OOXML QR credential-phishing lure

OOXML_QR_CREDENTIAL_PHISH

← All detection heuristics · Social engineering

critical OOXML_QR_CREDENTIAL_PHISH

What it means

An embedded QR URL is paired with a scan/sign-in/document-access lure.

Why it fires

The scanner decodes bounded OOXML media with zxing-cpp and requires visible credential or document-access context before asserting phishing.

Other Social engineering heuristics

SE_BOOKING_COMPLAINT_PHISH PDF_FAKE_DOCUMENT_COMPONENT_INSTALLER SE_CALLBACK_SCAM_TEMPLATE PDF_BRAND_ACCOUNT_UPDATE_REDIRECT_LURE PDF_IMAGE_REPEATED_DECOY_REDIRECT_LURE PDF_IMAGE_DOCUMENT_REVIEW_HOST_LURE PDF_LOCALIZED_DOWNLOAD_HOSTING_LURE PDF_MINIMAL_VIEW_DOCUMENT_REDIRECT PDF_NESTED_ENCODED_CROSSHOST_REDIRECT PDF_RFP_EXTERNAL_ACTION_LURE PDF_UTILITY_REFUND_OFFDOMAIN_LURE PDF_SPARSE_MOVED_ARTICLE_DOORWAY