Credential / secure-document lure with single non-reputable link

PDF_CREDENTIAL_LURE_NONREPUTABLE_LINK

← All detection heuristics · PDF

medium PDF_CREDENTIAL_LURE_NONREPUTABLE_LINK

What it means

Thin PDF whose rendered text is a credential / secure-document / identity-verification lure and whose only clickable action links to a non-reputable host.

Why it fires

The text-layer variant of the malspam carrier. The image-only lure rule requires an image-heavy, near-textless page (n_text < 3), so it misses Google-Docs-rendered phishing PDFs that carry a CID/ToUnicode text layer — SSA/IRS 'identity verification', 'secured Adobe PDF document' gates, French 'fichier sécurisé — voir le document'. The detector inspects the rendered text for a strong credential/secure-document lure phrase and fires when the page is thin and its sole external link (1–2 distinct) is not known-good. Suspicious rather than malicious: the lure text plus a lone non-reputable link is the corroboration; ML/AV signals push it higher.

Other PDF heuristics

PDF_LAUNCH_JS_PROTOCOL PDF_LAUNCH_COMMAND PDF_LAUNCH_MSHTA PDF_ADOBE_QR_UNLOCK_LURE PDF_JS_URL_KEYED_READER_EXPLOIT_KIT CVE_2009_2990_U3D_AUTOACTIVATE PDF_ANNOT_AUTHOR_EVAL_STAGER PDF_ANNOT_SUBJECT_HEX_EVAL_STAGER PDF_ANNOT_SUBJECT_MARKER_EVAL_STAGER PDF_JS_BASE_N_TOKEN_DOWNLOADER PDF_BASE64_PE_PAYLOAD PDF_BRAND_INVOICE_LURE_OFFDOMAIN PDF_BRAND_INVOICE_CLOUD_EMAIL_LURE PDF_CORPORATE_PRESENTATION_CLOUD_REDIRECT_LURE PDF_CORRUPTED_FILE_UPDATE_LURE PDF_CRACKED_SOFTWARE_SHORTLINK_LURE PDF_GAME_HACK_SEO_LINK_FARM PDF_DISTRIBUTED_PIRACY_LINK_FARM PDF_DOCUSIGN_DOWNLOAD_LURE PDF_DOCUMENT_ACTION_HOST_MISMATCH_LURE PDF_DYNAMIC_DNS_DOCUMENT_LINK_FARM PDF_SWF_NATIVE_MEMORY_CORRUPTION_PAYLOAD PDF_EMBEDDED_PE_PAYLOAD CVE_2010_1240_EMBEDDED_EXPORT_LAUNCH