Fake encrypted/secure-document view lure

SE_ENCRYPTED_DOC_LURE

← All detection heuristics · Social Engineering

high SE_ENCRYPTED_DOC_LURE

What it means

Document claims to be encrypted/protected and steers the reader to a deceptive 'secure view' link.

Why it fires

The secure-document phishing carrier: the page claims the file is encrypted or protected by a secure service ("this document is encrypted using …", "click below to securely view") and the action link uses deceptive infrastructure — a destination host whose first DNS label is literally 'http'/'https' (e.g. 'https.file-transfers.example.com'), or an abused app-hosting/redirector service. Legitimate secure-mail gateways use similar wording but link to their own honest domains, so the lure text alone never fires; the deceptive-link corroborator is required.

Other Social Engineering heuristics

SE_BOOKING_COMPLAINT_PHISH PDF_FAKE_DOCUMENT_COMPONENT_INSTALLER OOXML_QR_CREDENTIAL_PHISH SE_CALLBACK_SCAM_TEMPLATE PDF_BRAND_ACCOUNT_UPDATE_REDIRECT_LURE PDF_IMAGE_REPEATED_DECOY_REDIRECT_LURE PDF_IMAGE_DOCUMENT_REVIEW_HOST_LURE PDF_LOCALIZED_DOWNLOAD_HOSTING_LURE PDF_MINIMAL_VIEW_DOCUMENT_REDIRECT PDF_NESTED_ENCODED_CROSSHOST_REDIRECT PDF_RFP_EXTERNAL_ACTION_LURE PDF_UTILITY_REFUND_OFFDOMAIN_LURE PDF_SPARSE_MOVED_ARTICLE_DOORWAY