Clickable URL hides a base64-encoded recipient email

PDF_URL_ENCODED_RECIPIENT_EMAIL

← All detection heuristics · PDF

high PDF_URL_ENCODED_RECIPIENT_EMAIL

What it means

A clickable link carries the recipient email base64/URL-encoded in a query parameter or #fragment on generated/wrapper infrastructure.

Why it fires

Phishing kits stamp the target's email into the landing URL so the page pre-fills and tracks the credential form per recipient. When the address is base64- or URL-encoded (in a query parameter or the #fragment, which never reaches origin-side logs) it is deliberately hidden from plain-text inspection. Unlike PDF_QR_RECIPIENT_PERSONALIZED_LINK this does not require an image-heavy lure, so it catches links delivered behind URL-security rewrites (secure-web) or open-redirect wrappers with ordinary text. The decoded token must be a valid email and the host generated/disposable or lure-keyworded, so ordinary tracking parameters do not match.

Other PDF heuristics

PDF_LAUNCH_JS_PROTOCOL PDF_LAUNCH_COMMAND PDF_LAUNCH_MSHTA PDF_ADOBE_QR_UNLOCK_LURE PDF_JS_URL_KEYED_READER_EXPLOIT_KIT CVE_2009_2990_U3D_AUTOACTIVATE PDF_ANNOT_AUTHOR_EVAL_STAGER PDF_ANNOT_SUBJECT_HEX_EVAL_STAGER PDF_ANNOT_SUBJECT_MARKER_EVAL_STAGER PDF_JS_BASE_N_TOKEN_DOWNLOADER PDF_BASE64_PE_PAYLOAD PDF_BRAND_INVOICE_LURE_OFFDOMAIN PDF_BRAND_INVOICE_CLOUD_EMAIL_LURE PDF_CORPORATE_PRESENTATION_CLOUD_REDIRECT_LURE PDF_CORRUPTED_FILE_UPDATE_LURE PDF_CRACKED_SOFTWARE_SHORTLINK_LURE PDF_GAME_HACK_SEO_LINK_FARM PDF_DISTRIBUTED_PIRACY_LINK_FARM PDF_DOCUSIGN_DOWNLOAD_LURE PDF_DOCUMENT_ACTION_HOST_MISMATCH_LURE PDF_DYNAMIC_DNS_DOCUMENT_LINK_FARM PDF_SWF_NATIVE_MEMORY_CORRUPTION_PAYLOAD PDF_EMBEDDED_PE_PAYLOAD CVE_2010_1240_EMBEDDED_EXPORT_LAUNCH