Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)
Attachment: PDF with CVE-2026-34621 lures
Attachment: PDF with dub.sh shortened link
Attachment: PDF with eCheckRun lures
Attachment: PDF with embedded box-lure and javascript
Attachment: PDF with EOF MD5 hash marker
Attachment: PDF with fake invoice using suspicious font sizing
Attachment: PDF with JSFck obfuscation
Attachment: PDF with link to DMG file download
Attachment: PDF with link to zip containing a wsf file
Attachment: PDF with localhost IP in EXIF title metadata
Attachment: PDF with Microsoft Purview message impersonation
Attachment: PDF with multistage landing - ClickUp abuse
Attachment: PDF with password in filename matching body text
Attachment: PDF with personal Microsoft OneNote URL
Attachment: PDF with QR code containing recipient-specific credential theft content
Attachment: PDF with quote lure
Attachment: PDF with recipient email in link
Attachment: PDF with ReportLab library and default metadata
Attachment: PDF With SAI Global ISO9001 Logo
Attachment: PDF with secure document acknowledgment prompt
Attachment: PDF with self-service platform links with self sender or blank recipients
Attachment: PDF with specific author metadata
Attachment: PDF with specific W-9 lure
Attachment: PDF with split QR code
Attachment: PDF with suspicious document view lure
Attachment: PDF with suspicious HeadlessChrome metadata
Attachment: PDF with suspicious internal object reference identifier
Attachment: PDF with suspicious language and redirect to suspicious file type
Attachment: PDF with suspicious link and action-oriented language
Attachment: PDF with suspicious view document characteristics
Attachment: PDF with View RFP Document lure with external link
Attachment: PDF with W-9 form indicators
Attachment: QR code link with encoded recipient address
Attachment: QR code with userinfo portion
Attachment: QuickBooks PDF lure
Attachment: RFP/RFQ impersonating government entities
Attachment: Risk assessment PDF with inline image
Attachment: Self-sender PDF with minimal content and view prompt
Attachment: Single-page PDF with S3-hosted HTML link
Attachment: Soda PDF producer with encryption themes
Attachment: Suspicious employee policy update document lure
Attachment: Suspicious PDF created with headless browser
Attachment: USDA bid invitation impersonation
Brand impersonation: Adobe Acrobat Sign PDF phishing file format template
Brand impersonation: Adobe (QR code)
Brand impersonation: DocuSign PDF attachment with suspicious link
Brand impersonation: DocuSign (QR code)
Brand impersonation: Fake procurement/RFQ PDF from energy and industrial companies
Brand Impersonation: Google (QR Code)