Attachment: PDF with ReportLab library and default metadata
Attachment: PDF With SAI Global ISO9001 Logo
Attachment: PDF with self-service platform links with self sender or blank recipients
Attachment: PDF with specific author metadata
Attachment: PDF with split QR code
Attachment: PDF with suspicious HeadlessChrome metadata
Attachment: PDF with suspicious internal object reference identifier
Attachment: PDF with suspicious language and redirect to suspicious file type
Attachment: PDF with suspicious link and action-oriented language
Attachment: PDF with suspicious view document characteristics
Attachment: PDF with W-9 form indicators
Attachment: QR code link with base64-encoded recipient address
Attachment: QR code with userinfo portion
Attachment: RFP/RFQ impersonating government entities
Attachment: Self-sender PDF with minimal content and view prompt
Attachment: Soda PDF producer with encryption themes
Attachment: Suspicious employee policy update document lure
Attachment: Suspicious PDF created with headless browser
Attachment: USDA bid invitation impersonation
Brand impersonation: Adobe Acrobat Sign PDF phishing file format template
Brand impersonation: Adobe (QR code)
Brand impersonation: DocuSign PDF attachment with suspicious link
Brand impersonation: DocuSign (QR code)
Brand impersonation: Fake procurement/RFQ PDF from energy and industrial companies
Brand Impersonation: Google (QR Code)
Brand impersonation: Microsoft (QR code)
Brand impersonation: SharePoint PDF attachment with credential theft language
Callback phishing: Social Security Administration fraud
Credential phishing: Tax form impersonation with payment request
Extortion / Sextortion - PDF attachment leveraging breach data from freemail sender
Link: PDF display text with fake copyright claim template
Link: PDF file disguised as HTML page
Link: PDF filename impersonation with credential theft language
Link: SharePoint OneNote or PDF link with self sender behavior
Link: Uncommon SharePoint document type with sender's display name
PDF attachment with Google (AE) redirecting to a php or zip file
Sharepoint link likely unrelated to sender
Spam: Unsolicited malformed PDF
Suspicious attachment: Duplicate decoy PDF files
Suspicious attachment with unscannable Cloudflare link
Suspicious SharePoint file sharing
URLhaus: Malicious domain in message body or pdf attachment (trusted reporters)