Attachment: QR code with userinfo portion
Attachment: RDP connection file
Attachment: RFC822 containing suspicious file sharing language with links from untrusted sender
Attachment: RFP/RFQ impersonating government entities
Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
Attachment: RTF file with suspicious link
Attachment: RTF with embedded content
Attachment: Self-sender PDF with minimal content and view prompt
Attachment: SFX archive containing commands
Attachment: Single-page PDF with S3-hosted HTML link
Attachment: Small text file with link containing recipient email address
Attachment: Soda PDF producer with encryption themes
Attachment soliciting user to enable macros
Attachment: Suspicious employee policy update document lure
Attachment: Suspicious PDF created with headless browser
Attachment: SVG file execution
Attachment: SVG files with evasion elements
Attachment: SVG file with HTML entity encoded href attributes
Attachment: SVG file with hyperlinks and cursor styling
Attachment: TAR file with RAR type
Attachment: Uncommon compressed file
Attachment: USDA bid invitation impersonation
Attachment: Web files with suspicious comments
Attachment: WinRAR CVE-2025-8088 exploitation
Attachment with auto-executing macro (unsolicited)
Attachment with auto-opening VBA macro (unsolicited)
Attachment with encrypted zip (unsolicited)
Attachment with high risk VBA macro (unsolicited)
Attachment with macro calling executable
Attachment with suspicious author (unsolicited)
Attachment with unscannable encrypted zip
Attachment with VBA macros from employee impersonation (unsolicited)
Attachment: XLSX file with suspicious print titles metadata
Attachment: ZIP file with CVE-2026-0866 exploit
BEC/Fraud: Job scam fake thread or plaintext pivot to freemail
Brand impersonation: Adobe Acrobat Sign PDF phishing file format template
Brand impersonation: Amazon with suspicious attachment
Brand impersonation: Chase bank with credential phishing indicators
Brand impersonation: Coinbase with suspicious links
Brand impersonation: DocuSign PDF attachment with suspicious link
Brand impersonation: Dropbox
Brand impersonation: Fake procurement/RFQ PDF from energy and industrial companies
Brand impersonation: Google fake sign-in warning
Brand impersonation: Microsoft fake sign-in alert
Brand impersonation: Microsoft quarantine release notification in body
Brand impersonation: Microsoft quarantine release notification in image attachment
Brand impersonation: Microsoft Teams
Brand impersonation: Microsoft with low reputation links
Brand impersonation: Norton
Brand Impersonation: PayPal