Password-protected PDF (content uninspectable)

PDF_ENCRYPTED_PASSWORD_REQUIRED

← All detection heuristics · PDF

low PDF_ENCRYPTED_PASSWORD_REQUIRED

What it means

PDF is encrypted with a non-empty user password — it cannot be opened, decrypted, or statically inspected without the password.

Why it fires

Unlike a permission/DRM-sealed PDF that opens with an empty user password (billing statements, signed invoices — the reader decrypts transparently and the analyzer can inspect the content via qpdf), this document requires a real user password to open, so every string and stream is cryptographically inaccessible to static analysis. This is a recognised malware-delivery evasion: the open-password is supplied in the phishing e-mail body so the recipient can open the file while automated AV/sandbox pipelines cannot. It is not malicious on its own (confidential documents are also password-protected), but it means the content was not inspected and should be treated as unknown, not clean.

Other PDF heuristics

PDF_LAUNCH_JS_PROTOCOL PDF_LAUNCH_COMMAND PDF_LAUNCH_MSHTA PDF_ADOBE_QR_UNLOCK_LURE PDF_JS_URL_KEYED_READER_EXPLOIT_KIT CVE_2009_2990_U3D_AUTOACTIVATE PDF_ANNOT_AUTHOR_EVAL_STAGER PDF_ANNOT_SUBJECT_HEX_EVAL_STAGER PDF_ANNOT_SUBJECT_MARKER_EVAL_STAGER PDF_JS_BASE_N_TOKEN_DOWNLOADER PDF_BASE64_PE_PAYLOAD PDF_BRAND_INVOICE_LURE_OFFDOMAIN PDF_BRAND_INVOICE_CLOUD_EMAIL_LURE PDF_CORPORATE_PRESENTATION_CLOUD_REDIRECT_LURE PDF_CORRUPTED_FILE_UPDATE_LURE PDF_CRACKED_SOFTWARE_SHORTLINK_LURE PDF_GAME_HACK_SEO_LINK_FARM PDF_DISTRIBUTED_PIRACY_LINK_FARM PDF_DOCUSIGN_DOWNLOAD_LURE PDF_DOCUMENT_ACTION_HOST_MISMATCH_LURE PDF_DYNAMIC_DNS_DOCUMENT_LINK_FARM PDF_SWF_NATIVE_MEMORY_CORRUPTION_PAYLOAD PDF_EMBEDDED_PE_PAYLOAD CVE_2010_1240_EMBEDDED_EXPORT_LAUNCH