Attachment: WinRAR CVE-2025-8088 exploitation
Attachment with auto-executing macro (unsolicited)
Attachment with auto-opening VBA macro (unsolicited)
Attachment with encrypted zip (unsolicited)
Attachment with high risk VBA macro (unsolicited)
Attachment with macro calling executable
Attachment with suspicious author (unsolicited)
Attachment with unscannable encrypted zip
Attachment with VBA macros from employee impersonation (unsolicited)
Attachment: XLSX file with suspicious print titles metadata
Attachment: ZIP file with CVE-2026-0866 exploit
BEC/Fraud: Job scam fake thread or plaintext pivot to freemail
Brand impersonation: Adobe Acrobat Sign PDF phishing file format template
Brand impersonation: Amazon with suspicious attachment
Brand impersonation: Chase bank with credential phishing indicators
Brand impersonation: Coinbase with suspicious links
Brand impersonation: DocuSign PDF attachment with suspicious link
Brand impersonation: Dropbox
Brand impersonation: Google fake sign-in warning
Brand impersonation: Microsoft fake sign-in alert
Brand impersonation: Microsoft quarantine release notification in body
Brand impersonation: Microsoft quarantine release notification in image attachment
Brand impersonation: Microsoft Teams
Brand impersonation: Microsoft with low reputation links
Brand impersonation: Norton
Brand Impersonation: PayPal
Brand impersonation: Proofpoint secure messaging without legitimate indicators
Brand impersonation: Sharepoint
Brand impersonation: SharePoint PDF attachment with credential theft language
Business Email Compromise (BEC) attempt from unsolicited sender
Callback phishing: AOL senders with suspicious HTML template or PDF attachment
Callback phishing in body or attachment (untrusted sender)
Callback phishing: Social Security Administration fraud
Callback phishing solicitation in message body
Callback phishing via calendar invite
Callback phishing via extensionless rfc822 attachment
Callback phishing via Google Group abuse
Commonly abused sender TLD with engaging language
Credential phishing: Image as content, short or no body contents
Encrypted Microsoft Office files from untrusted sender
Extortion / sextortion in attachment from untrusted sender
Extortion / Sextortion - PDF attachment leveraging breach data from freemail sender
Free subdomain link with login or captcha (untrusted sender)
HTML smuggling containing recipient email address
Impersonation: Fake Gmail attachment
Impersonation: Recipient organization in sender display name with credential theft image
Link: Direct POWR.io Form Builder with suspicious patterns
Link: Microsoft Dynamics 365 form phishing
Link: Microsoft protected message with matching sender and recipient addresses
Link: QR code in EML attachment with credential phishing indicators