Document-share notification lure

SE_DOCUMENT_SHARE_NOTIFY

← All detection heuristics · Social Engineering

medium SE_DOCUMENT_SHARE_NOTIFY

What it means

Document impersonates a file-sharing notification ('a new document has been shared with you').

Why it fires

Consent-phishing and credential-harvest PDFs open with a file-share notification and put the real destination behind a button image. Legitimate share notices use the same wording, so the detector stays MEDIUM on its own; it is intended as the lure half of a composite that also requires an outbound link on a non-reputable host. The phrases are matched against a whitespace-removed copy of the text as well, because this family is usually rendered glyph-by-glyph.

Other Social Engineering heuristics

SE_BOOKING_COMPLAINT_PHISH PDF_FAKE_DOCUMENT_COMPONENT_INSTALLER OOXML_QR_CREDENTIAL_PHISH SE_CALLBACK_SCAM_TEMPLATE PDF_BRAND_ACCOUNT_UPDATE_REDIRECT_LURE PDF_IMAGE_REPEATED_DECOY_REDIRECT_LURE PDF_IMAGE_DOCUMENT_REVIEW_HOST_LURE PDF_LOCALIZED_DOWNLOAD_HOSTING_LURE PDF_MINIMAL_VIEW_DOCUMENT_REDIRECT PDF_NESTED_ENCODED_CROSSHOST_REDIRECT PDF_RFP_EXTERNAL_ACTION_LURE PDF_UTILITY_REFUND_OFFDOMAIN_LURE PDF_SPARSE_MOVED_ARTICLE_DOORWAY