Link: Self-sent PDF lure with subject correlation
Link: Suspicious Loom HTML file path
Link: Suspicious Sharepoint folder share
Link: Suspicious single-domain link with suspicious path and financial lure indicators
Link: Tycoon2FA phishing kit (non-exhaustive)
Link: Uncommon SharePoint document type with sender's display name
Link: URL scheme obfuscation via split HTML anchors
Low reputation link to auto-downloaded HTML file with smuggling indicators
Open redirect: Shibboleth SSO Logout Return Parameter
Outlook hyperlink bypass: left-to-right mark (LRM) in base HTML tag
Potential prompt injection attack in body HTML
Request for Quote or Purchase (RFQ|RFP) with HTML smuggling attachment
Self-impersonation: Sender matches recipient with bolded name and suspicious link
Service abuse: Adobe Creative Cloud share from an unsolicited sender address
Service abuse: Amazon invitation with suspected callback phishing
Service abuse: Apple TestFlight with suspicious developer reference
Service abuse: Google Firebase sender address with suspicious content
Service abuse: HelloSign from an unsolicited sender address
Service abuse: HungerRush domain with SendGrid tracking targeting ProtonMail
Service abuse: Meetup.com redirect with brand impersonation
Service abuse: Oracle Cloud Workflow callback scam
Service abuse: Substack credential theft with confusable characters and branded button redirects
Service abuse: SurveyMonkey with suspicious outbound links
Service abuse: Suspicious Zoom Docs link
Service abuse: Trello board invitation with VIP impersonation
Sharepoint link likely unrelated to sender
Spam: Commonly observed formatting of unauthorized free giveaways
Spam: Item giveaway spam template
URI protocol handler: search-ms
Venmo payment request abuse
VIP impersonation: VIP recipient of previous thread with HTML generator
Zoom Events newsletter abuse