- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-16-2012 11:37 PM
Dear all,
Our device warned us of pdf exploit evasion. (id:33939)
But, no information on that.
Please give me information.
Best regards
tomohiro
03-17-2012 04:21 AM
When you login to https://support.paloaltonetworks.com/ click on "Threat Database" in "Find Answers" (to the left or the right).
In the search box type "33939" (without the quotes), make sure "vulnerability" (for this case) is selected in "type" and finally click on the Find-button.
However... doing the above will only bring you the obvious:
"
Detail
Attack Name PDF Exploit Evasion Found
Description This alert indicates that PDF exploit evasion has been found on your network.
Threat ID 33939
Severity
informational
Category info-leak
"
So ehm... anyone else with ideas? 🙂
03-19-2012 10:22 AM
Hi Tomohiro,
This signature is looking for use of double- and triple-encoded data within PDFs. This is a commen evasion technique that malicious PDFs use to hide their malicious payload. However, legimate PDFs can sometimes use double- (and perhaps triple-) encoded data as well, and so this signature is rated as "informational". In fact, some PDF reports generated by the Palo Alto Networks firewalls can trigger this informational signature.
This signature, just like any other informational signature, is not the highest priority and should not necessarily trigger immediate alarm, however keeping an eye on instances of this alert for PDFs from untrusted sources is a good idea.
03-20-2012 08:55 PM
Hi, tettema
Thank you for your explanation. I understood this sigunagure.
Best regards,
Tomohiro
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!