EXPLORE DETECTIONS
Attachment: PDF Object Hash - Encrypted PDFs with fake payment notification
Detects PDF attachments containing a specific object hash (63bf167b66091a4bc53e8944a76f6b08) that may indicate malicious content or known threat indicators.
Attachment: PDF Object Hash associated with a fake invoice and a W-9
Matching PDF Object Hash associated with a fake invoice followed by a W-9.
Attachment: PDF Object Hash associated with fake Canada Revenue Agency documents
Matching PDF Object Hash associated with chrome -> export to pdf of a shared document related to Canada's Revenue Agency.
Attachment: PDF Object Hash with Blue File Icon
Detects PDF attachments containing a specific object hash (8638ef6bfe382a927aa12a18f2150757) associated with encrypted PDFs leading to cred phishing.
Attachment: PDF proposal with credential theft indicators
PDF attachment with 'proposal' in filename contains sender or recipient domain, credential theft language detected via OCR, and includes a single URL link.
Attachment: PDF templated investment lure
Detects inbound messages carrying PDF attachments that match a YARA signature for a recurring templated lure using a blue and white design theme.
Attachment: PDF with a suspicious string and single URL
Detects single-page PDF attachments containing suspicious language such as 'View Document' or 'View PDF' along with exactly one URL, commonly used in credential theft attacks.
Attachment: PDF with base64 JavaScript and eval functions
PDF attachment contains base64-encoded JavaScript variables with eval functions, indicating potential code obfuscation and execution techniques commonly used in malicious documents.
Attachment: PDF with blurry lure image
Detects PDF attachments containing a blurry image used in credential phishing lures.
Attachment: PDF with credential theft language and invalid reply-to domain
Detects PDF attachments containing high-confidence credential theft language that references the recipient's email address, combined with an invalid reply-to domain header.
Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)
Detects messages with credential theft PDFs linking to free subdomains.
Attachment: PDF with CVE-2026-34621 lures
Detects PDF attachments containing YARA signatures associated with CVE-2026-34621's observed lures.
Attachment: PDF with eCheckRun lures
Detects PDF attachments matching yara rules looking for attachments containing artifacts from related to fake financial/invoice themes, including eCheckRun lures. These are commonly used to trick users into believe they have received legitmate electronic payment messages.
Attachment: PDF with embedded box-lure and javascript
Detects inbound messages containing a PDF attachment that matches YARA signatures looking for JavaScript functions or specific lure boxes that have been observed within malicious documents.
Attachment: PDF with embedded Javascript
PDF contains embedded Javascript.
Attachment: PDF with fake invoice using suspicious font sizing
PDF attachment contains a fake invoice with suspicious font size patterns and unique image sizes, typically used in fraudulent billing schemes.
Attachment: PDF with JSFck obfuscation
PDF attachment contains JavaScript obfuscated using JSFck encoding techniques. JSFck is a method of writing JavaScript code using only six characters: []()!+ which is often used to evade detection by security tools.
Attachment: PDF with link to DMG file download
This rule identifies PDF attachments that either link directly to a DMG file, link to a ZIP archive containing a DMG file, or link to an encrypted ZIP containing a DMG file. This technique has been observed delivering MetaStealer Malware.
Attachment: PDF with link to zip containing a wsf file
Detects a PDF attachment with a link to a ZIP file that contains a WSF file
Attachment: PDF with localhost IP in EXIF title metadata
Detects inbound PDF attachments where the EXIF title metadata starts with '127.0.0.1', sent either to a self-addressed recipient or an invalid recipient domain. This technique may indicate automated or malicious document generation tools embedding localhost references in file metadata.
Attachment: PDF with Microsoft Purview message impersonation
Detects PDF attachments containing text that impersonates Microsoft Purview secure message notifications, potentially used to trick users into believing they have received legitimate secure communications from Microsoft services.
Attachment: PDF with multistage landing - ClickUp abuse
Detects PDF attachments containing ClickUp document links that either redirect to unavailable pages or contain embedded links leading to newly registered domains, free file hosts, URL shorteners, or verified credential theft pages.
Attachment: PDF with password in filename matching body text
Detects messages containing a single PDF attachment where the filename includes a numeric password that is explicitly referenced in the message body text.
Attachment: PDF with personal Microsoft OneNote URL
Detects PDF attachments containing a sharepoint URL referencing the senders personal OneNote.