Link: Single character path with credential theft body and self sender behavior or invalid recipient
Link: Spam website with evasion indicators
Link: Squarespace infrastructure abuse
Link: .su domain link redirection from new sender domains
Link: Suspicious Family fragment parameter with encoded recipient data
Link: Suspicious file retrieval with recipient targeting
Link: Suspicious go.php redirect with document lure
Link: Suspicious Loom HTML file path
Link: Suspicious recipient with timeout redirect
Link: Suspicious Sharepoint folder share
Link: Suspicious single-domain link with suspicious path and financial lure indicators
Link: Suspicious URL path with binary character sequence
Link: Suspicious URL with recipient targeting and special characters
Link: Suspicious wp-admin path from mismatched sender domain
Link: SVG with embedded recipient data
Link: Tax document lure Portuguese/Spanish with suspicious domains
Link: Telegraph-hosted content
Link to a domain with punycode characters
Link to auto-downloaded disk image in encrypted zip
Link to auto-downloaded DMG in archive
Link to auto-downloaded DMG in encrypted zip
Link to auto-downloaded file with Adobe branding
Link to auto-downloaded file with Google Drive branding
Link to auto-download of a suspicious file type (unsolicited)
Link to Google Apps Script macro (unsolicited)
Link to Google Apps Script macro via comment tagging
Link: Tycoon2FA phishing kit (non-exhaustive)
Link: Uncommon SharePoint document type with sender's display name
Link: Unformatted template with literal placeholder in mailto link
Link: Unicode character obfuscation in display name with base64-encoded URL fragment
Link: Unsolicited email contains link leading to Tycoon URL structure
Link: Unsolicited email contains link to page containing Tycoon URI structure
Link: URL fragmented by hidden spans
Link: URL fragment with hexadecimal pattern obfuscation
Link: URL path containing /moni/index
Link: URL redirecting to blob URL
Link: URL scheme obfuscation via split HTML anchors
Link: URL shortener chaining to workers.dev redirect
Link: URL shortener with copy-paste instructions and credential theft language
Link: URL using underscore-dot substitution in display text
Link: Webflow link from unsolicited sender
Link: WordPress admin targeting with recipient identifier in URL parts
Link: WordPress login page with Blogspot Binance scam
Link: Zoho form link from unsolicited sender
Low reputation link to auto-downloaded HTML file with smuggling indicators
Malware: Pikabot delivery via URL auto-download
Microsoft device code phishing
Mismatched links: Free file share with urgent language
New link domain (<=10d) from untrusted sender