Attachment: PDF with secure document acknowledgment prompt
Attachment: PDF with self-service platform links with self sender or blank recipients
Attachment: PDF with specific author metadata
Attachment: PDF with specific W-9 lure
Attachment: PDF with split QR code
Attachment: PDF with suspicious document view lure
Attachment: PDF with suspicious HeadlessChrome metadata
Attachment: PDF with suspicious internal object reference identifier
Attachment: PDF with suspicious language and redirect to suspicious file type
Attachment: PDF with suspicious link and action-oriented language
Attachment: PDF with suspicious view document characteristics
Attachment: PDF with View RFP Document lure with external link
Attachment: PDF with W-9 form indicators
Attachment: Potential sandbox evasion in Office file
Attachment: PowerPoint with suspicious hyperlink
Attachment: PowerShell content
Attachment: QR code link with base64-encoded recipient address
Attachment: QR code with encoded recipient targeting and redirect indicators
Attachment: QR code with recipient targeting and special characters
Attachment: QR code with suspicious URL patterns in EML file
Attachment: QR code with userinfo portion
Attachment: QuickBooks PDF lure
Attachment: RDP connection file
Attachment: RFC822 containing suspicious file sharing language with links from untrusted sender
Attachment: RFP/RFQ impersonating government entities
Attachment: Risk assessment PDF with inline image
Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
Attachment: RTF file with suspicious link
Attachment: RTF with embedded content
Attachment: RTF with link to free-hosted Cloudflare Pages
Attachment: Self-sender PDF with minimal content and view prompt
Attachment: SFX archive containing commands
Attachment: Single-page PDF with S3-hosted HTML link
Attachment: Small text file with link containing recipient email address
Attachment: Soda PDF producer with encryption themes
Attachment soliciting user to enable macros
Attachment: Suspicious employee policy update document lure
Attachment: Suspicious PDF created with headless browser
Attachment: SVG file execution
Attachment: SVG files with evasion elements
Attachment: SVG file with HTML entity encoded href attributes
Attachment: SVG file with hyperlinks and cursor styling
Attachment: TAR file with RAR type
Attachment: Targeted DOCX with personalized recipient acknowledgement lure
Attachment: Uncommon compressed file
Attachment: USDA bid invitation impersonation
Attachment: Web files with suspicious comments
Attachment: WinRAR CVE-2025-8088 exploitation
Attachment with auto-executing macro (unsolicited)
Attachment with auto-opening VBA macro (unsolicited)