Get the App
SLTechnology News&Howtos  ›  IT Information  › 

The organization alerts and discovers a new PDF attack technology, which can bypass routine detection and execute malicious code.

Shulou Source: shulou.com Published: 2023-11-24 19:08:18 10月01日 Update

CTOnews.com August 31 news, Japanese computer emergency response team JPCERT recently issued a warning, found a malicious Word documents embedded in the PDF format of a new type of attack, can bypass pdfid and other traditional PDF analysis tools.

Officially, the technology is named "MalDoc in PDF". The attacker creates a special PDF format file. Once opened through the Microsoft Word application, the user will activate the macro command in the file and execute malicious code.

In the sample observed by the agency, although the malicious file is in PDF format, the real suffix is .doc. If the user device configures that the default doc file processing application is Word, double-clicking the PDF will automatically invoke Word to open it.

Yuma Masubuchi, a security expert at the agency, said that attackers would create mht files in Word and attach a macro to the PDF file object, which is difficult to detect by traditional PDF analysis tools such as pdfid.

CTOnews.com is here to attach the original address, interested users can click to read.

Tags: Files malicious attacks formats users traditions tools attackers analysis applications code technology detection security experts interests original text suffixes addresses macro commands Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Shulou Technology MySQL Redmi NVidia Apple