Attachment: MS Office or RTF file with Shell.Explorer.1 com object with embedded LNK
Attachment: MS OOXML file created by Administrator with zero edit time
Attachment: Office document loads remote document template
Attachment: Office document with VSTO add-in
Attachment: Office file contains OLE relationship to credential phishing page
Attachment: Office file with credential phishing URLs
Attachment: Office file with document sharing and browser instruction lures
Attachment: Office file with suspicious function calls or downloaded file path
Attachment: Password-protected PDF with fake document indicators
Attachment: PDF Attachment with links to workers.dev
Attachment: PDF bid/proposal lure with credential theft indicators
Attachment: PDF contains W9 or invoice YARA signatures
Attachment: PDF credential phishing via wkhtmltopdf/Qt with suspicious link
Attachment: PDF file with link to fake Bitcoin exchange
Attachment: PDF file with low reputation links to suspicious filetypes (unsolicited)
Attachment: PDF file with low reputation link to ZIP file (unsolicited)
Attachment: PDF file with recipient domain and ATT eCheckRun pattern
Attachment: PDF generated with wkhtmltopdf tool and default title
Attachment: PDF Grant Payment lure with embedded link
Attachment: PDF Object Hash associated with a fake invoice and a W-9
Attachment: PDF Object Hash associated with fake Canada Revenue Agency documents
Attachment: PDF Object Hash - Encrypted PDFs with fake payment notification
Attachment: PDF Object Hash with Blue File Icon
Attachment: PDF proposal with credential theft indicators
Attachment: PDF templated investment lure
Attachment: PDF with a suspicious string and single URL
Attachment: PDF with base64 JavaScript and eval functions
Attachment: PDF with blurry lure image
Attachment: PDF with bolded passcode
Attachment: PDF with credential theft language and invalid reply-to domain
Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)
Attachment: PDF with CVE-2026-34621 lures
Attachment: PDF with dub.sh shortened link
Attachment: PDF with eCheckRun lures
Attachment: PDF with embedded box-lure and javascript
Attachment: PDF with fake invoice using suspicious font sizing
Attachment: PDF with JSFck obfuscation
Attachment: PDF with link to DMG file download
Attachment: PDF with link to zip containing a wsf file
Attachment: PDF with localhost IP in EXIF title metadata
Attachment: PDF with Microsoft Purview message impersonation
Attachment: PDF with multistage landing - ClickUp abuse
Attachment: PDF with password in filename matching body text
Attachment: PDF with personal Microsoft OneNote URL
Attachment: PDF with QR code containing recipient-specific credential theft content
Attachment: PDF with quote lure
Attachment: PDF with recipient email in link
Attachment: PDF with ReportLab library and default metadata
Attachment: PDF With SAI Global ISO9001 Logo