Link: Commonly Abused Web Service redirecting to ZIP file
Link: Concatenated display text concealing duplicate URLs with PDF reference
Link: Credential phishing traversing Russian infrastructure
Link: Credential phishing via WordPress
Link: Credential theft with Cloudflare tunnel and recipient targeting
Link: Credential theft with invisible Unicode character in page title from unsolicited sender
Link: Cryptocurrency fraud with suspicious links
Link: CVE-2024-21413 Microsoft Outlook Remote Code Execution Vulnerability
Link: Direct download of executable file
Link: Direct link to gamma.app document with mode parameter
Link: Direct link to keap.app contact-us page
Link: Direct link to limewire hosted file
Link: Direct link to riddle.com hosted showcase
Link: Direct link to Zoom Docs from non-Zoom sender
Link: Direct MSI download from low reputation domain
Link: Direct POWR.io Form Builder with suspicious patterns
Link: Display text matches subject line
Link: Display text with excessive right-to-left mark characters
Link: Excessive URL rewrite encoders
Link: Executable file download with suspicious message content
Link: Fake forwarded message with suspicious URL in plain text
Link: Fake secure message notification template
Link: Figma design deck with credential theft language
Link: File sharing impersonation with suspicious language and sending patterns
Link: File sharing pretext with suspicious body and link
Link: Financial account issue with suspicious indicators
Link: Flagged bit.ly link
Link: Flare-branded credential harvesting via Cloudflare tunnels
Link: Fraudulent state business filing notice
Link: Free file hosting with undisclosed recipients
Link: Free file host links from suspicious support sender with credential theft language
Link: Free file host link with 'Important Viewing Note' lure
Link: Free subdomain host with undisclosed recipients
Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender
Link: Google Cloud Storage hosted credential harvesting page
Link: Google Cloud Storage impersonating with googledrive in URL path
Link: Google Cloud Storage link with index.php in URL
Link: Google Cloud Storage link with redirect.html in URL
Link: Google Cloud Storage redirect to external domain
Link: Google Cloud Storage with short-path link delivery
Link: Google Cloud Storage with suspicious URL pattern
Link: Google Drawings link from new sender
Link: Google Firebase dynamic link that redirects to new domain (<7 days old)
Link: Google Forms link with credential theft language
Link: Google Translate (unsolicited)
Link: GoPhish query param values
Link: Hotel booking spoofed display URL
Link: HR impersonation with suspicious domain indicators and credential theft
Link: HTML file with suspicious binary fragment ending pattern
Link: /index.php enclosed in three asterisks