• Link to Rss this site
  • Link to LinkedIn
  • Link to Youtube
  • Link to X
  • Link to Instagram
  • English English English en
  • Deutsch Deutsch German de
Sales: +49 5251 304-800 | Support: +49 5251 304-636
NoSpamProxy
  • PRODUCT
    • NoSpamProxy Cloud
    • NoSpamProxy Protection
    • NoSpamProxy Encryption
    • NoSpamProxy Large Files
    • NoSpamProxy Disclaimer
    • NoSpamProxy 25Reports
  • SOLUTIONS
    • M365 Mail Security
    • Managed Certificates
    • 32Guards
    • AS4
  • RESOURCES
    • Documentation
    • Forum
    • Webcast Training
    • Training Courses
    • Support
    • Software Download
  • PARTNERS
    • Finding Resellers
    • Becoming Reseller
    • Partner Portal
    • NFR Licenses
  • COMPANY
    • Contact
    • Testimonials
    • Team
    • Career
    • Events
    • Awards
  • PRICES
  • BLOG
    • Blog
    • Newsletter Subscription
  • FREE TRIAL VERSION
    • Price Request
    • Free Trial Version
  • English
    • Deutsch
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • MalDoc in PDF Gefahr durch in PDFs versteckte Word Dateien

MalDoc in PDF: Danger from Word files hidden in PDFs

Stefan Feist | Technischer Redakteur
Author: Stefan FeistTechnical Writerhttps://www.linkedin.com/in/stefan-feist-23b257b0/–Connect on LinkedIn

Cybercriminals are constantly finding new ways to spread their malware. Currently, experts are warning about malicious Word documents embedded in PDF files. Read our blog article to learn what MalDoc in PDF is and how you can protect yourself.

08.09.2023|Last edited:11.08.2025

The Japanese CERT (JPCERT) is currently warning about a criminal technique called “MalDoc in PDF”. This technique hides malicious Word documents in PDF files, which is why malicious code contained in them cannot be detected by many analysis tools.

One file – two file formats

In this case, the experts were faced with a so-called polyglot file, i.e. a file that contains two different file formats and, depending on the application used, can be interpreted and executed as more than one file type.

In the case of MalDoc in PDF, the malicious file is recognized as a PDF by most programs, but as a Word document (.doc, .docx) by Office programs. This is possible because the file has a PDF structure, including magic numbers.

JPCERT has posted the following video on YouTube to show how MalDoc presents itself in PDF on Windows:

Macros download malicious code

In the examined cases, the PDF file contains a Word document with a VBS macro as MHT (MIME Encapsulation of Aggregate HTML Documents), i.e. a supposed archive of HTML pages. This macro leads to the download and installation of a contaminated MSI file. Because virus scanners only recognize the PDF document, the malicious code can be distributed – at least if macros are not disabled in Word. The attack does not bypass configured macro locks.

The malicious macros are also not executed when the file is opened in PDF readers or similar software.

The security researchers write that they first detected MalDoc in PDF in an attack in July 2023. However, information about the type of malware is not yet available.

What NoSpamProxy customers must do now

NoSpamProxy customers are protected from MalDoc in PDF if the content filter is configured accordingly, which is quite simple.

MalDoc in PDF recognizes NoSpamProxy as an unreadable PDF document. To reject these files, you just need to create a corresponding content filter set entry in your content filter.

Select as conditions

  • the file type Unreadable PDF document and
  • the file names *.doc and *.docx.

Setting the required conditions in NoSpamProxy Server

MalDoc in PDF conditions in NoSpamProxy Server

Setting the required conditions in NoSpamProxy Cloud

MalDoc in PDF conditions in NoSpamProxy Cloud

Reject all emails of this type using the appropriate content filter actions. When doing so, make sure that the corresponding content filter set entry appears before (above) other Office-related entries:

Order of content filter set entries in NoSpamProxy Server

The corresponding content filter set entry must be above other Office-related entries:

MalDoc in PDF content filter set entries in NoSpamProxy Server

Order of content filter set entries in NoSpamProxy Cloud

The corresponding content filter set entry must be above other Office-related entries:

32Guards also protects against MalDoc in PDF

From now on, a corresponding detection is also active in 32Guards, where the described combination of file type and file name is assigned 4 SCL points.

Protection from MalDoc in PDF with NoSpamProxy Protection

With NoSpamProxy you reliably protect your company against malware attacks. You don’t have NoSpamProxy in use yet? Request your free trial version now!

Get your free NoSpamProxy trial now!
  • share 
  • share 
  • share 
  • email 

SEARCH

PRODUCT

  • All Topics
  • NoSpamProxy Cloud
  • NoSpamProxy Protection
  • NoSpamProxy Encryption
  • NospamProxy Large Files

You need support?

You can find more information about NoSpamProxy in our documentation and forum.

CATEGORY

  • All Topics
  • News
  • Product
  • Tech & Support
  • Events

NoSpamProxy Newsletter

Subscribe to Newsletter
RSS Feed Logo RSS Feed Logo Subscribeto RSS Feed

NoSpamProxy

  • NoSpamProxy Cloud
  • NoSpamProxy Encryption
  • NoSpamProxy Large Files
  • NoSpamProxy Disclaimer
  • Price request
  • Team
  • Career
  • General terms and conditions
  • Data Protection Information for Business Partners and Applicants
  • Cybersecurity (PSIRT)

Partners

  • Becoming a reseller
  • Partners
  • Order Certificates
  • Newsletter

Categories

  • All topics
  • News
  • Support
  • Updates
  • Order certificates

Latest News

  • New features in 25Reports: more control, more security, more transparency17.11.2025 - 10:29
  • Flow Guard in NoSpamProxy: Ihr Schutz gegen E-Mail-Missbrauch 800x800
    Flow Guard in NoSpamProxy: Your protection against email abuse07.11.2025 - 14:07
  • Intelligentes Greylisting mit NoSpamProxy 800x800
    Intelligent greylisting with NoSpamProxy30.10.2025 - 13:35
IMPRINT • EULA • Privacy Policy • • © 2025 Net at Work GmbH
  • Link to Rss this site
  • Link to LinkedIn
  • Link to Youtube
  • Link to X
  • Link to Instagram
Link to: NIS2 – What the directive means for you Link to: NIS2 – What the directive means for you NIS2 – What the directive means for youNIS2 Network and Information Systems Directive Preview Link to: New SwissSign MPKI: What you need to do now Link to: New SwissSign MPKI: What you need to do now Info IconNew SwissSign MPKI: What you need to do now
Scroll to top Scroll to top Scroll to top