Image-only PDF links to deceptive (typosquat) host

PDF_IMAGE_LURE_DECEPTIVE_HOST_LINK

← All detection heuristics · PDF

high PDF_IMAGE_LURE_DECEPTIVE_HOST_LINK

What it means

Image-only PDF's clickable action targets a host impersonating a service/brand word with a leetspeak digit substitution (serv1ce, upd4te, …).

Why it fires

Screenshot-like phishing/fake-update PDFs render an image and a single clickable action whose destination host impersonates a security, service, or brand word using a leetspeak digit in place of a letter (e.g. 'serv1ce', 'l0gin', 'm1crosoft', 'payp4l'). The rule fires only when the document is image-only with little real text AND the destination is not a known-good (Tranco/allowlisted) domain, so a legitimate flyer linking to its real site is unaffected. The digit-for-letter substitution is the deception tell.

Other PDF heuristics

PDF_LAUNCH_JS_PROTOCOL PDF_LAUNCH_COMMAND PDF_LAUNCH_MSHTA PDF_ADOBE_QR_UNLOCK_LURE PDF_JS_URL_KEYED_READER_EXPLOIT_KIT CVE_2009_2990_U3D_AUTOACTIVATE PDF_ANNOT_AUTHOR_EVAL_STAGER PDF_ANNOT_SUBJECT_HEX_EVAL_STAGER PDF_ANNOT_SUBJECT_MARKER_EVAL_STAGER PDF_JS_BASE_N_TOKEN_DOWNLOADER PDF_BASE64_PE_PAYLOAD PDF_BRAND_INVOICE_LURE_OFFDOMAIN PDF_BRAND_INVOICE_CLOUD_EMAIL_LURE PDF_CORPORATE_PRESENTATION_CLOUD_REDIRECT_LURE PDF_CORRUPTED_FILE_UPDATE_LURE PDF_CRACKED_SOFTWARE_SHORTLINK_LURE PDF_GAME_HACK_SEO_LINK_FARM PDF_DISTRIBUTED_PIRACY_LINK_FARM PDF_DOCUSIGN_DOWNLOAD_LURE PDF_DOCUMENT_ACTION_HOST_MISMATCH_LURE PDF_DYNAMIC_DNS_DOCUMENT_LINK_FARM PDF_SWF_NATIVE_MEMORY_CORRUPTION_PAYLOAD PDF_EMBEDDED_PE_PAYLOAD CVE_2010_1240_EMBEDDED_EXPORT_LAUNCH