Abuse: Cloudflare Workers Hosted EvilTokens Domain Structure
Abuse: Robinhood injected content
Attachment: Adobe image lure in body or attachment with suspicious link
Attachment: Adobe Sign lure PDF with embedded banner images
Attachment: Any HTML file within archive (unsolicited)
Attachment: Archive containing HTML file with file scheme link
Attachment: Calendar file with invisible Unicode characters
Attachment: Calendar invite with Google redirect and invoice request
Attachment: Canva PDF with susupicious author metadata
Attachment: Compensation review lure with QR code
Attachment: Compensation-themed DOCX with QR code credential theft
Attachment: CVE-2025-24071 - Microsoft Windows File Explorer Spoofing Vulnerability
Attachment: Decoy PDF author (Julie P.)
Attachment: DocuSign impersonation via PDF linking to new domain
Attachment: DOCX with hyperlink targeting recipient address
Attachment: Double base64-encoded zip file in HTML smuggling attachment
Attachment: Dropbox image lure with no Dropbox domains in links
Attachment: EML containing a base64 encoded script
Attachment: EML file contains HTML attachment with login portal indicators
Attachment: EML file with HTML attachment (unsolicited)
Attachment: EML file with IPFS links
Attachment: EML with embedded Javascript in SVG file
Attachment: EML with link to credential phishing page
Attachment: EML with QR code redirecting to Cloudflare challenges
Attachment: EML with SharePoint files shared from GoDaddy federated tenants
Attachment: EML with Sharepoint link likely unrelated to sender
Attachment: EML with suspicious indicators
Attachment: Encrypted PDF With Credential Harvesting Indicators
Attachment: Encrypted PDF with credential theft body
Attachment: Excel file with document sharing lure created by Go Excelize
Attachment: Excel file with suspicious template identifier
Attachment: Excel Web Query File (IQY)
Attachment: Fake attachment image lure
Attachment: Fake PDF Invoices Yara
Attachment: Fake scan-to-email
Attachment: Fake secure message and suspicious indicators
Attachment: Fake voicemail via PDF
Attachment: Finance themed PDF with observed phishing template
Attachment: HTML attachment with Javascript location
Attachment: HTML attachment with login portal indicators
Attachment: HTML file contains exclusively Javascript
Attachment: HTML file with excessive 'const' declarations and abnormally long timeouts
Attachment: HTML file with excessive padding and suspicious patterns
Attachment: HTML file with reference to recipient and suspicious patterns
Attachment: HTML smuggling 'body onload' linking to suspicious destination
Attachment: HTML smuggling 'body onload' with high entropy and suspicious text
Attachment: HTML smuggling Microsoft sign in
Attachment: HTML smuggling - QR Code with suspicious links
Attachment: HTML smuggling with atob and high entropy