Cracked-software download doorway (base64-obfuscated)

PDF_CRACKED_SOFTWARE_DOWNLOAD_DOORWAY

← All detection heuristics · PDF

high PDF_CRACKED_SOFTWARE_DOWNLOAD_DOORWAY

What it means

PDF's embedded link hides a pirated-software title as a base64 blob in the URL (and/or carries the download| doorway marker).

Why it fires

TCPDF-generated SEO doorway PDFs that rank for software-piracy searches and funnel users to fake crack/keygen download pages. Unlike the plaintext link-farm lure, the pirated-software title is base64-encoded inside a single URL's path/query (never in visible text), which evades the visible-text and multi-link plaintext rules. The rule fires on the exact 'download|' doorway-template marker or on a base64 URL segment that decodes to piracy vocabulary (crack, keygen, serial key, torrent, patch), both of which a legitimate document effectively never produces. The PDF carries no parser exploit — the risk is the linked crack-download destination, so it is capped at suspicious on its own.

Other PDF heuristics

PDF_LAUNCH_JS_PROTOCOL PDF_LAUNCH_COMMAND PDF_LAUNCH_MSHTA PDF_ADOBE_QR_UNLOCK_LURE PDF_JS_URL_KEYED_READER_EXPLOIT_KIT CVE_2009_2990_U3D_AUTOACTIVATE PDF_ANNOT_AUTHOR_EVAL_STAGER PDF_ANNOT_SUBJECT_HEX_EVAL_STAGER PDF_ANNOT_SUBJECT_MARKER_EVAL_STAGER PDF_JS_BASE_N_TOKEN_DOWNLOADER PDF_BASE64_PE_PAYLOAD PDF_BRAND_INVOICE_LURE_OFFDOMAIN PDF_BRAND_INVOICE_CLOUD_EMAIL_LURE PDF_CORPORATE_PRESENTATION_CLOUD_REDIRECT_LURE PDF_CORRUPTED_FILE_UPDATE_LURE PDF_CRACKED_SOFTWARE_SHORTLINK_LURE PDF_GAME_HACK_SEO_LINK_FARM PDF_DISTRIBUTED_PIRACY_LINK_FARM PDF_DOCUSIGN_DOWNLOAD_LURE PDF_DOCUMENT_ACTION_HOST_MISMATCH_LURE PDF_DYNAMIC_DNS_DOCUMENT_LINK_FARM PDF_SWF_NATIVE_MEMORY_CORRUPTION_PAYLOAD PDF_EMBEDDED_PE_PAYLOAD CVE_2010_1240_EMBEDDED_EXPORT_LAUNCH