Advance Fee Fraud (AFF) from freemail provider or suspicious TLD
Attachment: Calendar file with invisible Unicode characters
Attachment: Calendar invite with Google redirect and invoice request
Attachment: Canva PDF with susupicious author metadata
Attachment: Credit card application with WhatsApp contact
Attachment: Duplicated header pages in fraudulent multi-page PDF Request for Quotation
Attachment: EML with Sharepoint link likely unrelated to sender
Attachment: Encrypted zip file with payment-related lure
Attachment: Fake lawyer & sports agent identities
Attachment: Fictitious invoice using LinkedIn's address
Attachment: ICS calendar file with suspicious UID domain
Attachment: ICS file with meeting prefix
Attachment: ICS with employee policy review lure
Attachment: Invoice and W-9 PDFs with suspicious creators
Attachment: Legal themed message or PDF with suspicious indicators
Attachment: Link to Doubleclick.net open redirect
Attachment: PDF bid/proposal lure with credential theft indicators
Attachment: PDF contains W9 or invoice YARA signatures
Attachment: PDF file with link to fake Bitcoin exchange
Attachment: PDF file with recipient domain and ATT eCheckRun pattern
Attachment: PDF generated with wkhtmltopdf tool and default title
Attachment: PDF Object Hash associated with a fake invoice and a W-9
Attachment: PDF with fake invoice using suspicious font sizing
Attachment: PDF with self-service platform links with self sender or blank recipients
Attachment: PDF with specific W-9 lure
Attachment: PDF with suspicious internal object reference identifier
Attachment: PDF with W-9 form indicators
Attachment: RFP/RFQ impersonating government entities
Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
Attachment: USDA bid invitation impersonation
BEC: Employee impersonation with subject manipulation
BEC: Executive coaching vendor impersonation
BEC: Financial fraud from newly registered sender domain
BEC/Fraud: Fake investment outreach from suspicious TLD
BEC/Fraud: Generic scam attempt to undisclosed recipients
BEC/Fraud: Job scam fake thread or plaintext pivot to freemail
BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply
BEC/Fraud: Scam lure with freemail pivot
BEC/Fraud: Student loan callback phishing
BEC/Fraud: Unsolicited business acquisition offer
BEC/Fraud: Urgent language and suspicious sending/infrastructure patterns
BEC with unusual reply-to or return-path mismatch
Body: Embedded email headers indicative of thread hijacking/abuse
Body: Invisible Unicode obfuscation student loan callback phishing
Body: PayApp transaction reference pattern
Body: Yellow highlighted text markers
Brand impersonation: AARP