← All detection heuristics · Social Engineering
high
SE_ENCRYPTED_DOC_LURE
What it means
Document claims to be encrypted/protected and steers the reader to a deceptive 'secure view' link.
Why it fires
The secure-document phishing carrier: the page claims the file is encrypted or protected by a secure service ("this document is encrypted using …", "click below to securely view") and the action link uses deceptive infrastructure — a destination host whose first DNS label is literally 'http'/'https' (e.g. 'https.file-transfers.example.com'), or an abused app-hosting/redirector service. Legitimate secure-mail gateways use similar wording but link to their own honest domains, so the lure text alone never fires; the deceptive-link corroborator is required.
Other Social Engineering heuristics
SE_BOOKING_COMPLAINT_PHISH PDF_FAKE_DOCUMENT_COMPONENT_INSTALLER OOXML_QR_CREDENTIAL_PHISH SE_CALLBACK_SCAM_TEMPLATE PDF_BRAND_ACCOUNT_UPDATE_REDIRECT_LURE PDF_IMAGE_REPEATED_DECOY_REDIRECT_LURE PDF_IMAGE_DOCUMENT_REVIEW_HOST_LURE PDF_LOCALIZED_DOWNLOAD_HOSTING_LURE PDF_MINIMAL_VIEW_DOCUMENT_REDIRECT PDF_NESTED_ENCODED_CROSSHOST_REDIRECT PDF_RFP_EXTERNAL_ACTION_LURE PDF_UTILITY_REFUND_OFFDOMAIN_LURE PDF_SPARSE_MOVED_ARTICLE_DOORWAY