Malicious PDF — malware analysis report

Static analysis result for SHA-256 fef2afe9f9f5b09e…

MALICIOUS

PDF

16.6 KB
MD5: e35f00b8786d1defb188913bc2d10819 SHA-1: 63c3fceccc34650d0ed52bc3801a76287e645733 SHA-256: fef2afe9f9f5b09eff0a6e2a52b703a98d8fba789a5e04421106c5c4bce4cd24
128 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File T1204 User Execution T1059.001 PowerShell

The sample is a PDF file that exploits CVE-2010-0188, a known vulnerability in Adobe Reader related to XFA forms. The heuristic firings indicate that the XFA payload was decoded from a raw stream, suggesting an attempt to execute malicious code. The embedded URL, while seemingly benign, is part of the XFA structure and could be used in conjunction with the exploit. The primary attack vector is likely user execution of the malicious PDF.

Heuristics 4

  • Adobe Reader LibTIFF XFA image exploit — CVE-2010-0188 critical CVE likely CVE_2010_0188
    PDF contains the CVE-2010-0188 exploit template: XFA JavaScript heap-spray setup, a generated TIFF image payload, and assignment of that TIFF data to an XFA image field rawValue to trigger Adobe Reader's LibTIFF parser.
  • ClamAV: Pdf.Exploit.Agent-36835 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Exploit.Agent-36835
  • XFA form low PDF_XFA
    PDF uses XML Forms Architecture — can contain script logic
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://www.xfa.org/schema/xfa-template/2.5/