Attachment: Link to Doubleclick.net open redirect
Attachment: Microsoft 365 credential phishing
Attachment: Microsoft impersonation via PDF with link and suspicious language
Attachment: Microsoft SharePoint Impersonation via images in macro-enabled attachment
Attachment: Office file contains OLE relationship to credential phishing page
Attachment: Office file with credential phishing URLs
Attachment: Office file with document sharing and browser instruction lures
Attachment: PDF bid/proposal lure with credential theft indicators
Attachment: PDF contains W9 or invoice YARA signatures
Attachment: PDF file with link to fake Bitcoin exchange
Attachment: PDF file with recipient domain and ATT eCheckRun pattern
Attachment: PDF proposal with credential theft indicators
Attachment: PDF with a suspicious string and single URL
Attachment: PDF with credential theft language and invalid reply-to domain
Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)
Attachment: PDF with fake invoice using suspicious font sizing
Attachment: PDF with Microsoft Purview message impersonation
Attachment: PDF with multistage landing - ClickUp abuse
Attachment: PDF with personal Microsoft OneNote URL
Attachment: PDF with QR code containing recipient-specific credential theft content
Attachment: PDF with quote lure
Attachment: PDF with recipient email in link
Attachment: PDF with secure document acknowledgment prompt
Attachment: PDF with specific W-9 lure
Attachment: PDF with suspicious document view lure
Attachment: PDF with suspicious link and action-oriented language
Attachment: PDF with suspicious view document characteristics
Attachment: PDF with W-9 form indicators
Attachment: QR code link with base64-encoded recipient address
Attachment: QR code with credential phishing indicators
Attachment: QR code with recipient targeting and special characters
Attachment: QR code with suspicious URL patterns in EML file
Attachment: RFC822 containing suspicious file sharing language with links from untrusted sender
Attachment: RFP/RFQ impersonating government entities
Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
Attachment: Self-sender PDF with minimal content and view prompt
Attachment: Small text file with link containing recipient email address
Attachment: Soda PDF producer with encryption themes
Attachment: Suspicious employee policy update document lure
Attachment: USDA bid invitation impersonation
Attachment with VBA macros from employee impersonation (unsolicited)
BEC: Employee impersonation with subject manipulation
BEC: Executive coaching vendor impersonation
BEC: Financial fraud from newly registered sender domain
BEC/Fraud: Fake investment outreach from suspicious TLD
BEC/Fraud: Generic scam attempt to undisclosed recipients
BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply
BEC/Fraud: Student loan callback phishing