Malicious PDF — malware analysis report

Static analysis result for SHA-256 fe3fb7447a655980…

MALICIOUS

PDF

78.7 KB
MD5: ff5f086d3b2ceb5f03bbf98e1e2e3072 SHA-1: 470f05f0f843426a0d9721d19b96214d4de59a91 SHA-256: fe3fb7447a655980b778f0808b466c9116b94b0df6f66b9ff2a59610536cf46d
96 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File: Malicious PDF T1059.001 Command and Scripting Interpreter: PowerShell

The PDF file exploits CVE-2010-0188, a vulnerability in Adobe Reader related to LibTIFF XFA images. This exploit allows for the execution of arbitrary code. The embedded file and script payload markers further indicate malicious intent. The embedded URLs, while mostly benign or unknown, are part of the document's structure related to the XFA form.

Heuristics 5

  • Adobe Reader LibTIFF XFA image exploit — CVE-2010-0188 critical CVE likely CVE_2010_0188
    PDF contains the CVE-2010-0188 exploit template: XFA JavaScript heap-spray setup, a generated TIFF image payload, and assignment of that TIFF data to an XFA image field rawValue to trigger Adobe Reader's LibTIFF parser.
  • Embedded script payload in PDF stream medium PDF_EMBEDDED_SCRIPT_PAYLOAD
    PDF stream bytes contain an HTML/XFA <script> tag without accompanying Windows shell-execution primitives — common in accessible XFA forms but worth surfacing for analyst review.
  • Embedded file low PDF_EMBEDDED
    PDF embeds a file attachment — could carry an executable or another weaponised document as a nested payload
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ns.adobe.com/xdp/
    • http://www.xfa.org/schema/xfa-template/2.5/
    • http://www.xfa.org/schema/xfa-data/1.0/

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
embedded_file_obj0008.bin
ac2b01ef0922bd7919272c08b72f2005172d9d75e6e9cc63eddd3fcada8a8de2
pdf-embedded-file PDF EmbeddedFile object 8 at offset 0xC6 79828 bytes