FILE-PDF -- Snort has detected suspicious traffic related to a PDF file. PDFs are easily exploitable. They include many ways to encapsulate data and are often targeted by attackers, who use the PDF's household name status for social engineering. Therefore, Snort includes Many PDF-targeted rules.
FILE-PDF Adobe Acrobat Reader start-of-file alternate header obfuscation
This event is generated when network traffic that indicates an Adobe PDF with an alternate header for obfuscation purposes has been observed. Impact: Possible detection evasion attempt. Details: This event indicates that an Adobe PDF with an alternate header for obfuscation purposes has been observed. Ease of Attack: Simple.
No information provided
No public information
No known false positives
Cisco Talos
No rule groups
None
No information provided
None