{"id":425733,"date":"2026-10-09T07:40:49","date_gmt":"2026-10-09T07:40:49","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=425733"},"modified":"2026-10-09T12:52:21","modified_gmt":"2026-10-09T12:52:21","slug":"hus-ltd-order-confirmation-email-scam","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/hus-ltd-order-confirmation-email-scam\/","title":{"rendered":"HUS Ltd Order Confirmation Email Scam: Dangerous Excel Attachment Exposed"},"content":{"rendered":"<p>A purchase order arrives with a company signature and an Excel attachment. For someone handling suppliers or sales, it looks like another task awaiting review.<\/p><div id=\"mwtad2366483910\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The HUS Ltd order-confirmation email deserves a closer look before that spreadsheet becomes part of your working day, especially if the order is unexpected.<\/p>\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1672\" height=\"941\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/hus-hero.png\" alt=\"Illustrative HUS Ltd impersonation email with an unexpected purchase order spreadsheet attachment\" class=\"wp-image-425734\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/hus-hero.png 1672w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/hus-hero-300x169.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/hus-hero-1024x576.png 1024w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/hus-hero-1536x864.png 1536w\" sizes=\"auto, (max-width: 1672px) 100vw, 1672px\" \/><\/figure>\n<div id=\"mwtad3333877798\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>A real steel company is being impersonated<\/h3>\n<p>This malicious order-confirmation campaign uses the name of HUS Ltd to persuade recipients to open an Excel attachment presented as business paperwork.<\/p><div id=\"mwtad1224069960\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The genuine <a href=\"https:\/\/www.husltd.com\/en\/\" target=\"_blank\" rel=\"noopener\">HUS Ltd website<\/a> identifies a steel manufacturing and trading company based in Plovdiv, Bulgaria.<\/p>\n<p>That legitimate business presence does not authenticate the email. A company signature, employee name, and public address can be copied into an unrelated message.<\/p>\n<p>The warning concerns the impersonation and attached file. It is not evidence that the real company&#8217;s employees sent malware or that its website was compromised.<\/p><div id=\"mwtad95290669\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<h3>The purchase order leads toward a spreadsheet security boundary<\/h3>\n<p>The reported subject references PO0425. Its attachment is named Order NO. PO00435, HUS Ltd.xls, and the message discusses order confirmation and purchase conditions.<\/p>\n<p>The reported workbook presents little useful content while encouraging the recipient to leave Protected View. That makes the requested security change particularly important.<\/p>\n<ul>\n<li>An unfamiliar order creates a business reason to open the attachment.<\/li>\n<li>A copied company identity supplies apparent legitimacy.<\/li>\n<li>The spreadsheet format feels normal for commercial records.<\/li>\n<li>An editing prompt shifts attention from verification to making the file work.<\/li>\n<\/ul>\n<h3>The payload is unknown, and the buttons matter<\/h3>\n<p>The available campaign report does not identify the final malware payload. We have not executed the attachment, so claims about a specific infection would be unsupported.<\/p><div id=\"mwtad549431555\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Also, Enable Editing and Enable Content are not interchangeable. Leaving Protected View does not automatically enable active content in Office.<\/p>\n<p>The lead illustration uses fictional sender details and represents the attachment lure. It is not the original workbook, and it contains no executable content.<\/p>\n<div id=\"mwtad2514816794\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why This Looks Like Ordinary Supplier Correspondence<\/h2>\n<div id=\"mwtad3151917804\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>Purchase orders are repetitive by design. They contain reference numbers, short instructions, attachments, and signatures that recipients often process quickly.<\/p>\n<p>A busy employee may judge the message by whether it resembles that workflow rather than whether the underlying order can be verified.<\/p>\n<p>Detailed signatures add another distraction. A street address, job title, and company website create an impression of completeness without authenticating the sender.<\/p>\n<p>Looking up the company may confirm that it exists. That answers a narrower question than whether this particular file came from it.<\/p>\n<p>The difference matters for anyone investigating suspicious supplier messages. Finding a real business does not resolve the provenance of an unsolicited attachment.<\/p>\n<p>Start with your own commercial records: did someone request this order, expect these conditions, or ask this contact to send a spreadsheet?<\/p>\n<p>If the answer is uncertain, the next step is verification, not changing Office settings until the file displays something useful.<\/p>\n<div id=\"mwtad469920183\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the HUS Ltd Order Confirmation Email Scam Works<\/h2>\n<h3>Step 1: The message supplies a ready-made business context<\/h3>\n<p>Instead of asking you to install unfamiliar software outright, the email presents a document that appears relevant to an ordinary commercial transaction.<\/p>\n<p>Order references make the message feel specific. Yet a reference is only meaningful when it matches a record held by your organization or verified counterparty.<\/p>\n<p>Do not assume a colleague must have arranged it simply because the company name sounds plausible. Ask the person responsible for the relevant purchase or sale.<\/p>\n<p>If no one recognizes the transaction, preserve the notice for reporting. You do not need to open its attachment to justify that decision.<\/p>\n<h3>Step 2: The signature lends the file someone else&#8217;s credibility<\/h3>\n<p>A business signature encourages readers to picture an accountable professional behind the email. That can make a technical warning seem like an inconvenience rather than useful protection.<\/p>\n<p>However, public contact information is easy to reuse. It cannot establish which account sent the message or whether the attached file was authorized.<\/p>\n<p>Even a familiar conversation should be checked if its request changes unexpectedly. Compromised correspondence and copied signatures are different possibilities requiring evidence, not assumptions.<\/p>\n<p>For this case, the available evidence supports impersonation. It does not identify the method used to obtain the signature or prove a breach at HUS.<\/p>\n<h3>Step 3: The attachment moves the interaction into Excel<\/h3>\n<p>The recipient is encouraged to treat the workbook as the place where the real transaction details will become clear.<\/p>\n<p>This can reverse the safe order of checks. Instead of confirming the transaction before opening the file, you open the file to discover the transaction.<\/p>\n<p>Excel workbooks can contain more than visible cells. Their risk depends on content, application behavior, security controls, and what the user authorizes.<\/p>\n<p>The .xls extension identifies an older Excel format; it is not a certificate of safety. Renaming a file or seeing a spreadsheet icon changes nothing.<\/p>\n<p>Do not upload private business attachments to a public analysis service without permission. Your security team may have a controlled way to inspect them.<\/p>\n<h3>Step 4: A viewing problem becomes a request to reduce protection<\/h3>\n<p>When expected content does not appear, readers naturally look for a way to fix the display. A prominent editing control can seem like the next sensible step.<\/p>\n<p>Protected View is a safety boundary, not an error message that a document sender is entitled to override.<\/p>\n<p>If an unsolicited order requires you to trust content before explaining itself, stop. The lack of useful visible information is not a reason to grant additional permissions.<\/p>\n<p>Do not follow instructions to disable protections globally, add an unknown trusted location, or run an unrelated command to reveal commercial paperwork.<\/p>\n<p>A legitimate counterpart can confirm the order and provide an approved alternative through your normal business process.<\/p>\n<h3>Step 5: Further execution depends on the file and environment<\/h3>\n<p>Some malicious Office documents rely on active content or vulnerable application behavior. Not every attachment executes merely because it is downloaded or viewed.<\/p>\n<p>Microsoft distinguishes leaving Protected View from enabling active content. Current Office defenses may also block internet-origin macros, depending on the product and configuration.<\/p>\n<p>That is why a response needs exact details: which file opened, which warnings appeared, and which controls you selected.<\/p>\n<p>There is no identified payload to name in this campaign&#8217;s available record. Do not assume ransomware, a password stealer, or remote access without further evidence.<\/p>\n<p>Nevertheless, unexpected execution or permission changes warrant assessment. Lack of a confirmed malware name is not a reason to continue experimenting with the workbook.<\/p>\n<div id=\"mwtad3852917471\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Enable Editing Is Not the Same as Enable Content<\/h2>\n<h3>Leaving Protected View changes how Office treats the document<\/h3>\n<p>Protected View restricts how an untrusted document is handled. Selecting Enable Editing takes the document out of that protective viewing mode.<\/p>\n<p>That action is meaningful, but it should not be described as universally equivalent to running macros. The distinction affects both prevention and incident reporting.<\/p>\n<p>Microsoft&#8217;s <a href=\"https:\/\/support.microsoft.com\/en-us\/office\/security-privacy\/trusted-documents\" target=\"_blank\" rel=\"noopener\">trusted-document documentation<\/a> states that active content is not automatically enabled when a user exits Protected View.<\/p>\n<p>If you remember clicking only Enable Editing, tell support exactly that. Do not change your account of events to match an alarming explanation you read online.<\/p>\n<h3>Active-content prompts and blocked macros are separate decisions<\/h3>\n<p>A workbook may present additional warnings about content that Office has disabled. Those warnings deserve their own assessment, not automatic approval.<\/p>\n<p>Microsoft also documents how <a href=\"https:\/\/learn.microsoft.com\/en-us\/microsoft-365-apps\/security\/internet-macros-blocked\" target=\"_blank\" rel=\"noopener\">internet-origin macros are blocked in supported Office configurations<\/a>.<\/p>\n<p>Do not search for a bypass to satisfy an unknown sender. A security control preventing the file from working may be doing exactly what it should.<\/p>\n<p>Your organization&#8217;s settings can differ from another person&#8217;s computer. Advice based on a different Office version may not explain what happened on yours.<\/p>\n<h3>A blank workbook is not a diagnosis<\/h3>\n<p>An empty-looking sheet does not prove infection, nor does it prove the attachment is harmless. It only describes what the application displayed.<\/p>\n<p>Similarly, an application crash does not identify a particular malware family. Security assessment needs the file and relevant system evidence.<\/p>\n<p>The safe practical decision is to stop handling an unexpected workbook and let an authorized person investigate it without lowering protections.<\/p>\n<h2>What to Do If You Opened the Attachment<\/h2>\n<ol>\n<li>\n<p><strong>Stop interacting with the workbook.<\/strong> Do not reopen it, approve more prompts, or try suggested display fixes from the sender.<\/p>\n<p>Write down what you remember seeing and clicking. Include whether the file stayed in Protected View or whether you enabled editing, content, or another permission.<\/p>\n<\/li>\n<li>\n<p><strong>Notify workplace IT if this is a business device.<\/strong> Provide the message and attachment using the approved incident-reporting process.<\/p>\n<p>Avoid forwarding the file to coworkers for an informal second opinion. That could expose more people while adding little reliable evidence.<\/p>\n<p>If you suspect active compromise, stop sensitive work and follow your organization&#8217;s isolation procedure. Let responders decide how to preserve logs and system state.<\/p>\n<\/li>\n<li>\n<p><strong>Preserve the original message safely.<\/strong> Headers, arrival time, attachment name, and the recipient account can help investigators connect related deliveries.<\/p>\n<p>Do not post the workbook publicly or send confidential business material to an unknown scanning service. Ask the security team how to transfer it.<\/p>\n<\/li>\n<li>\n<p><strong>Have a personal device checked if risky content ran.<\/strong> Use trusted security software and install operating-system and Office updates through their normal channels.<\/p>\n<p>Malwarebytes can assist with detecting malicious or unwanted software. No single scan can establish every action a file may have taken before detection.<\/p>\n<p>Seek qualified help if warnings persist, unfamiliar programs appear, or you cannot explain recent account activity. Avoid cleanup tools offered by the suspicious email.<\/p>\n<\/li>\n<li>\n<p><strong>Secure accounts if there is evidence of exposure.<\/strong> Use a clean device when malware execution is suspected, especially for email and financial services.<\/p>\n<p>Replace compromised credentials and examine suspicious account activity with the provider or administrator. Merely receiving the attachment does not mean every password must have been stolen.<\/p>\n<\/li>\n<li>\n<p><strong>Review browser changes only if the incident included browsing.<\/strong> Remove unexpected extensions or notification permissions granted during any related visit.<\/p>\n<p>AdGuard may help with malicious advertising exposure on the web. It is not a tool for neutralizing an Excel workbook or restoring a compromised machine.<\/p>\n<\/li>\n<li>\n<p><strong>Confirm the commercial situation independently.<\/strong> Ask the genuine business contact whether an actual order or delivery needs attention.<\/p>\n<p>Use an existing vendor record or the company&#8217;s independently opened website. Do not accuse the named employee based only on a copied signature.<\/p>\n<\/li>\n<li>\n<p><strong>Close the incident with a clear internal record.<\/strong> Record the assessment, affected systems, cleanup, and any account changes your responders directed.<\/p>\n<p>If the file was blocked before execution, document that outcome too. Accurate reporting helps avoid both unnecessary alarm and missed follow-up work.<\/p>\n<\/li>\n<\/ol>\n<h2>A Safer Purchase-Order Workflow<\/h2>\n<p>Purchasing and sales teams need to exchange documents. A useful defense should make unexpected orders easier to verify, not make ordinary work impossible.<\/p>\n<p>Maintain a trusted vendor directory separately from incoming messages. That gives employees a contact route the suspicious sender did not supply.<\/p>\n<p>Assign someone to keep that directory current when staff or suppliers change. An outdated contact list can send employees back to unverified email signatures.<\/p>\n<p>Require unfamiliar order references to be matched with an internal owner. A busy shared inbox should not turn uncertainty into permission to open every attachment.<\/p>\n<p>When a sender asks for a different file-handling process, confirm the change outside the email thread. This is especially important for security-setting exceptions.<\/p>\n<p>Agree on approved document formats and transfer channels where practical. A transaction can often continue without asking staff to enable unknown active content.<\/p>\n<p>Keep software supported and updated, but do not treat updates as permission to trust arbitrary attachments. Technical defenses and business verification address different risks.<\/p>\n<p>Encourage fast reporting of mistakes. Someone who clicked a warning should be able to explain it immediately without first trying to fix the situation alone.<\/p>\n<p>The strongest lesson from this lure is about workflow: the desire to finish an ordinary task should not determine whether an unfamiliar file receives trust.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Is HUS Ltd a fake company?<\/h3>\n<p>No. Its official site describes a real steel business. This warning concerns a malicious message using its identity, not the legitimacy of the company itself.<\/p>\n<h3>Is the attachment a confirmed ransomware installer?<\/h3>\n<p>The available record does not identify its final payload. Calling it a specific ransomware family would go beyond the evidence.<\/p>\n<h3>Does clicking Enable Editing automatically run macros?<\/h3>\n<p>No. Office distinguishes leaving Protected View from enabling active content. Report the exact prompts you approved so the incident can be assessed correctly.<\/p>\n<h3>What if I downloaded the spreadsheet but never opened it?<\/h3>\n<p>Do not open it now. Report and handle the file through your security process; downloading alone does not establish that its content executed.<\/p>\n<h3>Can I trust the message because the address is real?<\/h3>\n<p>A real address can be copied. Verify the particular order and sender through established business records rather than treating signature details as authentication.<\/p>\n<h3>Should I request another copy from the same sender?<\/h3>\n<p>First confirm the transaction through an independently verified contact. Asking the unverified sender for another file may simply restart the same exposure.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The HUS Ltd order-confirmation scam hides a risky attachment inside an ordinary supplier workflow. A real company name cannot make an unexpected workbook trustworthy.<\/p>\n<p>Verify the transaction before handling the file, keep Office protections intact, and report any interaction accurately. Unknown payload details should prompt careful assessment, not invented certainty.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A purchase order arrives with a company signature and an Excel attachment. For someone handling suppliers or sales, it looks like another task awaiting review. The HUS Ltd order-confirmation email deserves a closer look before &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"HUS Ltd Order Confirmation Email Scam: Dangerous Excel Attachment Exposed\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/hus-ltd-order-confirmation-email-scam\/#more-425733\" aria-label=\"Read more about HUS Ltd Order Confirmation Email Scam: Dangerous Excel Attachment Exposed\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":425734,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-425733","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/425733","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=425733"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/425733\/revisions"}],"predecessor-version":[{"id":425735,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/425733\/revisions\/425735"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/425734"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=425733"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=425733"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=425733"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}