forumNew topic

I was about to download a PDF from a job application, then we got scared thinking it might be malware

AAli Ö***Member
Job title
Accounting clerk
Sector
Plastic
Organization type
20-person company
Joined
Nov 2023
Message
42

Doki · Mobile app · 2023

#1

One of the job applications that came to the HR team looked very professional. The file is uploading, I was about to download the attached PDF but someone said 'this could be fake malware'. Now we're scared.

This is the first time someone said something like this since we started receiving job applications. Could it really be malware? How can I tell?

Which applications will we accept from now on, and which ones won't we take?

MMehmet B***Member
Job title
Customer service representative
Sector
Construction
Organization type
120-person company
Joined
Nov 2023
Message
7

Doki · Vulnerability scanning · 2023

Most Helpful#2

Job applications are a common attack vector. Attachments (especially with exe, bat, scr extensions) can contain malware. PDF files also carry risk because some PDF readers might be vulnerable.

Protocol: Don't open attachments from unknown sources directly. Scan them with an antivirus program or use an online scanning site (like virustotal.com).

Train the HR team: Only accept expected application formats. Verify the sender's info before opening the file.

UUğur V***MemberCommunity member
Joined
Aug 2023
Message
282
#3

we got scared too in the same way... anyway then we scanned it with antivirus it came out clean but still deleted the mail. wish we hadn't made a mistake in terms of ethics

TTarkanMember
Job title
Retail manager
Joined
Mar 2024
Message
104
#4

Steps: 1. Upload the file to VirusTotal.com 2. Wait for the scan to complete 3. If the result is clean, open it; if not, delete and report 4. HR: Ban opening files alone

HHakan G***Member
Job title
Purchasing manager
Sector
Seafood
Organization type
300-person organization
Joined
Oct 2024
Message
185
#5

virustotal is very useful bro we always check there. we taught the employees too, no probles arise

FFatma Ç***New memberCommunity member
Joined
May 2026
Message
1
#6

Malware distribution method: Job application, PDF, Word doc ZIP archive. Because people open these files quickly. High risk.

NNazlı T***Member
Job title
Social media manager
Sector
Packaging
Organization type
medium-sized business
Joined
Nov 2023
Message
58
#7

So if VirusTotal is used, is that site reliable too? Aren't the files stored?

AAli T***Member
Job title
Board member
Sector
Chemistry
Organization type
8-person team
Joined
Jun 2025
Message
334
#8

you guys escaped by that much bro.. and i mean you really acted fast. its great that you were suspicious!

ÖÖzge A***Member
Job title
Studio Founder
Sector
Consulting
Organization type
regional distributor
Joined
Aug 2024
Message
1
#9

Same here.

EEfe A***Member
Job title
IT manager
Sector
Livestock
Organization type
early-stage startup
Joined
Apr 2024
Message
2
#10

I didn't know that. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

Correct me if I'm wrong.

SSena Ç***Member
Job title
General Manager
Sector
Education
Organization type
family business
Joined
Jun 2025
Message
257
#11

I have an objection here. When making a decision, first look at what data you have on hand.

Most incidents start with a leaked password, not a vulnerability. Of course, it varies if your situation is different.

SSelim K***Member
Job title
Sales Manager
Sector
Media and publishing
Organization type
120-person company
Joined
Mar 2025
Message
305

Doki · SEO consulting · 2024

#12

The discussion got scattered let me summarize. Mistakes made on the file in fake job application attachment side are usually reversible but expensive.

Hope this helps.

EElif P***New member
Job title
Quality control inspector
Sector
Energy
Organization type
a company within a holding
Joined
Jul 2026
Message
130
#13

I completely agree. Having backups accessible on the same network and with the same identity makes them part of the target.

If I were you, I'd go this route.

OOkan T***VeteranCommunity member
Joined
Jan 2023
Message
7
#14

You're right. Having backups accessible on the same network and with the same identity makes them part of the target.

Good luck with that.

FFatma N***Member
Job title
Data Engineer
Organization type
sole proprietorship
Joined
Apr 2024
Message
142
#15

I agree with this. Processes without records never improve, because you don't know what to fix.

I'm also curious if anyone does it differently.

BBora A***Member
Job title
Production planning
Sector
E-commerce
Organization type
a company within a holding
Joined
Oct 2024
Message
65
#16

If I understood correctly, you're saying: Everything goes well for the first three months; problems arise in the fourth.

Hope this helps.

HHilal B***Veteran
Job title
Graphic Designer
Sector
Electrical-electronics
Organization type
regional distributor
Joined
Dec 2023
Message
17
#17

You're right. Taking notes for two weeks yields better results than a six-month estimate.

Solutions that work at a small scale collapse when you grow; I learned this late. Correct me if I'm wrong.

ZZehra G***Member
Job title
Operations director
Sector
Catering
Organization type
boutique agency
Joined
Feb 2024
Message
162
#18

theres a part I dont understand but honestly most incidents start with a leaked password, not a vulnerability.

of course, it varies if your situation is different.

LLevent K***MemberCommunity member
Joined
Jul 2024
Message
2
#19

id say dont rush. if you scold false alarms nobody will report again.

correct me if Im wrong.

EEmre K***Expert
Job title
Quality control inspector
Sector
Real estate
Organization type
sole proprietorship
Joined
Apr 2023
Message
39
#20

There's also a measurement aspect to this. If you get three different answers on a topic, the question was asked wrong.

Just leaving this note, it might be useful.

Reply