Flash ActionScript-3 exploit loader in PDF

PDF_FLASH_AS3_EXPLOIT_LOADER

← All detection heuristics · PDF

critical CVE related PDF_FLASH_AS3_EXPLOIT_LOADER

What it means

Embedded SWF's ActionScript-3 bytecode loads and executes an inner SWF from raw bytes (allowLoadBytesCodeExecution) and/or Vector heap-spray groomers.

Why it fires

The embedded Flash object's ActionScript-3 constant pool (recovered by the SWF/ABC parser) references exploit-loader primitives: LoaderContext.allowLoadBytesCodeExecution (to execute a second-stage SWF decompressed into a ByteArray) and/or Vector.<uint>/Vector.<Number> heap/JIT spray groomers with raw byte writes. Benign Flash content (sound players, scrollable text, Flex widgets) never loads and runs code from raw bytes; this is a staged Flash exploit delivered through the document. The specific Flash CVE lives in the inner second-stage SWF, so attribution stays family-level.

Other PDF heuristics

PDF_LAUNCH_JS_PROTOCOL PDF_LAUNCH_COMMAND PDF_LAUNCH_MSHTA PDF_ADOBE_QR_UNLOCK_LURE PDF_JS_URL_KEYED_READER_EXPLOIT_KIT CVE_2009_2990_U3D_AUTOACTIVATE PDF_ANNOT_AUTHOR_EVAL_STAGER PDF_ANNOT_SUBJECT_HEX_EVAL_STAGER PDF_ANNOT_SUBJECT_MARKER_EVAL_STAGER PDF_JS_BASE_N_TOKEN_DOWNLOADER PDF_BASE64_PE_PAYLOAD PDF_BRAND_INVOICE_LURE_OFFDOMAIN PDF_BRAND_INVOICE_CLOUD_EMAIL_LURE PDF_CORPORATE_PRESENTATION_CLOUD_REDIRECT_LURE PDF_CORRUPTED_FILE_UPDATE_LURE PDF_CRACKED_SOFTWARE_SHORTLINK_LURE PDF_GAME_HACK_SEO_LINK_FARM PDF_DISTRIBUTED_PIRACY_LINK_FARM PDF_DOCUSIGN_DOWNLOAD_LURE PDF_DOCUMENT_ACTION_HOST_MISMATCH_LURE PDF_DYNAMIC_DNS_DOCUMENT_LINK_FARM PDF_SWF_NATIVE_MEMORY_CORRUPTION_PAYLOAD PDF_EMBEDDED_PE_PAYLOAD CVE_2010_1240_EMBEDDED_EXPORT_LAUNCH