c SHA-1: 867396224c82ccadca93418cef1bd3412fcf6019 SHA-256: ec88a1ad8cd665629a9192d142751f5e44fb96714ed356c1fd0cc983c3cad8fc
136 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: User Execution: Malicious File T1059.001 Command and Scripting Interpreter: PowerShell

The PDF file exploits CVE-2010-0188, a known vulnerability in Adobe Reader related to XFA forms. The heuristic firings indicate an embedded script payload within an XFA form, suggesting the document is designed to trigger this exploit upon opening. The script likely attempts to download and execute a secondary payload, which is a common attack vector for this type of exploit. No specific family could be identified.

Heuristics 6

  • Adobe Reader LibTIFF XFA image exploit — CVE-2010-0188 critical CVE likely CVE_2010_0188
    PDF contains the CVE-2010-0188 exploit template: XFA JavaScript heap-spray setup, a generated TIFF image payload, and assignment of that TIFF data to an XFA image field rawValue to trigger Adobe Reader's LibTIFF parser.
  • XFA form contains executable script high CVE related PDF_XFA_SCRIPT
    PDF embeds an XFA form whose dataset contains a <script> or <xfa:script> block — XFA scripting has been the exploit primitive for several Adobe Reader RCEs (CVE-2010-0188 family, CVE-2018-4901, and others). Plain XFA without scripts is far less risky.
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0008.bin
a28d64b7086eca338a8e770f840d4a84cd9c922284ebbb62205048db1736ab43
pdf-embedded-file PDF EmbeddedFile object 8 at offset 0xC6 101263 bytes