Link: QuickBooks image lure with suspicious link
Link: ScreenConnect installer with suspicious relay domain
Link to auto-downloaded disk image in encrypted zip
Link to auto-downloaded DMG in archive
Link to auto-downloaded DMG in encrypted zip
Link to auto-downloaded file with Adobe branding
Link to auto-downloaded file with Google Drive branding
Link to auto-download of a suspicious file type (unsolicited)
Low reputation link to auto-downloaded HTML file with smuggling indicators
macOS malware: Compiled AppleScript with document double-extension
MalwareBazaar: Malicious attachment hash in archive (trusted reporters)
MalwareBazaar: Malicious attachment hash (trusted reporters)
Malware: Pikabot delivery via URL auto-download
Non-RFC compliant calendar files from unsolicited sender
Open Redirect: Google domain with /url path and suspicious indicators
Open redirect: Hakumonkai.org
Open redirect: typedrawers.com
PDF attachment with Google (AE) redirecting to a php or zip file
QR code to auto-download of a suspicious file type (unsolicited)
Request for Quote or Purchase (RFQ|RFP) with HTML smuggling attachment
Service abuse: Citrix ShareFile impersonation via Outlook plugin
Service abuse: Monday.com infrastructure with phishing intent
Spam: Unsolicited malformed PDF
Suspicious attachment: Duplicate decoy PDF files
Suspicious attachment with unscannable Cloudflare link
Suspicious invoice reference with missing or image-only attachments
Suspicious VBA macros from untrusted sender
URI protocol handler: search-ms
URLhaus: Malicious domain in message body or pdf attachment (trusted reporters)
X (Twitter) impersonation with credential phishing motives