Adobe branded PDF file linking to a password-protected file from untrusted sender
Attachment: Adobe Sign lure PDF with embedded banner images
Attachment: Archive with pdf, txt and wsf files
Attachment: Callback phishing solicitation via pdf file
Attachment: Canva PDF with susupicious author metadata
Attachment: Compensation review lure with QR code
Attachment: Decoy PDF author (Julie P.)
Attachment: DocuSign impersonation via PDF linking to new domain
Attachment: Duplicated header pages in fraudulent multi-page PDF Request for Quotation
Attachment: Encrypted PDF With Credential Harvesting Indicators
Attachment: Encrypted PDF with credential theft body
Attachment: Encrypted PDF with credential theft language in EML
Attachment: Fake PDF Invoices Yara
Attachment: Fake research internship offer
Attachment: Fake scan-to-email
Attachment: Fake voicemail via PDF
Attachment: Fictitious invoice using LinkedIn's address
Attachment: Finance themed PDF with observed phishing template
Attachment: Hex-encoded recipient email in URL fragment
Attachment: Identity Confirmation With Document Unlock Code
Attachment: Invoice and W-9 PDFs with suspicious creators
Attachment: Legal themed message or PDF with suspicious indicators
Attachment: Microsoft impersonation via PDF with link and suspicious language
Attachment: Microsoft OAuth credential harvesting via EML with embedded malicious links
Attachment: Password-protected PDF with fake document indicators
Attachment: PDF Attachment with links to workers.dev
Attachment: PDF bid/proposal lure with credential theft indicators
Attachment: PDF contains W9 or invoice YARA signatures
Attachment: PDF credential phishing via wkhtmltopdf/Qt with suspicious link
Attachment: PDF document portal credential theft lure
Attachment: PDF file with link to fake Bitcoin exchange
Attachment: PDF file with low reputation links to suspicious filetypes (unsolicited)
Attachment: PDF file with low reputation link to ZIP file (unsolicited)
Attachment: PDF file with recipient domain and ATT eCheckRun pattern
Attachment: PDF generated with wkhtmltopdf tool and default title
Attachment: PDF Grant Payment lure with embedded link
Attachment: PDF Object Hash associated with a fake invoice and a W-9
Attachment: PDF Object Hash associated with fake Canada Revenue Agency documents
Attachment: PDF Object Hash - Encrypted PDFs with fake payment notification
Attachment: PDF Object Hash - Encrypted PDF with proposal bid lure
Attachment: PDF Object Hash with Blue File Icon
Attachment: PDF proposal with credential theft indicators
Attachment: PDF templated investment lure
Attachment: PDF W9 signature reuse
Attachment: PDF with a suspicious string and single URL
Attachment: PDF with base64 JavaScript and eval functions
Attachment: PDF with blurry lure image
Attachment: PDF with bolded passcode
Attachment: PDF with credential theft language and invalid reply-to domain