Exit
  • Global community
    • Language:
      • Deutsch
      • English
      • Español
      • Français
      • Português
  • 日本語コミュニティ
  • 한국 커뮤니티
0

Is this PDF file up to no good?

Community Beginner ,
Sep 28, 2024 Sep 28, 2024

I recieved a PDF file a while back that I believe to be malicious.  I'm wondering if anyone could tell me what SOPHIA means when it comes to Adobe.  This is one of the files that the PDF writes.

 

C:\Users\<USER>\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\SOPHIA.json

 

There is a lot more to this file, but this is the only thing i'm asking about right now.

 

Is this a normal file?

TOPICS
PDF
3.6K
Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
Sep 29, 2024 Sep 29, 2024

This is not a PDF file, but a JSON file, which can contain data and code, which can be (in theory) malicious. But unless you share the file with us there's really no way to say for sure. And SOPHIA doesn't mean anything in the Adobe-world, as far as I know. It's just the name of the file/folder.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Sep 30, 2024 Sep 30, 2024

Hi,

 

I have a similar issue too. Here is the thing the file (or folder SOPHIA) has been created by Adobe Acrobat. On some computers, the file does not exist. The problem I have is similar to this isssue https://www.reddit.com/r/techsupport/comments/z7mozw/stealth_malware_keeps_destroying_wifibluetooth/   when I use virustotal with some random pdf files (in different sizes) I get similar results. Some of the results are flagged as "Mitre" I am not sure whether it is legit or not. However, the file do not exists on some pc of my friends. I deleted the folder and it is created automatically when I open a pdf.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
Sep 23, 2025 Sep 23, 2025

@m_8223  , 

 

Most interesting ==> "Mitre"

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Beginner ,
Oct 16, 2024 Oct 16, 2024

I don't have direct access to the file at the moment.  Would it be appropriate to share its Virus Total report?

 

https://www.virustotal.com/gui/file/3058863cd7da6ac3993305641a06c47c72d3618cc66faf19daf02b3658490160

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
Oct 16, 2024 Oct 16, 2024

What's the issue? It doesn't look like it detected anything wrong with it.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Apr 30, 2025 Apr 30, 2025

I encountered a similar issue. In addition to what's been reported regarding the creation of SOPHIA, I received a PDF today that appears to perform several other actions. Is there a way I can share it with you for analysis?

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
Sep 23, 2025 Sep 23, 2025
LATEST

@arthur_moncosso_9366 , 

 

This is not the most responsible way to share a file that you suspect could be the culprit of spreading malware in your work environment. Specifically in a public Internet forum. 

 

As far as I would be concerned, you yourself could be playing the victim with nefarious intentions (no offense intended, just healthy paranoia).

 

Please use the most appropriate channels (linked below) if you suspect this file indeed poses a security threat to the overall Internet community:

 

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Adobe Employee ,
Oct 21, 2024 Oct 21, 2024

Hi @carl_6924 

 

This is a json file downloaded by Reader for some of its internal functioning. Are you facing any issue due to this file?

 

Regards

Ravi

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
New Here ,
Sep 21, 2025 Sep 21, 2025

This is triggering threat detection and malware warnings in VirusTotal and whilst trying to upload PDFs to GoogleDrive.... which isn't a great user experience for Adobe Customers.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines