Adobe branded PDF file linking to a password-protected file from untrusted sender
Attachment: Adobe Sign lure PDF with embedded banner images
Attachment: Archive with pdf, txt and wsf files
Attachment: Callback phishing solicitation via pdf file
Attachment: Canva PDF with susupicious author metadata
Attachment: Compensation review lure with QR code
Attachment: Decoy PDF author (Julie P.)
Attachment: DocuSign impersonation via PDF linking to new domain
Attachment: Duplicated header pages in fraudulent multi-page PDF Request for Quotation
Attachment: Encrypted PDF With Credential Harvesting Indicators
Attachment: Encrypted PDF with credential theft body
Attachment: Fake PDF Invoices Yara
Attachment: Fake scan-to-email
Attachment: Fake voicemail via PDF
Attachment: Fictitious invoice using LinkedIn's address
Attachment: Finance themed PDF with observed phishing template
Attachment: Invoice and W-9 PDFs with suspicious creators
Attachment: Legal themed message or PDF with suspicious indicators
Attachment: Microsoft impersonation via PDF with link and suspicious language
Attachment: Microsoft OAuth credential harvesting via EML with embedded malicious links
Attachment: Password-protected PDF with fake document indicators
Attachment: PDF Attachment with links to workers.dev
Attachment: PDF bid/proposal lure with credential theft indicators
Attachment: PDF contains W9 or invoice YARA signatures
Attachment: PDF file with link to fake Bitcoin exchange
Attachment: PDF file with low reputation links to suspicious filetypes (unsolicited)
Attachment: PDF file with low reputation link to ZIP file (unsolicited)
Attachment: PDF file with recipient domain and ATT eCheckRun pattern
Attachment: PDF generated with wkhtmltopdf tool and default title
Attachment: PDF Object Hash associated with fake Canada Revenue Agency documents
Attachment: PDF Object Hash - Encrypted PDFs with fake payment notification
Attachment: PDF Object Hash with Blue File Icon
Attachment: PDF proposal with credential theft indicators
Attachment: PDF with a suspicious string and single URL
Attachment: PDF with blurry lure image
Attachment: PDF with credential theft language and invalid reply-to domain
Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)
Attachment: PDF with CVE-2026-34621 lures
Attachment: PDF with eCheckRun lures
Attachment: PDF with fake invoice using suspicious font sizing
Attachment: PDF with JSFck obfuscation
Attachment: PDF with link to DMG file download
Attachment: PDF with link to zip containing a wsf file
Attachment: PDF with localhost IP in EXIF title metadata
Attachment: PDF with Microsoft Purview message impersonation
Attachment: PDF with multistage landing - ClickUp abuse
Attachment: PDF with password in filename matching body text
Attachment: PDF with personal Microsoft OneNote URL
Attachment: PDF with QR code containing recipient-specific credential theft content
Attachment: PDF with recipient email in link