A Booking.com guest-complaint lure sends its review action to an unrelated domain.
An Adobe/PDF compatibility prompt links to an installer or remote-management agent.
An embedded QR URL is paired with a scan/sign-in/document-access lure.
An unauthorized-payment callback lure contains unresolved campaign placeholders.
A branded account-lock or payment warning uses a non-brand destination.
An image-heavy PDF repeats a machine-readable decoy layer while redirecting externally.
An image-only document carrier links to a host named like a review, signing, or sharing service.
A localized download/view instruction points to object storage or an unrelated host.
A content-free view/open-document carrier links through tracking, preview, or user hosting.
A PDF link hides a different destination host behind multiple percent-encoding layers.
A request-for-proposal CTA uses an external form or document workflow.
A utility overpayment or refund notice directs the recipient to unrelated hosting.
A nearly empty PDF says an article moved and supplies one external action.