Link: Microsoft protected message with matching sender and recipient addresses
Link: Multistage landing - Abused Adobe Acrobat hosted PDF
Link: Multistage landing - Ludus presentation
Link: .onion From Unsolicited Sender
Link: PDF filename impersonation with credential theft language
Link: Personalized URL with recipient address on commonly abused web service
Link: Personal SharePoint with invalid recipients and credential theft language
Link: Recipient domain in URL path
Link: Referrer anonymization service from untrusted sender
Link: Romance/Sexual Language With Suspicious Link
Link: Self-sender credential theft with configuration placeholder
Link: Self-sender with sender org in subject and credential theft indicator
Link: Self-sent message with quarterly document review request
Link: Self-sent PDF lure with subject correlation
Link: SharePoint OneNote or PDF link with self sender behavior
Link: Shortened URL with fragment matching subject
Link: Single character path with credential theft body and self sender behavior or invalid recipient
Link: Squarespace infrastructure abuse
Link: Suspicious Sharepoint folder share
Link: Suspicious wp-admin path from mismatched sender domain
Link: Uncommon SharePoint document type with sender's display name
macOS malware: Compiled AppleScript with document double-extension
Mass campaign: Cross Site Scripting (XSS) attempt
Mass campaign: recipient address in subject, body, and link (untrusted sender)
Message traversed multiple onmicrosoft.com tenants
Microsoft infrastructure abuse with suspicious patterns
Newly registered sender or reply-to domain with newly registered linked domain
Observed IOC: Malicious reply-to domains
Observed IOC: Malicious reply-to email addresses
Observed IOC: Malicious reply-to root domains
Observed IOC: Malicious sender domains
Observed IOC: Malicious sender email addresses
Observed IOC: Malicious sender root domains
Open redirect: giving.lluh.org
Open redirect (go2.aspx) leading to Microsoft credential phishing
Open Redirect: Google domain with /url path and suspicious indicators
Open redirect: marketing.edinburghairport.com
Open redirect: people.anuneo.com
Open redirect: queue.swytchbike.com
Open redirect: slubnaglowie.pl
Open redirect: Xfinity CMP Redirection to Google AMP
PHP Mailer with common phishing attachments
Potential prompt injection attack in body HTML
QR Code with suspicious indicators
Reconnaissance: All recipients cc/bcc'd or undisclosed
Reconnaissance: Email address harvesting attempt
Reconnaissance: Empty message from uncommon sender
Reconnaissance: Empty subject with mismatched reply-to from new sender