PDF paints image(s) but contains no text operators

PDF_IMAGE_ONLY_LURE

← All detection heuristics · PDF

medium PDF_IMAGE_ONLY_LURE

What it means

PDF has at least one image XObject and zero text-emitting operators in raw or decompressed content streams.

Why it fires

Phishing PDFs are often built by exporting a screenshot to PDF: a single page with one or more image XObjects and no text. The carrier evades text-based scanners (no keywords to match) and delivers its call-to-action purely through rendered pixels — a phone number to call, a QR code to scan, or a link the user is told to type. Distinct from PDF_IMAGE_LURE, which requires a small file and an in-PDF click-action; the detector has neither constraint and looks inside compressed content streams to avoid false positives on real text-bearing PDFs.

Other PDF heuristics

PDF_LAUNCH_JS_PROTOCOL PDF_LAUNCH_COMMAND PDF_LAUNCH_MSHTA PDF_ADOBE_QR_UNLOCK_LURE PDF_JS_URL_KEYED_READER_EXPLOIT_KIT CVE_2009_2990_U3D_AUTOACTIVATE PDF_ANNOT_AUTHOR_EVAL_STAGER PDF_ANNOT_SUBJECT_HEX_EVAL_STAGER PDF_ANNOT_SUBJECT_MARKER_EVAL_STAGER PDF_JS_BASE_N_TOKEN_DOWNLOADER PDF_BASE64_PE_PAYLOAD PDF_BRAND_INVOICE_LURE_OFFDOMAIN PDF_BRAND_INVOICE_CLOUD_EMAIL_LURE PDF_CORPORATE_PRESENTATION_CLOUD_REDIRECT_LURE PDF_CORRUPTED_FILE_UPDATE_LURE PDF_CRACKED_SOFTWARE_SHORTLINK_LURE PDF_GAME_HACK_SEO_LINK_FARM PDF_DISTRIBUTED_PIRACY_LINK_FARM PDF_DOCUSIGN_DOWNLOAD_LURE PDF_DOCUMENT_ACTION_HOST_MISMATCH_LURE PDF_DYNAMIC_DNS_DOCUMENT_LINK_FARM PDF_SWF_NATIVE_MEMORY_CORRUPTION_PAYLOAD PDF_EMBEDDED_PE_PAYLOAD CVE_2010_1240_EMBEDDED_EXPORT_LAUNCH