Image lure linking to an SEO redirector (free-download phishing)

PDF_SEO_UTM_REDIRECTOR_LINK

← All detection heuristics · PDF

high PDF_SEO_UTM_REDIRECTOR_LINK

What it means

PDF image lure with a clickable multi-word utm_term / FeedBurner-proxied SEO redirector link — the 'free ebook/manual download' phishing family.

Why it fires

The 'free ebook / solution-manual / document download' SEO-phishing family ships a tiny image-only (or image + filler-text) PDF whose single clickable /URI is a search-keyword gateway — a multi-word utm_term/keyword redirector (the natural-language phrase the page ranks for) or a FeedBurner-proxied feedproxy.google.com/~r/.../uplcv hop abusing a trusted Google host. The PDF carries no exploit; the payload lives on the linked destination. The broader PDF_SEO_DISPOSABLE_LINK_FARM detector requires many links and does not cover single-link variants. ClamAV and the ML model may also miss variants padded with a few text pages. Pairing the redirector with an image lure produces a HIGH finding regardless of text-page count or ClamAV/ML results. The redirector alone (no image lure) is surfaced at LOW as an IOC only.

Other PDF heuristics

PDF_LAUNCH_JS_PROTOCOL PDF_LAUNCH_COMMAND PDF_LAUNCH_MSHTA PDF_ADOBE_QR_UNLOCK_LURE PDF_JS_URL_KEYED_READER_EXPLOIT_KIT CVE_2009_2990_U3D_AUTOACTIVATE PDF_ANNOT_AUTHOR_EVAL_STAGER PDF_ANNOT_SUBJECT_HEX_EVAL_STAGER PDF_ANNOT_SUBJECT_MARKER_EVAL_STAGER PDF_JS_BASE_N_TOKEN_DOWNLOADER PDF_BASE64_PE_PAYLOAD PDF_BRAND_INVOICE_LURE_OFFDOMAIN PDF_BRAND_INVOICE_CLOUD_EMAIL_LURE PDF_CORPORATE_PRESENTATION_CLOUD_REDIRECT_LURE PDF_CORRUPTED_FILE_UPDATE_LURE PDF_CRACKED_SOFTWARE_SHORTLINK_LURE PDF_GAME_HACK_SEO_LINK_FARM PDF_DISTRIBUTED_PIRACY_LINK_FARM PDF_DOCUSIGN_DOWNLOAD_LURE PDF_DOCUMENT_ACTION_HOST_MISMATCH_LURE PDF_DYNAMIC_DNS_DOCUMENT_LINK_FARM PDF_SWF_NATIVE_MEMORY_CORRUPTION_PAYLOAD PDF_EMBEDDED_PE_PAYLOAD CVE_2010_1240_EMBEDDED_EXPORT_LAUNCH