PDF exploit evasion(33939)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

PDF exploit evasion(33939)

Dear all,

Our device warned us of pdf exploit evasion. (id:33939)

But, no information on that.

Please give me information.

Best regards

tomohiro

3 REPLIES 3

L6 Presenter

When you login to https://support.paloaltonetworks.com/ click on "Threat Database" in "Find Answers" (to the left or the right).

In the search box type "33939" (without the quotes), make sure "vulnerability" (for this case) is selected in "type" and finally click on the Find-button.

However... doing the above will only bring you the obvious:

"
Detail

Attack Name     PDF Exploit Evasion Found
Description     This alert indicates that PDF exploit evasion has been found on your network.
Threat ID     33939
Severity    
informational
Category     info-leak
"

So ehm... anyone else with ideas? 🙂

L3 Networker

Hi Tomohiro,

This signature is looking for use of double- and triple-encoded data within PDFs.  This is a commen evasion technique that malicious PDFs use to hide their malicious payload.  However, legimate PDFs can sometimes use double- (and perhaps triple-) encoded data as well, and so this signature is rated as "informational".  In fact, some PDF reports generated by the Palo Alto Networks firewalls can trigger this informational signature.

This signature, just like any other informational signature, is not the highest priority and should not necessarily trigger immediate alarm, however keeping an eye on instances of this alert for PDFs from untrusted sources is a good idea.

Hi, tettema

Thank you for your explanation. I understood this sigunagure.

Best regards,

Tomohiro

  • 4594 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!