Google presentation open redirect phishing
Google services using g.co shortlinks
Image as content with a link to an open redirect
Impersonation: Chrome Web Store policy
Impersonation: Fake product discount promotion
Impersonation: Salesforce fake campaign failure notification
Impersonation: Suspected supplier impersonation with suspicious content
Inline image as message with attachment or link
Issuu document with suspicious embedded link
Link: 9WOLF phishkit initial landing URI
Link: Abused Adobe Express
Link abuse: Self-service creation platform link with suspicious recipient behavior
Link: Adobe share with suspicious indicators
Link: Apple App Store link to apps impersonating AI adveristing
Link: Apple App Store malicious ad manager themed apps from free email provider
Link: Apple TestFlight from suspicious sender
Link: Base64 encoded recipient address in URL fragment with hex subdomain
Link: Base64 encoded recipient address in URL fragment with subject hash
Link: BEC with newly registered domains and financial keywords
Link: Blogspot hosting explicit romance content
Link: Breely link masquerading as PDF
Link: chatbot.page platform abuse
Link: Common hidden directory observed
Link: Commonly Abused Web Service redirecting to ZIP file
Link: Compromised WordPress site redirecting to suspicious root domain
Link: Concatenated display text concealing duplicate URLs with PDF reference
Link: Credential phishing traversing Russian infrastructure
Link: Credential phishing via WordPress
Link: Credential phishing with obfuscated JavaScript redirect
Link: Credential theft with Cloudflare tunnel and recipient targeting
Link: Credential theft with invisible Unicode character in page title from unsolicited sender
Link: Cryptocurrency fraud with suspicious links
Link: CVE-2024-21413 Microsoft Outlook Remote Code Execution Vulnerability
Link: Delimited encoded path parameters (~V~ scheme)
Link: Direct download of executable file
Link: Direct link to Dropbox Paper file
Link: Direct link to gamma.app document with mode parameter
Link: Direct link to keap.app contact-us page
Link: Direct link to limewire hosted file
Link: Direct link to riddle.com hosted showcase
Link: Direct link to Zoom Docs from non-Zoom sender
Link: Direct MSI download from low reputation domain
Link: Direct POWR.io Form Builder with suspicious patterns
Link: Display text is 'unsb'
Link: Display text matches subject line
Link: Display text with excessive right-to-left mark characters
Link: Document-themed link to newly registered domain
Link: Double base64-encoded URL path
Link: Excessive URL rewrite encoders
Link: Executable file download with suspicious message content