Attachment: Adobe Sign lure PDF with embedded banner images
Attachment: Archive contains DLL-loading macro
Attachment: Archive with embedded EXE file
Attachment: DocX embedded binary
Attachment: DOCX with malicious document template artifacts
Attachment: EML with Encrypted ZIP
Attachment: Encrypted PDF With Credential Harvesting Indicators
Attachment: Fake PDF Invoices Yara
Attachment: HTML file with excessive padding and suspicious patterns
Attachment: HTML file with reference to recipient and suspicious patterns
Attachment: HTML smuggling with embedded base64-encoded executable
Attachment: JavaScript file with suspicious base64-encoded executable
Attachment: Malformed OLE file
Attachment: Malicious OneNote commands
Attachment: Malicious zip file matching zipline campaign
Attachment: MS Office or RTF file with Shell.Explorer.1 com object with embedded LNK
Attachment: Password-protected PDF with fake document indicators
Attachment: PDF contains W9 or invoice YARA signatures
Attachment: PDF with blurry lure image
Attachment: PDF with CVE-2026-34621 lures
Attachment: PDF with eCheckRun lures
Attachment: PDF with fake invoice using suspicious font sizing
Attachment: PDF with JSFck obfuscation
Attachment: PDF with quote lure
Attachment: PDF With SAI Global ISO9001 Logo
Attachment: PDF with secure document acknowledgment prompt
Attachment: PDF with specific W-9 lure
Attachment: PDF with split QR code
Attachment: PDF with suspicious document view lure
Attachment: PDF with suspicious view document characteristics
Attachment: PDF with W-9 form indicators
Attachment: RTF with embedded content
Attachment: WinRAR CVE-2025-8088 exploitation
Attachment with unscannable encrypted zip
Attachment: ZIP file with CVE-2026-0866 exploit
Encrypted Microsoft Office files from untrusted sender
Link to auto-downloaded disk image in encrypted zip
Link to auto-downloaded DMG in encrypted zip
Link to auto-download of a suspicious file type (unsolicited)