PDF heuristics

345 detection rules

← All detection heuristics

/Launch /P parameter is a javascript: URL critical PDF_LAUNCH_JS_PROTOCOL
PDF /Launch action passes a `javascript:` URL as the /P parameter.
/Launch action target critical PDF_LAUNCH_COMMAND
PDF /Launch action specifies an executable target (and optionally parameters).
/Launch action targets mshta.exe (LOLBIN) critical PDF_LAUNCH_MSHTA
PDF /Launch action whose /F parameter explicitly names mshta.
Adobe QR document-unlock lure critical PDF_ADOBE_QR_UNLOCK_LURE
An Adobe security notice instructs the user to scan a QR code to unlock a document.
Adobe Reader JavaScript exploit kit (URL-keyed loader) critical PDF_JS_URL_KEYED_READER_EXPLOIT_KIT
PDF OpenAction JS uses a this.URL-keyed cipher + hex-decode + eval — a known anti-analysis Adobe Reader exploit kit.
Adobe Reader U3D auto-activated 3D annotation — CVE-2009-2990 critical CVE_2009_2990_U3D_AUTOACTIVATE
PDF embeds a U3D stream behind a /3D annotation set to auto-activate on page view.
Annotation author eval stager critical PDF_ANNOT_AUTHOR_EVAL_STAGER
OpenAction JavaScript evaluates an annotation subject stage, which then evaluates the annotation author field.
Annotation subject hex-decoded eval stager critical PDF_ANNOT_SUBJECT_HEX_EVAL_STAGER
PDF JavaScript decodes dash-delimited hex from annotation subjects and evals the result.
Annotation subject percent-decoding eval stager critical PDF_ANNOT_SUBJECT_MARKER_EVAL_STAGER
OpenAction JavaScript reads an annotation /Subject payload, rewrites marker bytes into percent escapes, unescapes the result, and dispatches it through eval.
Base-N token-array Windows downloader critical PDF_JS_BASE_N_TOKEN_DOWNLOADER
Numeric string arrays reconstruct a WScript download, file-write, and execution stage.
Base64-encoded Windows executable payload in PDF critical PDF_BASE64_PE_PAYLOAD
PDF text contains a long base64 blob that decodes to a verified MZ/PE executable payload.
Brand invoice PDF lure links off-domain critical PDF_BRAND_INVOICE_LURE_OFFDOMAIN
PDF impersonates a branded invoice workflow but links outside the brand's own domains.
Brand invoice cloud email lure critical PDF_BRAND_INVOICE_CLOUD_EMAIL_LURE
Branded invoice PDF links to public cloud object storage with a recipient email parameter.
Corporate presentation cloud-redirect lure critical PDF_CORPORATE_PRESENTATION_CLOUD_REDIRECT_LURE
A corporate presentation or investment lure points to redirect-named object storage.
Corrupted-file update PDF lure critical PDF_CORRUPTED_FILE_UPDATE_LURE
PDF shows a corrupted-file/update lure and links to an external URL.
Cracked-software shortlink/download lure critical PDF_CRACKED_SOFTWARE_SHORTLINK_LURE
PDF visible text advertises cracked software, serials, or archive downloads and links to a shortlink/download gateway.
Distributed game-hack scam link farm critical PDF_GAME_HACK_SEO_LINK_FARM
PDF carries many game-hack/free-generator PDF links spread across distinct hosts.
Distributed piracy/download link farm critical PDF_DISTRIBUTED_PIRACY_LINK_FARM
Piracy/download lure text is paired with links across several unrelated hosts.
DocuSign download lure links off-domain critical PDF_DOCUSIGN_DOWNLOAD_LURE
PDF contains DocuSign-themed download/signing lure text and links to a non-DocuSign host.
Document-action lure links to risky external infrastructure critical PDF_DOCUMENT_ACTION_HOST_MISMATCH_LURE
A document review/open/sign/install CTA links to a risky delivery or redirect destination.
Dynamic-DNS document link farm critical PDF_DYNAMIC_DNS_DOCUMENT_LINK_FARM
A PDF sends many title-shaped document links through one dynamic-DNS host.
Embedded Flash native memory-corruption payload critical PDF_SWF_NATIVE_MEMORY_CORRUPTION_PAYLOAD
Embedded SWF combines native-memory discovery, protection changes, and process execution.
Embedded Windows executable payload in PDF stream critical PDF_EMBEDDED_PE_PAYLOAD
PDF stream bytes contain an embedded MZ/PE executable payload.
Embedded export-and-launch chain — CVE-2010-1240 likely critical CVE_2010_1240_EMBEDDED_EXPORT_LAUNCH
PDF combines /Launch, EmbeddedFiles/EF, and exportDataObject with nLaunch:0.
File starts as a GIF, contains a secondary PDF body, and the carved PDF has JBIG2 stream anomalies consistent with FORCEDENTRY-style CoreGraphics exploitation.
Fake 'free download' SEO-poisoning PDF critical PDF_SEO_FAKE_DOWNLOAD
ML-flagged PDF that also carries a download/call-to-action lure and an off-domain downloadN.php?file=document gateway link.
Fake Adobe Reader download/update link critical PDF_FAKE_ADOBE_READER_LINK
PDF links to an Adobe Reader-themed path on a non-Adobe host.
Flash ActionScript-3 exploit loader in PDF critical PDF_FLASH_AS3_EXPLOIT_LOADER
Embedded SWF's ActionScript-3 bytecode loads and executes an inner SWF from raw bytes (allowLoadBytesCodeExecution) and/or Vector heap-spray groomers.
Flash ByteArray/loadBytes exploit kit critical PDF_FLASH_BYTEARRAY_LOADBYTES_EXPLOIT_KIT
RichMedia PDF pairs obfuscated exploit JavaScript with a ByteArray/loadBytes SWF loader.
An oversized PDF Launch FileSpec triggers the Foxit Reader 3.0 stack overflow after JavaScript heap-sprays native shellcode.
HR or compensation QR lure critical PDF_QR_HR_COMPENSATION_LURE
An HR, salary, payroll, or signing lure hides its action in a QR code.
Hidden ZIP with executable payloads in PDF stream critical PDF_HIDDEN_ZIP_EXECUTABLE_PAYLOAD
PDF stream contains a hidden ZIP archive with executable entries.
Icon-hidden heap-spray exploit stage critical PDF_ICON_CHANNEL_MEMORY_CORRUPTION_EXPLOIT
The recovered icon-channel JavaScript contains a heap spray and percent-encoded shellcode.
Image button with opaque notification redirect critical PDF_IMAGE_OPAQUE_NOTIFICATION_REDIRECT
A localized image-based open/view button links to a long opaque path on a notification/update-themed host.
Image lure link embeds recipient email critical PDF_IMAGE_LURE_RECIPIENT_EMAIL_LINK
Image-heavy PDF carries a clickable URL with the recipient email address in a query parameter.
Image lure links to invalid destination hostname critical PDF_IMAGE_LURE_INVALID_DESTINATION_HOST
An image-based PDF lure links to a syntactically invalid or unregistered hostname.
Image-only multihost doorway critical PDF_IMAGE_MULTIHOST_DOORWAY
An image-only PDF routes actions through multiple unrelated low-context hosts.
Image/QR lure link is personalized to the recipient critical PDF_QR_RECIPIENT_PERSONALIZED_LINK
Sparse image/QR PDF links to generated infrastructure while embedding the recipient email address.
JBIG2-filtered JavaScript action stream critical PDF_JBIG2_JAVASCRIPT_ACTION_STREAM
A /JavaScript action references a stream whose terminal filter is JBIG2Decode.
PDF combines JBIG2Decode image streams with JavaScript heap-spray or decoder scaffolding.
JavaScript concealed behind anomalous image filter chain critical PDF_JS_IMAGE_FILTER_CHAIN_EVASION
A JavaScript stream abuses a mixed compression/image filter chain with extreme dimensions.
JavaScript heap-spray padding critical PDF_JS_HEAP_SPRAY_PADDING
A deflated /JS stream inflates into a large blob that is almost entirely whitespace wrapped around a small code core.
JavaScript reconstructed from a PDF icon channel critical PDF_ICON_CHANNEL_EVAL_STAGER
Acrobat JavaScript decodes biased pixel-channel bits and evaluates the recovered stage.
Known malicious redirector link critical PDF_MALICIOUS_REDIRECTOR_LINK
PDF links to redirector infrastructure used by a known malicious PDF campaign.
Launch VBS dropper command chain — CVE-2010-1240 likely critical CVE_2010_1240_LAUNCH_VBS_DROPPER
PDF /Launch invokes cmd.exe to build a VBS ADODB.Stream/XMLHTTP/FileSystemObject dropper.
Launch action critical PDF_LAUNCH
PDF contains a /Launch action to start an external application.
Launch/export embedded executable chain — CVE-2010-1240 likely critical CVE_2010_1240_EMBEDDED_PE_EXPORT
PDF combines /Launch, EmbeddedFiles/EF, exportDataObject, and embedded executable bytes.
Manual execution lure for Base64 PE payload critical PDF_BASE64_PE_MANUAL_EXECUTION_LURE
A PDF wrapper contains a verified Base64 PE and explicitly instructs the user to run it.
Document JavaScript matches the CVE-2016-3198 generator-constructor CSP bypass pattern.
Obfuscated HTML script loader appended to PDF critical PDF_TRAILING_HTML_OBFUSCATED_SCRIPT_LOADER
Trailing HTML reconstructs a remote script URL from transformed RGB values.
Obfuscated embedded-file export and launch critical PDF_JS_COMPUTED_EXPORT_LAUNCH_DROPPER
Array-indexed JavaScript properties resolve to exportDataObject with nLaunch enabled.
Obfuscated multi-stage PDF JavaScript heap-spray exploit critical PDF_JS_OBFUSCATED_MULTISTAGE_HEAPSPRAY
PDF JS behind nested filters / a custom rolling-XOR decoder de-obfuscates to a heap-spray / ROP chain.
Off-domain document CTA lure critical PDF_OFFDOMAIN_DOCUMENT_CTA_LURE
PDF uses document-review CTA wording but links to an unrelated hosted portal.
Official lure uses free-mail contact critical PDF_OFFICIAL_LURE_FREE_MAIL_CONTACT
An official or prize-themed document directs contact to consumer webmail.
OpenAction Launch PowerShell downloader critical PDF_OPENACTION_POWERSHELL_DOWNLOADER
PDF automatically launches an encoded PowerShell download-and-execute command.
PDF AcroForm Marker Unescape JavaScript Stager critical PDF_ACROFORM_MARKER_UNESCAPE_JS_STAGER
PDF structural or payload evidence: PDF AcroForm Marker Unescape JavaScript Stager.
PDF JavaScript Exploit Cluster critical PDF_JS_EXPLOIT_CLUSTER
PDF JavaScript contains a cluster of exploit-like primitives.
PDF JavaScript Shellcode Behavior critical PDF_JS_SHELLCODE_BEHAVIOR
PDF JavaScript behavior: PDF JavaScript Shellcode Behavior.
PDF Launch Plus Dropper JavaScript critical PDF_LAUNCH_PLUS_DROPPER_JS
PDF structural or payload evidence: PDF Launch Plus Dropper JavaScript.
PDF Malformed Exploit Stream Length critical PDF_MALFORMED_EXPLOIT_STREAM_LENGTH
PDF stream length metadata is malformed in an exploit-like way.
PDF VBS Hex PE Dropper critical PDF_VBS_HEX_PE_DROPPER
PDF structural or payload evidence: PDF VBS Hex PE Dropper.
PDF XFA Heap Spray critical PDF_XFA_HEAP_SPRAY
PDF XFA behavior: PDF XFA Heap Spray.
PDF credential prompt with URL exfiltration critical PDF_CREDENTIAL_PROMPT_URL_EXFILTRATION
Acrobat JavaScript prompts for credential-like input and places it in a network request.
PDF embedded-file fixed-stride eval stager critical PDF_EMBEDDED_FILE_STRIDE_EVAL_STAGER
PDF JavaScript reconstructs and evals a hidden stage from every Nth byte of an embedded file.
PDF exploit shellcode decodes to download-and-execute payload critical PDF_JS_FIXED_XOR_DOWNLOAD_EXEC_SHELLCODE
Recovered PDF shellcode statically XOR-decodes to a native URLMON downloader and executable launcher.
PHP-gateway SEO-spam PDF link farm critical PDF_SEO_PHP_GATEWAY_LINK_FARM
PDF carries >=4 links to .php gateways with a multi-word search-phrase document slug (pharma / binary-options / SEO spam).
Pidief-style multi-CVE JavaScript dispatcher critical PDF_PIDIEF_MULTI_CVE_DISPATCH
Single PDF JavaScript body branches on viewerVersion and invokes multiple Reader CVE sinks.
PowerShell download cradle in PDF critical PDF_PS_DOWNLOAD_CRADLE
PDF action body contains a PowerShell download-and-execute cradle.
PowerShell retrieve-and-execute Launch action critical PDF_LAUNCH_POWERSHELL_RETRIEVE_EXECUTE
A PDF Launch action retrieves remote content and pipes it to an IEX-equivalent sink.
Protected document on workspace tenant critical PDF_PROTECTED_DOCUMENT_WORKSPACE_LURE
A protected receipt, invoice, or document lure opens an unrelated collaborative-workspace tenant.
QR business lure with obfuscated text critical PDF_QR_BUSINESS_LURE_OBFUSCATED_TEXT
PDF contains a QR-like image and business-process scan instructions hidden with invisible text characters.
Recipient-personalized hosting lure critical PDF_RECIPIENT_EMAIL_HOSTING_LURE
A sparse recipient-address PDF links to arbitrary hosted infrastructure.
Repeated invisible payload link critical PDF_REPEATED_PAYLOAD_LINK_LURE
PDF uses invisible/repeated links to deliver a direct payload file.
Repeated personalized redirect overlay critical PDF_REPEATED_PERSONALIZED_REDIRECT_OVERLAY
A repeated obfuscated link overlay embeds a Base64 recipient address.
RichMedia AES demo paired with PDF-side shellcode stage critical PDF_RICHMEDIA_AESPHP_SHELLCODE_STAGE
PDF embeds an AESFlashToPHPDemo RichMedia SWF while OpenAction JavaScript builds shellcode.
RichMedia Flash exploit — CVE-2011-0611 likely critical CVE_2011_0611_FLASH_RICHMEDIA
PDF combines RichMedia Flash activation, an AS3 ByteArray/loadBytes SWF, and shellcode staging.
SEO/link-farm PDF carrier critical PDF_SEO_LINK_FARM
Small PDF contains many clickable external PDF links clustered on one host.
Search-themed obfuscated getURL redirector campaign critical PDF_JS_SEARCH_REDIRECTOR_GETURL_CAMPAIGN
PDF document JavaScript opens a known search-themed redirector campaign URL.
SearchGlobalSite obfuscated getURL redirector critical PDF_JS_SEARCHGLOBALSITE_GETURL_REDIRECTOR
PDF document JavaScript opens the known SearchGlobalSite redirector campaign URL.
Shell.Application.ShellExecute COM pivot critical PDF_SHELL_APPLICATION_PIVOT
PDF (or its embedded JavaScript stub) instantiates Shell.Application and calls ShellExecute.
Single-link piracy redirect critical PDF_SINGLE_LINK_PIRACY_REDIRECT
A free/full-movie lure links to an unrelated non-media host.
Substitution-obfuscated heap spray with oversized Launch trigger critical PDF_JS_SUBSTITUTION_HEAPSPRAY_OVERSIZED_LAUNCH_EXPLOIT
A constant-alphabet JavaScript decoder reconstructs native shellcode beside an oversized PDF Launch FileSpec.
Tatsumaki/Arashi Flash exploit family — CVE-2011-0611 related critical PDF_TATSUMAKI_CVE_2011_0611_RELATED
Tatsumaki.swf is present and parsed ABC surfaces expose its ByteArray/loadBytes groomer.
Time-locked SHA-1 XOR JavaScript loader critical PDF_JS_TIME_LOCKED_SHA1_LOADER
PDF JS embeds a SHA-1 routine keyed on the victim's wall-clock minute to XOR-decrypt and eval a payload.
PDF combines U3D/3D annotation content with JavaScript heap-spray shellcode.
U3D/RichMedia activation — CVE-2011-2462 likely critical CVE_2011_2462_RICHMEDIA_U3D
PDF combines U3D stream markers with RichMedia and JavaScript/XFA activation surfaces.
VBScript decimal byte array PE payload in PDF critical PDF_VBS_DECIMAL_ARRAY_PE_PAYLOAD
PDF comment text contains a decimal byte array that decodes to a verified MZ/PE executable payload.
Whitespace-interleaved PDF JavaScript exploit critical PDF_JS_INTERCHARACTER_WHITESPACE_EXPLOIT
PDF JavaScript hides exploit tokens by inserting whitespace between source characters.
WwwSearchSites obfuscated getURL redirector critical PDF_JS_WWWSEARCHSITES_GETURL_REDIRECTOR
PDF document JavaScript opens the known WwwSearchSites redirector campaign URL.
XFA image field contains XOR-obfuscated shellcode critical PDF_XFA_HEX_IMAGE_SHELLCODE
A non-image XFA image payload decodes to command and network shellcode strings.
exportDataObject + nLaunch — embedded-file dropper critical PDF_JS_EXPORT_LAUNCH_DROPPER
PDF JavaScript calls exportDataObject() with nLaunch set, extracting and launching the document's embedded file on open.
/OpenAction targets an object not reachable from /Root high PDF_OPENACTION_HIDDEN_OBJECT
PDF defines an /OpenAction whose target object cannot be reached by walking indirect references from the document /Root catalog tree.
PDF JavaScript gates the payload on the Reader 7.0.x / 8.0–8.1.1 window.
PDF JavaScript gates the payload on the exact Adobe APSB09-15 patch boundary.
Adobe viewer lure links off-domain high PDF_ADOBE_VIEWER_LURE
PDF uses Adobe secure-document/viewer lure wording and links to a non-Adobe host.
Adult or viral redirector lure high PDF_ADULT_VIRAL_REDIRECTOR_LURE
An adult or viral-video lure uses a URL shortener or smart link.
Annotation subject callee-key hex JavaScript stager high PDF_ANNOT_SUBJECT_CALLEE_HEX_STAGER
PDF JavaScript decodes an annotation /Subject payload with marker replacement and a callee.toString-derived key.
Annotation subject split/self-key JavaScript stager high PDF_ANNOT_SUBJECT_SPLIT_EVAL_STAGER
PDF JavaScript rebuilds hidden exploit code from annotation /Subject fields.
PDF JavaScript shows the annotation use-after-free exploitation shape (addAnnot spray + destroy free + getAnnot re-entry + getter/leak).
Base-N pair JavaScript stager high PDF_BASE_N_PAIR_JS_STAGER
PDF JavaScript rebuilds an exploit stage from base-N character pairs.
Brand impersonation link high PDF_BRAND_IMPERSONATION_LINK
PDF links to a Microsoft-login impersonation domain.
PDF uses CCITTFaxDecode alongside active-content indicators.
CFF CharString excessive subroutine calls high PDF_CFF_CHARSTRING_SUBR_STORM
CFF CharStrings contain an unusually high number of subroutine calls.
CFF CharString operand stack underflow high PDF_CFF_CHARSTRING_STACK_UNDERFLOW
Type 2 CharString bytecode invokes an operator without enough operands.
CFF INDEX has an invalid offSize high PDF_CFF_OFFSIZE_INVALID
CFF INDEX or header declares an offSize outside the spec-allowed 1..4 range.
CFF INDEX's offset array contains entries that decrease, so successive elements appear in unexpected order.
CFF INDEX offsets extend past stream end high PDF_CFF_INDEX_OFFSET_OVERFLOW
CFF INDEX offset array or data section is declared to extend beyond the available font bytes.
CFF Private DICT offset points outside font high PDF_CFF_PRIVATE_DICT_OUT_OF_RANGE
CFF Top DICT points the Private DICT outside the embedded font stream.
CFF2 BLEND operand-stack growth high PDF_CFF2_BLEND_STACK_OVERFLOW
CFF2 blend bytecode grows the operand stack beyond expected bounds.
CFF2 BLEND operand-stack underflow high PDF_CFF2_BLEND_STACK_UNDERFLOW
CFF2 blend/stack bytecode consumes operands that are not available.
CFF2 CharString repeated BLEND operators high PDF_CFF2_BLEND_STORM
Embedded CFF2 font bytecode contains repeated BLEND operators.
Character-table JavaScript eval stager high PDF_JS_CHAR_TABLE_EVAL_STAGER
PDF JavaScript rebuilds an exploit stage through character-table indexes and eval.
PDF clickable URI hides its real host as an obfuscated IP literal or behind a brand-looking user@ userinfo.
Clickable URL hides a base64-encoded recipient email high PDF_URL_ENCODED_RECIPIENT_EMAIL
A clickable link carries the recipient email base64/URL-encoded in a query parameter or #fragment on generated/wrapper infrastructure.
Compressed object stream hides active PDF content high PDF_OBJSTM_ACTIVE_CONTENT
A PDF /ObjStm stream contains active-content keys such as /JavaScript or /OpenAction.
Cracked-software download doorway (base64-obfuscated) high PDF_CRACKED_SOFTWARE_DOWNLOAD_DOORWAY
PDF's embedded link hides a pirated-software title as a base64 blob in the URL (and/or carries the download| doorway marker).
Cracked-software download-gateway link farm high PDF_CRACKED_SOFTWARE_REDIRECTOR_LINK_FARM
PDF cracked-software lure links are paired with encoded download-gateway redirectors.
Direct payload download link high PDF_DIRECT_PAYLOAD_LINK
PDF clickable URI points directly to an executable, script, shortcut, disk image, or archive.
Document-open overlay redirect lure high PDF_DOCUMENT_OPEN_OVERLAY_REDIRECT_LURE
An image-centric open/view overlay routes to multiple unrelated destinations.
Document-phishing landing link high PDF_DOCUMENT_PHISHING_LINK
PDF links to a non-reputable host using a document-phishing landing path.
Document-workflow phish host on serverless free hosting high PDF_FREE_HOSTING_DOC_PHISH_LINK
PDF links to a serverless free-hosting subdomain named like a document-signing workflow.
Embedded JS stream high PDF_JS
PDF references a /JS stream with inline JavaScript code.
Embedded script payload in PDF stream high PDF_EMBEDDED_SCRIPT_PAYLOAD
PDF stream bytes contain Windows or HTML script execution markers.
Encrypted PDF carrying executable triggers high PDF_ENCRYPTED_WITH_JS
PDF declares /Encrypt and also contains /JavaScript, /Launch, or an OpenAction resolved to an executable action dictionary — payload is hidden from static analysis. Navigation-only OpenAction destinations are excluded.
Escaped URI image lure high PDF_ESCAPED_URI_IMAGE_LURE
PDF image lure hides its clickable HTTP(S) URI with PDF octal string escapes.
Free-generator / game-hack redirector lure high PDF_GAME_HACK_REDIRECT_LURE
PDF's clickable action targets a /app/<id>/<slug>-game-hack redirector.
Free-hosted document/account lure high PDF_FREE_HOSTED_DOC_ACCOUNT_LURE
PDF links to a document/account-themed hostname on free static hosting.
Gift-card or fixed-reward scam high PDF_GIFT_CARD_REWARD_SCAM
A free gift-code, reward, points, or generator lure links to an unrelated host.
Government summons on arbitrary hosting high PDF_GOVERNMENT_SUMMONS_HOSTING_LURE
A government or judicial notice links to user-controlled hosting.
Hidden HTML iframe in PDF high PDF_HIDDEN_HTML_IFRAME
PDF bytes contain a zero-size external HTML iframe.
ICC tag offset+size lies outside the profile high PDF_ICC_TAG_OUT_OF_RANGE
ICC tag entry points at byte ranges outside the embedded profile (or inside the tag-table region).
PDF image lure with a clickable multi-word utm_term / FeedBurner-proxied SEO redirector link — the 'free ebook/manual download' phishing family.
Image lure with local builder path and remote links high PDF_IMAGE_LURE_LOCAL_FILE_AND_REMOTE_URI
Image-only PDF contains both remote HTTP(S) links and a local file:/// builder path.
Image-centric PDF redirects to an untrusted video path high PDF_IMAGE_VIDEO_REDIRECT_LURE
An image-centric PDF links to a watch/video/play path outside recognized video services.
Image-heavy PDF with invisible suspicious link high PDF_SUSPICIOUS_LINK_LURE
PDF uses invisible link annotations over image-heavy content to send users to a suspicious URI.
Image-only PDF links to deceptive (typosquat) host high PDF_IMAGE_LURE_DECEPTIVE_HOST_LINK
Image-only PDF's clickable action targets a host impersonating a service/brand word with a leetspeak digit substitution (serv1ce, upd4te, …).
Image-only PDF links to scheme-label deceptive host high PDF_IMAGE_LURE_SCHEME_HOST_LINK
Image-only PDF's clickable action targets a host beginning with a literal 'http.'/'https.' label.
Image/button lure to file-hosting download high PDF_FILE_HOSTING_DOWNLOAD_LURE
PDF screenshot/button lure links to a public file-hosting download endpoint.
Invisible CAPTCHA web lure high PDF_CAPTCHA_LINK_LURE
PDF uses invisible links to a CAPTCHA/capcha-themed web path.
Invisible OAuth redirect link high PDF_OAUTH_REDIRECT_LINK_LURE
PDF uses invisible link annotations that point to an OAuth authorization URL with a redirector chain.
JBIG2 segment refers forward to a later segment high PDF_JBIG2_FORWARD_REFERENCE
JBIG2 segment refers to one or more later segments by number.
JBIG2 segment refers to an undefined segment high PDF_JBIG2_REFERRED_OUT_OF_RANGE
JBIG2 segment refers to a segment number that has not been declared earlier in the stream.
JBIG2 segment refers to itself high PDF_JBIG2_SELF_REFERENCE
JBIG2 segment lists its own segment number in its referred-to list.
JBIG2 unknown-length form on non-generic-region segment high PDF_JBIG2_DATA_LENGTH_OVERFLOW
JBIG2 segment uses the 0xFFFFFFFF 'unknown length' form on a segment type other than generic region.
JPEG2000 COD declares too many decomposition levels high PDF_JPX_COD_DECOMP_LEVELS_HIGH
COD marker declares more than the spec-maximum 32 wavelet decomposition levels.
PCLR (palette) sub-box declares more than the spec-maximum 1024 entries.
JPEG2000 SIZ marker declares image dimensions, image offsets, or component counts outside plausible ranges.
JP2 box header declares a total length less than 8 bytes (the minimum for the size+type header alone).
JPEG2000 box extends past stream end high PDF_JPX_BOX_TRUNCATED
JP2 box declares a length that runs past the available stream bytes.
jp2c codestream box does not begin with the required Start Of Codestream (FF 4F) marker.
JPEG2000 jp2h missing required ihdr sub-box high PDF_JPX_JP2H_MISSING_IHDR
jp2h header box does not begin with the mandatory ihdr (image header) sub-box.
JPEG2000 top-level boxes overlap high PDF_JPX_BOX_OVERLAP
Two top-level JP2 boxes claim overlapping byte ranges.
PDF uses JPXDecode/JPEG2000 alongside active/exploit-delivery indicators.
JavaScript action high PDF_JAVASCRIPT
PDF contains a /JavaScript action.
JavaScript heap-spray launcher high PDF_JS_HEAPSPRAY
PDF JS schedules a callback with a multi-kilobyte string (heap-spray primitive).
Large character-table JavaScript eval stager high PDF_JS_LARGE_CHAR_TABLE_EVAL_STAGER
PDF JavaScript uses a large numeric index table and indirect eval to rebuild a hidden stage.
Malformed PDF with no object graph high PDF_MALFORMED_NO_OBJECT_GRAPH
File has a PDF header but no indirect objects, xref table/stream, or startxref pointer.
Meta policy appeal phishing lure high PDF_META_POLICY_APPEAL_PHISH
A Facebook or Meta violation/deactivation warning sends its appeal to a non-Meta domain.
Obfuscated JavaScript getURL redirector high PDF_JS_OBFUSCATED_GETURL_REDIRECTOR
PDF document JavaScript opens an obfuscated redirector URL with getURL().
Obfuscated Pidief-style JavaScript loader (stage not decoded) high PDF_PIDIEF_OBFUSCATED_VERSION_GATED_LOADER
PDF JavaScript carries a large opaque encoded stage built to be eval'd, but the encoding resisted full static decoding so no exact CVE could be attributed.
Obfuscated multi-stage PDF JavaScript dropper high PDF_JS_OBFUSCATED_DROPPER
Composite signal of pre-2011 Adobe Reader exploit-kit dropper shape.
Object defined twice with divergent /Filter chains high PDF_DUPLICATE_OBJ_DIVERGENT
Same indirect object (N G) is defined more than once in the file, and the definitions declare different /Filter chains.
OpenAction trigger high PDF_OPENACTION
PDF has an /OpenAction that performs an action when the file is opened.
OpenType EBSC max-range record with bitmap tables high PDF_OPENTYPE_EBSC_WITH_SBIT
Malformed EBSC max-range record appears alongside EBLC/EBDT bitmap tables.
OpenType EBSC table declares max offset and length high PDF_OPENTYPE_EBSC_MAX_RANGE
sfnt EBSC table record declares offset=0xffffffff and length=0xffffffff.
OpenType VariationStore itemVariationDataCount is huge high PDF_OPENTYPE_VARSTORE_COUNT_HUGE
Embedded OpenType variable font declares an implausibly large itemVariationDataCount.
OpenType VariationStore offset out of range high PDF_OPENTYPE_VARSTORE_OFFSET_OUT_OF_RANGE
VariationStore or itemVariationData offsets point outside the containing table.
OpenType cmap subtable offset out of range high PDF_OPENTYPE_CMAP_OFFSET_OUT_OF_RANGE
A cmap encoding record points outside the cmap table.
EBLC/EBDT compound bitmap glyph metadata positions a component beyond the computed bitmap buffer.
OpenType glyph offset outside glyf table high PDF_OPENTYPE_GLYF_OFFSET_OUT_OF_RANGE
A loca entry points beyond the glyf table.
OpenType head table is truncated high PDF_OPENTYPE_HEAD_TRUNCATED
The head table is too short to carry indexToLocFormat.
OpenType invalid loca format high PDF_OPENTYPE_LOCA_FORMAT_INVALID
head.indexToLocFormat is outside the valid 0/1 range.
OpenType itemVariationData malformed high PDF_OPENTYPE_VARSTORE_ITEMDATA_MALFORMED
itemVariationData subtable has impossible item or region counts.
OpenType loca offsets decrease high PDF_OPENTYPE_LOCA_NOT_MONOTONIC
loca glyph offsets are not monotonically increasing.
OpenType loca table too short high PDF_OPENTYPE_LOCA_TRUNCATED
loca cannot hold numGlyphs+1 offsets.
OpenType maxp table is truncated high PDF_OPENTYPE_MAXP_TRUNCATED
The maxp table is too short to declare numGlyphs.
OpenType table record points outside the font high PDF_OPENTYPE_TABLE_OUT_OF_RANGE
sfnt table-record entry's offset+length lies beyond the embedded font bytes.
PDF Affiliate Scam Review Lure high PDF_AFFILIATE_SCAM_REVIEW_LURE
PDF structural or payload evidence: PDF Affiliate Scam Review Lure.
PDF Arithmetic Percent JavaScript Stager high PDF_ARITHMETIC_PERCENT_JS_STAGER
PDF structural or payload evidence: PDF Arithmetic Percent JavaScript Stager.
PDF Binary Xor JavaScript Stager high PDF_BINARY_XOR_JS_STAGER
PDF structural or payload evidence: PDF Binary Xor JavaScript Stager.
PDF Disposable Redirector Campaign high PDF_DISPOSABLE_REDIRECTOR_CAMPAIGN
PDF structural or payload evidence: PDF Disposable Redirector Campaign.
PDF Disposable Redirector Subdomain Fanout high PDF_DISPOSABLE_REDIRECTOR_SUBDOMAIN_FANOUT
PDF fans out to many disposable random-subdomain redirector links.
PDF Embedded Child Static Triage high PDF_EMBEDDED_CHILD_STATIC_TRIAGE
PDF structural or payload evidence: PDF Embedded Child Static Triage.
PDF Exfiltration Sink URL high PDF_EXFIL_SINK_URL
PDF structural or payload evidence: PDF Exfiltration Sink URL.
PDF Fake Acrobat Update Lure high PDF_FAKE_ACROBAT_UPDATE_LURE
PDF structural or payload evidence: PDF Fake Acrobat Update Lure.
PDF Image Lure Brand Host Link high PDF_IMAGE_LURE_BRAND_HOST_LINK
PDF image-lure link pattern: PDF Image Lure Brand Host Link.
PDF Image Lure Brand Path Link high PDF_IMAGE_LURE_BRAND_PATH_LINK
PDF image-lure link pattern: PDF Image Lure Brand Path Link.
PDF Image Lure Shortener Link high PDF_IMAGE_LURE_SHORTENER_LINK
PDF image-lure link pattern: PDF Image Lure Shortener Link.
PDF Info Producer Char Range JavaScript Stager high PDF_INFO_PRODUCER_CHAR_RANGE_JS_STAGER
PDF structural or payload evidence: PDF Info Producer Char Range JavaScript Stager.
PDF JavaScript ActiveX downloader high PDF_JS_ACTIVEX_DOWNLOADER
Decoded PDF JavaScript downloads, writes, and executes a Windows payload through ActiveX.
PDF JavaScript Exfiltration Sink URL high PDF_JS_EXFIL_SINK_URL
PDF JavaScript behavior: PDF JavaScript Exfiltration Sink URL.
PDF JavaScript Network Beacon high PDF_JS_NETWORK_BEACON
PDF JavaScript behavior: PDF JavaScript Network Beacon.
PDF JavaScript Obfuscated Unicode Heap Spray high PDF_JS_OBFUSCATED_UNICODE_HEAP_SPRAY
PDF JavaScript behavior: PDF JavaScript Obfuscated Unicode Heap Spray.
PDF JavaScript Page Word Heapspray Stager high PDF_JS_PAGE_WORD_HEAPSPRAY_STAGER
PDF JavaScript behavior: PDF JavaScript Page Word Heapspray Stager.
PDF JavaScript Replace Obfuscated Charcode Builder high PDF_JS_REPLACE_OBFUSCATED_CHARCODE_BUILDER
PDF JavaScript behavior: PDF JavaScript Replace Obfuscated Charcode Builder.
PDF JavaScript Submitform URL high PDF_JS_SUBMITFORM_URL
PDF JavaScript behavior: PDF JavaScript Submitform URL.
PDF JavaScript WScript downloader high PDF_JS_WSCRIPT_DOWNLOADER
Decoded PDF JavaScript reconstructs a Windows Script Host downloader.
PDF JavaScript contains Windows Script Host/JScript payload behavior.
PDF JavaScript object lifetime reuse pattern high PDF_JS_LIFETIME_REUSE_PATTERN
PDF JavaScript acquires, releases, delays, and then reuses a viewer-managed object.
PDF JavaScript reaches eval (or unescape/Function) through a computed member access assembled from single-character pieces.
A URL was recovered from a %uXXXX shellcode run inside decoded PDF JavaScript.
PDF Obfuscated Name Object high PDF_OBFUSCATED_NAME_OBJECT
PDF structural or payload evidence: PDF Obfuscated Name Object.
PDF Obfuscated Uri Scheme high PDF_OBFUSCATED_URI_SCHEME
PDF structural or payload evidence: PDF Obfuscated Uri Scheme.
PDF Openaction JavaScript Submitform high PDF_OPENACTION_JS_SUBMITFORM
PDF structural or payload evidence: PDF Openaction JavaScript Submitform.
PDF Piracy Streaming Lure high PDF_PIRACY_STREAMING_LURE
PDF structural or payload evidence: PDF Piracy Streaming Lure.
PDF Quoted Hex Fragment JavaScript Stager high PDF_QUOTED_HEX_FRAGMENT_JS_STAGER
PDF structural or payload evidence: PDF Quoted Hex Fragment JavaScript Stager.
PDF Random URL Link high PDF_RANDOM_URL_LINK
PDF structural or payload evidence: PDF Random URL Link.
PDF Shuffled Var Join JavaScript Stager high PDF_SHUFFLED_VAR_JOIN_JS_STAGER
PDF structural or payload evidence: PDF Shuffled Var Join JavaScript Stager.
PDF URI command path high PDF_DANGEROUS_URI_COMMAND
PDF /URI action references a command interpreter or script host path.
PDF URL Mailmerge Placeholder high PDF_URL_MAILMERGE_PLACEHOLDER
PDF URL anomaly: PDF URL Mailmerge Placeholder.
PDF URL Recipient Email Param high PDF_URL_RECIPIENT_EMAIL_PARAM
PDF URL anomaly: PDF URL Recipient Email Param.
PDF XFA Title Base26 Eval Stager high PDF_XFA_TITLE_BASE26_EVAL_STAGER
PDF XFA behavior: PDF XFA Title Base26 Eval Stager.
PDF link URL hidden with octal escapes high PDF_OCTAL_ESCAPED_URI
A /URI link action encodes most of its URL as PDF octal escapes, hiding the destination from URL extraction.
PDF links to document on public blob storage high PDF_PUBLIC_BLOB_DOCUMENT_LINK
PDF contains a clickable action to a document hosted on public blob/object storage.
PDF metadata JavaScript eval stager high PDF_METADATA_EVAL_STAGER
PDF JavaScript decodes document metadata fields and evals the recovered stage.
PDF metadata arithmetic JavaScript stager high PDF_INFO_ARITHMETIC_JS_STAGER
PDF Info metadata rebuilds an exploit stage through arithmetic char-code tokens.
PDF modified after it was signed high PDF_SIGNATURE_POST_SIGN_MODIFICATION
Bytes were appended after the signed/certified byte range.
PDF parsers disagree on structural counts high PDF_PARSER_DIVERGENCE
Two independent PDF parsers produced significantly different counts of streams or pages on the same bytes.
PRC stream missing 'PRC' magic high PDF_PRC_HEADER_INVALID
PRC stream does not begin with the ASCII bytes 'PRC' at offset 0.
Page-word XOR JavaScript eval stager high PDF_PAGE_WORD_XOR_EVAL_STAGER
PDF JavaScript rebuilds and evals a hidden stage from rendered page words.
Pending document on user-controlled hosting high PDF_PENDING_DOCUMENT_HOSTING_LURE
A pending or confidential document prompt links to a generic hosting tenant.
Prototype-pollution JavaScript pattern high PDF_JS_PROTOTYPE_POLLUTION
PDF JavaScript mutates prototypes and references privileged PDF APIs.
Public-sector hostname impersonation high PDF_PUBLIC_SECTOR_HOST_IMPERSONATION_LINK
PDF link embeds a gov.xx-style host prefix inside an unrelated domain.
Public-sector update lure link high PDF_PUBLIC_SECTOR_UPDATE_LURE_LINK
PDF links to a non-reputable government/update themed hostname.
PDF combines a QR-like image with scan/verification/business-process lure text.
QR-code image-only phishing carrier high PDF_QR_IMAGE_ONLY_LURE
PDF contains a QR-like image but no extracted PDF URI and little or no machine-readable text.
Quotation/specification lure links to public file host high PDF_QUOTATION_FILE_HOST_LURE
PDF contains quotation/RFQ/specification lure text and links to a document payload on public blob/file hosting.
RichMedia (Flash) high PDF_RICHMEDIA
PDF contains /RichMedia (Adobe Flash content).
Search-engine open redirect to obfuscated target high PDF_SEARCH_REDIRECT_OBFUSCATED_TARGET
PDF link launders its destination through a search-engine redirect whose unwrapped target carries phishing obfuscation.
Secure document lure on unrelated hosting high PDF_SECURE_DOCUMENT_OFFDOMAIN_LURE
A secure file-sharing lure links to unrelated hosted infrastructure.
Tax-refund bank-confirmation phishing high PDF_TAX_REFUND_BANK_CONFIRMATION_PHISH
A tax-refund notice requests personal or bank confirmation through an unrelated host.
PDF contains a validated malformed TrueType bitmap-font primitive plus active content.
Truncated PDF prevents complete static analysis high PDF_SCAN_INCOMPLETE_TRUNCATED
A linearized PDF declares a substantially larger file than was received.
Trusted document-service host mismatch high PDF_BRANDED_DOCUMENT_HOST_MISMATCH
A branded SharePoint, Google, Adobe, or government document lure links outside that service.
Type 1 CharString callOtherSubr stack-pivot sequence high PDF_TYPE1_CALLOTHERSUBR_STACK_PIVOT
Decrypted Type 1 CharString contains repeated get/callOtherSubr bytecode sequences.
Type 1 CharString operand stack grows beyond spec high PDF_TYPE1_CHARSTRING_STACK_OVERFLOW
Decrypted Type 1 CharString bytecode pushes more operands than expected.
Type 1 CharString operand stack underflow high PDF_TYPE1_CHARSTRING_STACK_UNDERFLOW
Decrypted Type 1 CharString bytecode consumes operands that are unavailable.
U3D block declares an implausibly large size high PDF_U3D_HUGE_BLOCK_SIZE
U3D block declares a data or metadata section size beyond any plausible legitimate value.
U3D block extends past stream end high PDF_U3D_BLOCK_TRUNCATED
U3D block declares a total size that runs past the available stream bytes.
U3D stream missing or wrong File Header block high PDF_U3D_HEADER_MISSING
An embedded U3D (3D-model) stream does not start with the required File Header block — a malformed/parser-divergence shape on a rarely-inspected attack surface.
PDF embeds an XFA dataset with a <script> or <xfa:script> block.
XFA numeric JavaScript stager high PDF_XFA_NUMERIC_JS_STAGER
PDF XFA script rebuilds hidden JavaScript from numeric field data or a character table.
XFA numeric character-table eval stager high PDF_XFA_NUMERIC_EVAL_STAGER
XFA initialize script maps numeric rawValue data through a character table and evals it.
app.launchURL with file/cmd/UNC target high PDF_FOXIT_LAUNCHURL
PDF JavaScript launches a URL with a file://, cmd:, or UNC scheme.
eval() call high PDF_EVAL
JavaScript eval() function found in PDF.
getAnnots heap-spray JavaScript stager high PDF_JS_GETANNOTS_HEAPSPRAY_STAGER
PDF JavaScript pairs getAnnots with heap-spray shellcode and an embedded payload.
unescape() call high PDF_UNESCAPE
JavaScript unescape() function found in PDF.
xref table points away from the real object high PDF_XREF_OFFSET_MISMATCH
PDF cross-reference table claims object N is at byte offset O, but the bytes at O do not begin with the expected 'N G obj' header.
PDF uses ASCII85Decode stream filter alongside active scripting content.
PDF uses ASCIIHexDecode stream filter alongside active scripting content.
Ad redirect link medium PDF_AD_REDIRECT_LINK
Small PDF routes a clickable link through an ad/tracking redirector.
PDF defines /AA (Additional Actions) triggers.
CFF CharString is unusually large medium PDF_CFF_CHARSTRING_HUGE
A single CFF Type 2 glyph program is far larger than expected.
CFF INDEX declares an implausibly large entry count medium PDF_CFF_INDEX_COUNT_HUGE
CFF INDEX (Name / Top DICT / String / Subrs / CharStrings) declares thousands of entries.
CFF INDEX first offset != 1 medium PDF_CFF_INDEX_FIRST_OFFSET_WRONG
CFF INDEX's first offset entry is not 1 (the spec-mandated value).
CFF font header is truncated or malformed medium PDF_CFF_HEADER_TRUNCATED
CFF font header is structurally invalid: header size out of range, or header runs past the stream length.
Cracked-software link-farm lure medium PDF_CRACKED_SOFTWARE_LURE
PDF links advertise cracked/pirated software (crack, keygen, serial key, warez).
Credential / secure-document lure with single non-reputable link medium PDF_CREDENTIAL_LURE_NONREPUTABLE_LINK
Thin PDF whose rendered text is a credential / secure-document / identity-verification lure and whose only clickable action links to a non-reputable host.
Escaped URL shortener medium PDF_ESCAPED_SHORTENER_URI
PDF hides a clickable URL-shortener destination with PDF string escapes.
Fake manual-download gateway medium PDF_FAKE_MANUAL_DOWNLOAD_GATEWAY
A technical-manual download lure links to a query-driven PHP document gateway.
Free game-currency generator scam lure medium PDF_GAME_CURRENCY_SCAM_LURE
PDF advertises a free Robux/V-Bucks generator and links to a scam doorway or Looker Studio redirector.
High stream count medium PDF_MANY_STREAMS
PDF contains 500+ stream objects.
ICC profile contains a duplicate tag signature medium PDF_ICC_DUPLICATE_TAG_SIG
Same ICC tag signature appears more than once in the tag table.
ICC profile declares more than ~256 tag entries; real-world profiles have at most a few dozen.
ICC profile header field 'profile size' does not match the actual length of the embedded profile bytes (or the tag table extends past the bytes available).
ICC tag has size=0 with non-zero offset medium PDF_ICC_TAG_ZERO_SIZE_NONZERO_OFFSET
ICC tag declares zero data length but a non-zero offset.
Image-only PDF redirects through an external link medium PDF_IMAGE_ONLY_EXTERNAL_URI_LURE
A raster-only PDF overlays an actionable link to a non-official external host.
Image-only lure with single non-reputable link medium PDF_IMAGE_LURE_NONREPUTABLE_LINK
Image-heavy PDF whose sole clickable action links to a non-reputable host carrying a random throwaway subdomain.
JBIG2 segment-header walk aborted medium PDF_JBIG2_HEADER_TRUNCATED
A JBIG2 image segment header could not be parsed cleanly (e.g. a length field points past the end of the data) — a renderer-divergence shape.
JBIG2 stream declares thousands of segments where real-world scanned-document JBIG2 typically contains tens to a few hundred.
JBIG2Decode filter medium PDF_JBIG2
PDF uses JBIG2Decode image compression.
Loan-approval shortener lure medium PDF_LOAN_APPROVAL_SHORTENER_LURE
A loan or instant-approval solicitation conceals its destination behind a URL shortener.
Minimal view-PDF form doorway medium PDF_MINIMAL_VIEW_FORM_DOORWAY
A nearly empty view/open-PDF carrier links to a user-created external form.
OpenType / sfnt directory declares too many tables medium PDF_OPENTYPE_NUMTABLES_HUGE
sfnt offset table declares more than ~64 tables, well beyond any realistic font.
OpenType cmap declares too many subtables medium PDF_OPENTYPE_CMAP_SUBTABLES_HUGE
cmap declares an implausibly large number of subtables.
OpenType cmap table is truncated medium PDF_OPENTYPE_CMAP_TRUNCATED
cmap header or encoding records extend past the table.
OpenType directory contains a duplicate table tag medium PDF_OPENTYPE_DUPLICATE_TABLE
sfnt directory contains the same 4-byte table tag more than once.
OpenType maxp declares implausibly many glyphs medium PDF_OPENTYPE_MAXP_GLYPHS_HUGE
maxp.numGlyphs is far beyond typical embedded PDF fonts.
OpenType name string offset out of range medium PDF_OPENTYPE_NAME_STRING_OUT_OF_RANGE
A name record points outside name table string storage.
OpenType name table declares too many records medium PDF_OPENTYPE_NAME_RECORDS_HUGE
The name table record count is implausibly large.
OpenType name table is truncated medium PDF_OPENTYPE_NAME_TRUNCATED
name records or string storage point outside the name table.
PDF Action Parser Evasion medium PDF_ACTION_PARSER_EVASION
PDF structural or payload evidence: PDF Action Parser Evasion.
PDF Adobe Reader Multi CVE JavaScript Kit medium PDF_ADOBE_READER_MULTI_CVE_JS_KIT
PDF JavaScript matches a multi-CVE Adobe Reader exploit-kit pattern.
PDF Aitm Tokenized Phish Link medium PDF_AITM_TOKENIZED_PHISH_LINK
PDF structural or payload evidence: PDF Aitm Tokenized Phish Link.
PDF Auto Open Redirect medium PDF_AUTO_OPEN_REDIRECT
PDF structural or payload evidence: PDF Auto Open Redirect.
PDF Compromised CMS Upload Link Farm medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARM
PDF link farm points into compromised CMS upload paths.
PDF Embedded FileSpec Content Mismatch medium PDF_EMBEDDED_FILESPEC_CONTENT_MISMATCH
PDF structural or payload evidence: PDF Embedded FileSpec Content Mismatch.
PDF Flate Image Nop Sled medium PDF_FLATE_IMAGE_NOP_SLED
PDF structural or payload evidence: PDF Flate Image Nop Sled.
PDF Form Capability Uncorroborated medium PDF_FORM_CAPABILITY_UNCORROBORATED
PDF structural or payload evidence: PDF Form Capability Uncorroborated.
PDF Game Hack Link Farm medium PDF_GAME_HACK_LINK_FARM
PDF structural or payload evidence: PDF Game Hack Link Farm.
PDF Generic Stage Recovery medium PDF_GENERIC_STAGE_RECOVERY
PDF structural or payload evidence: PDF Generic Stage Recovery.
PDF JavaScript Extreme String Rewrite Obfuscation medium PDF_JS_EXTREME_STRING_REWRITE_OBFUSCATION
PDF JavaScript behavior: PDF JavaScript Extreme String Rewrite Obfuscation.
PDF JavaScript Known CVE Heapspray Family medium PDF_JS_KNOWN_CVE_HEAPSPRAY_FAMILY
PDF JavaScript behavior: PDF JavaScript Known CVE Heapspray Family.
PDF JavaScript Large Comment Padded Eval medium PDF_JS_LARGE_COMMENT_PADDED_EVAL
PDF JavaScript behavior: PDF JavaScript Large Comment Padded Eval.
PDF JavaScript Remote Doc Fetch medium PDF_JS_REMOTE_DOC_FETCH
PDF JavaScript behavior: PDF JavaScript Remote Doc Fetch.
PDF JavaScript Stream Truncated medium PDF_JS_STREAM_TRUNCATED
PDF JavaScript behavior: PDF JavaScript Stream Truncated.
PDF JavaScript Template Placeholder medium PDF_JS_TEMPLATE_PLACEHOLDER
PDF JavaScript behavior: PDF JavaScript Template Placeholder.
PDF Myhome Coded Book Link Farm medium PDF_MYHOME_CODED_BOOK_LINK_FARM
PDF structural or payload evidence: PDF Myhome Coded Book Link Farm.
PDF SEO Disposable Link Farm medium PDF_SEO_DISPOSABLE_LINK_FARM
PDF contains a dense disposable-domain SEO link-farm pattern.
PDF SEO Spam Template medium PDF_SEO_SPAM_TEMPLATE
PDF structural or payload evidence: PDF SEO Spam Template.
PDF Script Encoder Blob medium PDF_SCRIPT_ENCODER_BLOB
PDF structural or payload evidence: PDF Script Encoder Blob.
PDF Type1 Mm Font Overflow medium PDF_TYPE1_MM_FONT_OVERFLOW
PDF structural or payload evidence: PDF Type1 Mm Font Overflow.
A PDF signature's CMS failed verification.
PDF embedded file could not be fully decoded medium PDF_EMBEDDED_FILE_UNDECODED
A declared PDF /EmbeddedFile stream could not be decoded through its filter chain.
PDF embeds a script file as an attachment medium PDF_EMBEDDED_SCRIPT_ATTACHMENT
An /EmbeddedFile attachment is named as a shell, PowerShell, batch, or scripting-host script.
PDF has at least one image XObject and zero text-emitting operators in raw or decompressed content streams.
PDF signature ByteRange does not start at the file head medium PDF_SIGNATURE_BYTERANGE_EVASION
A signature's ByteRange starts past byte 0, leaving content uncovered.
Raw-IP clickable URI medium PDF_URI_IP_LITERAL
PDF clickable URI points to a literal IPv4 address.
Referenced PDF JavaScript object is missing medium PDF_JAVASCRIPT_REFERENCED_OBJECT_MISSING
A /JS action refers to an object absent from the file.
Remote GoTo action medium PDF_GOTO_REMOTE
PDF references a remote or embedded document via GoToR/GoToE.
SEO doc-farm redirector links medium PDF_SEO_DOC_REDIRECTOR_LINK_FARM
PDF carries /pdf/<domain> + /doc/<domain> SEO doc-farm redirector links.
Scheme-label deceptive host link medium PDF_DECEPTIVE_SCHEME_HOST_LINK
PDF clickable link host starts with a literal 'http.'/'https.' DNS label.
Sparse localized cloud-open doorway medium PDF_SPARSE_LOCALIZED_CLOUD_OPEN_LURE
A nearly textless open/view button leads to a user-controlled cloud share.
PDF stream object declares a /Length that does not match the actual bytes between 'stream' and 'endstream'.
Stream advertises a filter that cannot decode the body medium PDF_FILTER_CHAIN_UNDECODABLE
PDF stream declares /Filter /FlateDecode but the raw stream bytes are rejected by zlib in both wrapped and raw modes.
String.fromCharCode medium PDF_FROMCHARCODE
String.fromCharCode found in PDF JavaScript.
SubmitForm action medium PDF_SUBMITFORM
PDF has a /SubmitForm action that can POST data to an external URL.
Truncated exploit-looking PDF JavaScript literal medium PDF_JS_LITERAL_TRUNCATED
A dense /JS reconstruction stage is cut off before its balanced closing delimiter.
U3D stream contains thousands of blocks where real-world files typically contain at most a few hundred.
URL shortener link medium PDF_URL_SHORTENER_URI
PDF clickable URI points to a URL shortener.
Website-builder CDN PDF link farm medium PDF_CDN_PDF_LINK_FARM
PDF carries many document links parked on website-builder CDNs or simple download gateways.
AcroForm button with action trigger low PDF_ACROFORM_BUTTON
PDF contains a /Btn form field paired with a SubmitForm/URI/Launch/JS trigger.
Embedded file low PDF_EMBEDDED
PDF embeds a file attachment.
PDF contains many images but very few text blocks — possible screenshot lure.
Indirect reference to undefined object low PDF_DANGLING_INDIRECT
PDF body contains an indirect reference (N G R) to an object number that is never defined in the file.
PDF uses Optional Content Groups (OCG) and contains an action trigger.
Password-protected PDF (content uninspectable) low PDF_ENCRYPTED_PASSWORD_REQUIRED
PDF is encrypted with a non-empty user password — it cannot be opened, decrypted, or statically inspected without the password.
U3D/3D content in PDF low PDF_U3D_CONTENT
PDF contains U3D/3D annotation content or U3D signatures.
XFA form low PDF_XFA
PDF uses XML Forms Architecture (XFA).
syncAnnotScan annotation-staging primitive low PDF_FOXIT_SYNCANNOTSCAN
PDF JavaScript calls syncAnnotScan() — an exploit-kit staging primitive used to force annotation enumeration before reading payload bytes from /Subject fields.
Body-only duplicate object in PDF info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
Same indirect object (N G) is defined more than once with different body bytes.
CFF CharString operand stack grows beyond spec info PDF_CFF_CHARSTRING_STACK_OVERFLOW
Type 2 CharString bytecode pushes more operands than the interpreter stack should hold.
Duplicate JavaScript provenance copies collapsed info PDF_JAVASCRIPT_PROVENANCE_DEDUP
Semantically equivalent JavaScript views were deduplicated before counting and analysis.
EICAR PDF attachment export/launch demonstration info PDF_EICAR_EXPORT_LAUNCH_TEST
The standard EICAR test string is exported and launched by Acrobat JavaScript.
Encrypted document info PDF_ENCRYPTED
PDF declares /Encrypt — strings and stream contents are encrypted.
External URI info PDF_URI
PDF contains an external URL action.
Large image-only JBIG2 scanned document info PDF_IMAGE_ONLY_SCAN_PROFILE
Large PDF contains many JBIG2 page images without executable actions.
Object defined twice with different bodies info PDF_DUPLICATE_OBJ_DIVERGENT_BODY
Same indirect object (N G) is defined more than once with different body bytes.
The document is digitally signed or certified.
PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
The cross-check parser (pdfminer.six) raised an error on this file.
PDF signed with a self-signed certificate info PDF_SIGNATURE_SELF_SIGNED
The PDF signing certificate is self-signed (issuer == subject).
Recognised benign Acrobat JavaScript helper info PDF_BENIGN_JAVASCRIPT_HELPER
Document JavaScript matches a narrow barcode or attachment UI helper profile.
Reconstructed PDF JavaScript provenance info PDF_JAVASCRIPT_RECONSTRUCTION_PROVENANCE
Source objects, stage index, and semantic hash are retained for reconstructed JavaScript.
RichMedia asset is empty or truncated info PDF_RICHMEDIA_EMPTY_ASSET
All embedded assets referenced by the RichMedia configuration are zero bytes.
Validly signed PDF form without harmful behavior info PDF_VALID_SIGNATURE_BENIGN_FORM
Validly signed PDF form was downgraded after no harmful behavior was found.