Attachment: ICS file with links to newly registered domains
Attachment: ICS file with meeting prefix
Attachment: ICS invite meeting lure
Attachment: ICS Link With Valueless Base64 Query Parameter
Attachment: ICS voicemail lure with suspicious link
Attachment: ICS with employee policy review lure
Attachment: Identity Confirmation With Document Unlock Code
Attachment: Image-only docx/pptx callback phishing
Attachment: Invoice and W-9 PDFs with suspicious creators
Attachment: Legal themed message or PDF with suspicious indicators
Attachment: Link to Doubleclick.net open redirect
Attachment: Microsoft 365 credential phishing
Attachment: Microsoft impersonation via PDF with link and suspicious language
Attachment: Microsoft SharePoint Impersonation via images in macro-enabled attachment
Attachment: Office file contains OLE relationship to credential phishing page
Attachment: Office file with credential phishing URLs
Attachment: Office file with document sharing and browser instruction lures
Attachment: PDF bid/proposal lure with credential theft indicators
Attachment: PDF contains W9 or invoice YARA signatures
Attachment: PDF credential phishing via wkhtmltopdf/Qt with suspicious link
Attachment: PDF file with link to fake Bitcoin exchange
Attachment: PDF file with recipient domain and ATT eCheckRun pattern
Attachment: PDF Grant Payment lure with embedded link
Attachment: PDF proposal with credential theft indicators
Attachment: PDF templated investment lure
Attachment: PDF with a suspicious string and single URL
Attachment: PDF with bolded passcode
Attachment: PDF with credential theft language and invalid reply-to domain
Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)
Attachment: PDF with dub.sh shortened link
Attachment: PDF with embedded box-lure and javascript
Attachment: PDF with fake invoice using suspicious font sizing
Attachment: PDF with Microsoft Purview message impersonation
Attachment: PDF with multistage landing - ClickUp abuse
Attachment: PDF with personal Microsoft OneNote URL
Attachment: PDF with QR code containing recipient-specific credential theft content
Attachment: PDF with quote lure
Attachment: PDF with recipient email in link
Attachment: PDF with secure document acknowledgment prompt
Attachment: PDF with specific W-9 lure
Attachment: PDF with suspicious document view lure
Attachment: PDF with suspicious link and action-oriented language
Attachment: PDF with suspicious view document characteristics
Attachment: PDF with View RFP Document lure with external link
Attachment: PDF with W-9 form indicators
Attachment: QR code link with base64-encoded recipient address
Attachment: QR code with credential phishing indicators
Attachment: QR code with recipient targeting and special characters
Attachment: QR code with suspicious URL patterns in EML file