{"id":402977,"date":"2026-08-16T06:11:57","date_gmt":"2026-08-16T06:11:57","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=402977"},"modified":"2026-08-16T06:11:57","modified_gmt":"2026-08-16T06:11:57","slug":"fedex-e-order-email-scam","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/fedex-e-order-email-scam\/","title":{"rendered":"FedEx e-Order Email Scam Hides Malware Inside a Fake Customs Spreadsheet"},"content":{"rendered":"<p>An unexpected customs problem can sound routine when a company regularly receives shipments.<\/p><div id=\"mwtad3434460218\" class=\"gas_fallback-ad_309684--placement_400588\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The FedEx e-Order Email Scam abuses that expectation, hiding a potentially dangerous Excel file behind the language of an air waybill, tax receipt, and time-sensitive clearance request.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/fedex-e-order-email.png\" alt=\"Reconstruction of a fake FedEx e-Order email about customs clearance documents\" title=\"\"><\/figure>\n<div id=\"mwtad3929920003\" class=\"mwtadp1 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"> \r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"7312657698\"><\/ins>\r\n <\/div><p>The message says a package needs additional information for customs clearance and may be held in temporary storage for 20 days. It asks the recipient to inspect an attached spreadsheet presented as shipping or payment documentation.<\/p>\n<p>The attachment can open with a realistic contract or logistics document visible behind Microsoft Excel&#8217;s Protected View warning.<\/p>\n<p>That polished appearance is bait. The danger begins when the recipient enables editing, enables content, or follows instructions embedded in the workbook.<\/p>\n<p>The exact malware delivered by a campaign can change between messages and was not established from the lure alone.<\/p>\n<p>It could act as a loader for an information stealer, remote-access tool, ransomware, or another payload, so the attachment should be treated as malicious rather than assigned an unsupported family name.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/fedex-malicious-excel.png\" alt=\"Reconstruction of a suspicious FedEx spreadsheet opened in Protected View\" title=\"\"><\/figure>\n<div id=\"mwtad3797818645\" class=\"gas_fallback-ad_309747-ad_309691-placement_400589\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>A Shipping Problem Written for Business Inboxes<\/h3>\n<p>The FedEx e-Order Email Scam is crafted to blend into procurement, logistics, accounts-payable, and customer-service mail.<\/p>\n<div id=\"mwtad2520705387\" class=\"mwtadp3 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"5910219726\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>References to an air waybill, bill of lading, tax document, or customs receipt are familiar enough that an employee may open the file before confirming whether the shipment exists.<\/p>\n<div id=\"mwtad4206464727\" class=\"gas_fallback-ad_309686-ad_309691-placement_400597\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>The message can claim the parcel is waiting for clearance and that information must be supplied within a storage window. This creates operational pressure: the reader imagines delays, fees, missed inventory, or an unhappy customer if the document is ignored.<\/p>\n<h3>The Spreadsheet Is the Delivery Mechanism<\/h3>\n<p>Unlike a simple credential-phishing link, this campaign uses an attached Excel workbook.<\/p>\n<p>A filename such as fedex_awb_bl_tax_bill_document_receipt_payment_05_25_2026_00000000.xls combines several logistics terms to look like a generated transaction record.<\/p>\n<p>Opening the workbook may not immediately infect the computer because Office can place files from the internet in Protected View.<\/p>\n<p>The scam therefore needs the victim to override that protection, enable active content, interact with an embedded object, or follow another instruction that allows code to run.<\/p>\n<h3>One Attachment Can Become a Wider Network Incident<\/h3>\n<p>If malicious content executes, the initial program may download additional components, steal browser and email data, capture credentials, establish remote access, or prepare files for encryption.<\/p>\n<p>The final behavior depends on the payload served at that time.<\/p>\n<p>A work computer creates risks beyond one mailbox. Saved passwords, shared drives, cloud sessions, accounting records, and trusted supplier conversations can give an intruder routes to other employees and business partners.<\/p>\n<ul>\n<li>Impersonated brand: FedEx, with shipping and customs terminology copied into the message.<\/li>\n<li>False claim: a package requires documentation and can remain in temporary storage for 20 days.<\/li>\n<li>Dangerous item: an unsolicited legacy .xls workbook disguised as logistics paperwork.<\/li>\n<li>Activation attempt: instructions to enable editing, enable content, or otherwise leave Protected View.<\/li>\n<li>Potential impact: credential theft, remote access, follow-on malware, ransomware, and business-email compromise.<\/li>\n<\/ul>\n<div id=\"mwtad3216921330\" class=\"gas_fallback-ad_309748-ad_309691-placement_400590\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why the FedEx Customs Spreadsheet Should Not Be Trusted<\/h2>\n<h3>An Unsolicited Attachment Is Not Shipment Verification<\/h3>\n<p>A logo, tracking vocabulary, and professional signature can be copied into any email. The message must be matched to a shipment initiated by the recipient or organization before its file is considered relevant.<\/p>\n<p>FedEx warns that fraudulent messages may use attachments and shipping claims. A real tracking number can be checked by opening fedex.com independently, without downloading a document or using contact details supplied by the sender.<\/p>\n<h3>Protected View Is a Security Boundary, Not an Error<\/h3>\n<p>Microsoft Office uses Protected View to restrict files obtained from potentially unsafe locations. A banner asking the user to remain protected is not preventing normal reading by accident; it is reducing what the workbook can do to the device.<\/p>\n<p>Scam documents often place a blurred page, fake contract, or instruction behind the banner so the victim believes enabling editing is required to reveal the content. That instruction comes from the attacker, not from FedEx or Microsoft.<\/p>\n<h3>The Payload Cannot Be Identified From the Brand Alone<\/h3>\n<p>Calling every malicious spreadsheet ransomware or a specific stealer would overstate the available evidence.<\/p>\n<p>Campaign operators can replace the downloaded payload, use different attachments for different targets, or shut down one server and activate another.<\/p>\n<p>The correct conclusion is that the file is a malware delivery attempt with an unknown final payload.<\/p>\n<p>Incident response should therefore look for execution, persistence, credential access, network connections, and additional downloads rather than assuming only one behavior.<\/p>\n<div id=\"mwtad1445414914\" class=\"gas_fallback-ad_309749-ad_309691-placement_400591\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5354318971\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the FedEx e-Order Email Scam Works<\/h2>\n<h3>Step 1: The Attacker Sends a Fake e-Order Notice<\/h3>\n<p>The email arrives with a subject related to an e-order, shipment, customs clearance, or missing information. FedEx branding is used because recipients already associate the company with automated delivery messages.<\/p>\n<p>High-volume campaigns send the same template widely, while targeted versions may use a real employee name or public company details. Neither personalization nor a recognizable logo proves that FedEx sent the message.<\/p>\n<h3>Step 2: A Customs Delay Creates Business Pressure<\/h3>\n<p>The body claims that documents are required before the parcel can clear customs. A 20-day temporary-storage period sounds procedural and gives the warning a deadline without making it look like an obvious last-minute threat.<\/p>\n<p>The reader may be asked to reply, review a tax bill, confirm payment, or provide shipment information. In a busy office, the possibility that another department placed the order can stop the recipient from dismissing it immediately.<\/p>\n<h3>Step 3: A Long Filename Makes the Attachment Look Administrative<\/h3>\n<p>The attached .xls file combines terms such as AWB, BL, tax bill, document receipt, payment, a date, and a serial number. This resembles the naming style of an exported enterprise record.<\/p>\n<p>A long filename is not evidence of origin. The legacy .xls format can contain active components and is frequently abused because users still expect spreadsheets in finance and logistics workflows.<\/p>\n<h3>Step 4: The Workbook Opens in Protected View<\/h3>\n<p>Excel may display the file with editing disabled. A realistic shipping agreement, table, stamp, or contract can be visible in the background, reassuring the victim that the attachment contains the promised paperwork.<\/p>\n<p>At this stage, the safest action is to close the workbook. The protective banner should not be bypassed merely because the document claims it cannot display correctly.<\/p>\n<h3>Step 5: Social Engineering Asks the User to Enable Content<\/h3>\n<p>The workbook can tell the reader to click Enable Editing, Enable Content, update links, or interact with an embedded element. The stated reason may be document compatibility, secure preview, or protected company data.<\/p>\n<p>That click can allow macros, formulas, embedded objects, exploits, or another execution path to run. Exact techniques vary, but the shared objective is to turn a passive attachment into active code.<\/p>\n<h3>Step 6: The Initial Code Retrieves or Launches Malware<\/h3>\n<p>Once permitted to run, the workbook can start a script, launch a built-in system tool, unpack hidden content, or contact a remote server. An early component may exist only to fingerprint the device and fetch the current payload.<\/p>\n<p>Security products or a disconnected command server can interrupt the chain, but the absence of an immediate pop-up is not proof of safety. Malware often operates quietly and delays visible behavior.<\/p>\n<h3>Step 7: The Intruder Expands Access and Monetizes the Infection<\/h3>\n<p>A successful payload may steal browser cookies and passwords, capture email sessions, establish remote control, search shared storage, or deliver ransomware later.<\/p>\n<p>Stolen business mail can also be used to replace invoice details or send the same attachment to trusted contacts.<\/p>\n<p>Criminals may sell initial access to another group, so the later incident can look unrelated to the FedEx email. Preserving the message and workbook helps responders connect the first execution event to subsequent activity.<\/p>\n<div id=\"mwtad2910460271\" class=\"gas_fallback-ad_309750-ad_309691-placement_400592\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4041237300\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Company, Address, and Fulfillment Checks<\/h2>\n<h3>FedEx Identity: Start From the Official Site<\/h3>\n<p>Open fedex.com manually or use the official app. Do not rely on an email logo, reply address, or embedded tracking button. FedEx states that it does not send unsolicited requests for sensitive information through insecure channels.<\/p>\n<h3>Sender and Domain: Inspect More Than the Display Name<\/h3>\n<p>Expand the From and Reply-To fields and review the domain. A sender can display FedEx while using an unrelated mailbox.<\/p>\n<p>Authentication results in the full headers can help an administrator assess spoofing, but recipients should still verify the shipment independently.<\/p>\n<h3>Shipment Trace: Match a Known Tracking Number<\/h3>\n<p>Ask whether anyone in the organization expects the parcel, then enter the tracking number on the official FedEx site. Confirm sender, destination, and status through known records. A vague customs claim with no matching shipment should be isolated.<\/p>\n<h3>File Trace: Preserve It Without Opening It Again<\/h3>\n<p>If the attachment reached a work environment, send the original message to the security team using the approved reporting method. Do not forward the live file casually. Responders can hash, detonate, and inspect it in controlled systems without exposing another user.<\/p>\n<div id=\"mwtad1646527998\" class=\"gas_fallback-ad_309751-ad_309691-placement_400593\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3690286463\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Warning Signs in a FedEx e-Order Email<\/h2>\n<p>Shipping malspam works because many legitimate notifications are automated. The differences appear when the attachment and shipment are checked as evidence rather than accepted as routine.<\/p>\n<ul>\n<li>No employee or household member can identify the shipment described in the message.<\/li>\n<li>The sender or Reply-To domain is unrelated to FedEx.<\/li>\n<li>The email attaches a legacy .xls file instead of directing the recipient to a known account.<\/li>\n<li>The filename combines many shipping, tax, and payment terms to appear system-generated.<\/li>\n<li>The workbook opens in Protected View and asks the user to enable editing or content.<\/li>\n<li>The message creates customs pressure but provides no independently verifiable tracking history.<\/li>\n<li>The attachment tries to run code, open a command prompt, contact a domain, or install software.<\/li>\n<li>A reply is requested at an unrelated address or with information FedEx should already possess.<\/li>\n<\/ul>\n<p>The decisive warning is not a spelling mistake. It is the request to turn an unsolicited spreadsheet into active content before the shipment has been verified through FedEx&#8217;s real systems.<\/p>\n<div id=\"deskad1\" class=\"gas_fallback-ad_174270-ad_309691-placement_400594\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5700081834\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<p>If the workbook was opened or content was enabled, treat the event as a possible malware incident. Quick isolation and accurate details are more useful than guessing which malware family may be involved.<\/p>\n<ol>\n<li><strong>Disconnect the affected computer from networks.<\/strong> Turn off Wi-Fi and unplug Ethernet without powering the machine down unless the security team instructs otherwise. Isolation can interrupt data theft and movement to shared systems.<\/li>\n<li><strong>Tell the organization&#8217;s security team immediately.<\/strong> Provide the time the file opened, every button clicked, the filename, and any unusual screen or login prompt. Do not hide that content was enabled; timing directly affects containment.<\/li>\n<li><strong>Do not reopen, rename, or forward the attachment.<\/strong> Preserve the original email and file in place for trained responders. Sending the live workbook to coworkers can create additional infections.<\/li>\n<li><strong>Run a full Malwarebytes scan on a personal device.<\/strong> Update Malwarebytes first if it is safe to reconnect under guidance, scan all drives, quarantine detections, and keep the report. Business devices should follow the company&#8217;s response tooling and policies.<\/li>\n<li><strong>Use AdGuard as a preventive web layer.<\/strong> AdGuard may block known command servers, malicious redirects, and scam pages, but it cannot make an already executed attachment safe or replace endpoint investigation.<\/li>\n<li><strong>Change exposed credentials from a clean device.<\/strong> Prioritize email, VPN, Microsoft 365, Google Workspace, banking, cloud storage, and password managers. Revoke active sessions and tokens, not only the passwords.<\/li>\n<li><strong>Inspect mailbox and business-account persistence.<\/strong> Remove unknown forwarding rules, delegates, OAuth applications, recovery methods, and newly registered multifactor devices. Review Sent Items for messages the attacker may have distributed.<\/li>\n<li><strong>Check financial and shipping workflows.<\/strong> Alert accounts payable, procurement, and logistics to verify payment changes, new bank details, customs requests, and unusual FedEx messages through known contacts.<\/li>\n<li><strong>Monitor the environment after the first cleanup.<\/strong> Look for new programs, scheduled tasks, browser extensions, remote-access tools, encryption, unusual outbound traffic, and sign-ins. Some payloads delay activity or return after a partial removal.<\/li>\n<li><strong>Report the impersonation through official channels.<\/strong> Suspicious FedEx messages can be forwarded to abuse@fedex.com. Preserve headers and case details, and involve law enforcement or cyber-insurance contacts if data, funds, or business operations were affected.<\/li>\n<\/ol>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Is the FedEx e-Order email genuine?<\/h3>\n<p>The campaign described here is not connected to FedEx. Verify any real shipment by entering its tracking number on fedex.com or by contacting a known FedEx representative.<\/p>\n<h3>Does opening the Excel file automatically install malware?<\/h3>\n<p>Not in every case. Protected View can restrict active content, but risk increases if editing, macros, links, embedded objects, or other instructions are enabled. Close the file and report it.<\/p>\n<h3>What malware does the spreadsheet install?<\/h3>\n<p>The final payload was not established from the lure alone and can change. Treat it as an unknown malware-delivery chain and investigate broadly rather than assuming one named family.<\/p>\n<h3>Why does the attachment show a realistic contract?<\/h3>\n<p>Attackers use a visible document as social proof and as a reason to override Protected View. A professional-looking background does not authenticate the code or sender.<\/p>\n<h3>What if I opened it but did not enable anything?<\/h3>\n<p>Close it, preserve the email, and scan the device. Tell the security team in a work environment because alternate execution methods and software vulnerabilities must be considered.<\/p>\n<h3>Where can I report the fake FedEx message?<\/h3>\n<p>Forward suspicious FedEx impersonation email to abuse@fedex.com and use the organization&#8217;s internal phishing-reporting process. Avoid forwarding the attachment to ordinary recipients.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The FedEx e-Order Email Scam uses a believable customs delay to make a dangerous spreadsheet feel like routine paperwork.<\/p>\n<p>The 20-day storage story, administrative filename, and visible contract are all designed to persuade the recipient to override Excel&#8217;s protections.<\/p>\n<p>Verify the shipment through fedex.com and never enable active content in an unsolicited workbook. If the file ran, isolate the device, report it, and secure credentials from a clean system.<\/p>\n<div id=\"mwtad2754062893\" class=\"gas_fallback-ad_176819-ad_309691-placement_400595\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>An unexpected customs problem can sound routine when a company regularly receives shipments. The FedEx e-Order Email Scam abuses that expectation, hiding a potentially dangerous Excel file behind the language of an air waybill, tax &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"FedEx e-Order Email Scam Hides Malware Inside a Fake Customs Spreadsheet\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/fedex-e-order-email-scam\/#more-402977\" aria-label=\"Read more about FedEx e-Order Email Scam Hides Malware Inside a Fake Customs Spreadsheet\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":402978,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-402977","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/402977","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=402977"}],"version-history":[{"count":4,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/402977\/revisions"}],"predecessor-version":[{"id":403129,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/402977\/revisions\/403129"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/402978"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=402977"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=402977"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=402977"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}