Skip to main content
MROP_25
New Member
October 15, 2025
Question

Attachment Scan Rules

  • October 15, 2025
  • 3 replies
  • 414 views

how is working this rule executable_windows??

 

FortiMail Attachment Scan Rules (executable_windows), was catched this file 1.pdf:( detected by Content Filter, filetype application/javascript filename ABC.js in file ABC2 Integration Document - Phase 1.pdf, attachment scan rule: executable_windows).

 

but when downloaded that file to scan by Sandbox, the file was clean result??

 

Any one had same this problem, and was solved?

3 replies

AEK
SuperUser
SuperUser
October 15, 2025

It seems this PDF file includes a JS script. While when scanned with Sandbox it founds the script is not harmful.

Your FML's content filter doesn't look for malware, it just block the file when it finds a JS script. Your content filter is just working as it is supposed to do.

Since you have a Sandbox, if you need to allow JS scripts that are embedded in PDF files, then your solution would be to allow JS scripts in the content filter. The Sandbox will do the rest.

AEK
New Member
June 11, 2026

HI, we are having the same problem, a few PDFs are being caught with .js embedded, but we don’t have Sandbox, so is our only options are :
1) not to scan PDFs? 
2) manually check each PDFs?

Regards, Damien

AEK
SuperUser
SuperUser
June 11, 2026

Hi Damien

FML does scan PDF files with JS content but it is signature based.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!