Malicious PDF — malware analysis report

Static analysis result for SHA-256 fd3fe24b9b27d2d5…

MALICIOUS

PDF

5.0 KB Created: 2013-10-09 16:18:28
MD5: 1597e1ac325dbc873a6eb0eff0a25620 SHA-1: 16b8eda517590cf4fc8425e63d20b61909d5320f SHA-256: fd3fe24b9b27d2d5628c8d42c0c5116c2987a3d0e2c1d223c6cf3f290d5f4ddf
186 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File T1204.002 Malicious File: User Execution T1059 Command and Scripting Interpreter T1059.001 Command and Scripting Interpreter: PowerShell

The sample is a PDF file identified by ClamAV as 'Pdf.Exploit.CVE_2010_0188-10', indicating it exploits the CVE-2010-0188 vulnerability. ML classification strongly supports this, and an embedded script payload was detected. The embedded artifact was also flagged by ClamAV, confirming its malicious nature. The primary attack vector is likely user execution of the malicious PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • ClamAV: Pdf.Exploit.CVE_2010_0188-10 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.CVE_2010_0188-10
  • ClamAV detection on extracted artifact critical EXTRACTED_FILE_CLAMAV
    ClamAV flagged at least one file extracted from inside this sample. Even when the wrapping document carries no AV detection of its own, a hit on the carved artifact is a strong indicator the sample is a delivery vehicle.
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0004.bin
0da5d2e28cee747a1a91ec6621d33f31d223fae2d06c8f870be63bc6a48db57a
pdf-embedded-file PDF EmbeddedFile object 4 at offset 0x45D 14397 bytes
Detection
ClamAV: Pdf.Exploit.CVE_2010_0188-10
Obfuscation or payload: unlikely