Copy link to clipboard
Copied
I recieved a PDF file a while back that I believe to be malicious. I'm wondering if anyone could tell me what SOPHIA means when it comes to Adobe. This is one of the files that the PDF writes.
C:\Users\<USER>\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\SOPHIA.json
There is a lot more to this file, but this is the only thing i'm asking about right now.
Is this a normal file?
Copy link to clipboard
Copied
This is not a PDF file, but a JSON file, which can contain data and code, which can be (in theory) malicious. But unless you share the file with us there's really no way to say for sure. And SOPHIA doesn't mean anything in the Adobe-world, as far as I know. It's just the name of the file/folder.
Copy link to clipboard
Copied
Hi,
I have a similar issue too. Here is the thing the file (or folder SOPHIA) has been created by Adobe Acrobat. On some computers, the file does not exist. The problem I have is similar to this isssue https://www.reddit.com/r/techsupport/comments/z7mozw/stealth_malware_keeps_destroying_wifibluetooth/ when I use virustotal with some random pdf files (in different sizes) I get similar results. Some of the results are flagged as "Mitre" I am not sure whether it is legit or not. However, the file do not exists on some pc of my friends. I deleted the folder and it is created automatically when I open a pdf.
Copy link to clipboard
Copied
Copy link to clipboard
Copied
I don't have direct access to the file at the moment. Would it be appropriate to share its Virus Total report?
https://www.virustotal.com/gui/file/3058863cd7da6ac3993305641a06c47c72d3618cc66faf19daf02b3658490160
Copy link to clipboard
Copied
What's the issue? It doesn't look like it detected anything wrong with it.
Copy link to clipboard
Copied
Copy link to clipboard
Copied
This is not the most responsible way to share a file that you suspect could be the culprit of spreading malware in your work environment. Specifically in a public Internet forum.
As far as I would be concerned, you yourself could be playing the victim with nefarious intentions (no offense intended, just healthy paranoia).
Please use the most appropriate channels (linked below) if you suspect this file indeed poses a security threat to the overall Internet community:
Copy link to clipboard
Copied
Hi @carl_6924
This is a json file downloaded by Reader for some of its internal functioning. Are you facing any issue due to this file?
Regards
Ravi
Copy link to clipboard
Copied
This is triggering threat detection and malware warnings in VirusTotal and whilst trying to upload PDFs to GoogleDrive.... which isn't a great user experience for Adobe Customers.
Find more inspiration, events, and resources on the new Adobe Community
Explore Now