Abuse: Cloudflare Workers Hosted EvilTokens Domain Structure
Attachment: Adobe image lure in body or attachment with suspicious link
Attachment: Calendar invite with Google redirect and invoice request
Attachment: Calendar invite with suspicious link leading to an open redirect
Attachment: Callback phishing solicitation via image file
Attachment: DocuSign impersonation via PDF linking to new domain
Attachment: EML file with IPFS links
Attachment: EML with link to credential phishing page
Attachment: EML with QR code redirecting to Cloudflare challenges
Attachment: EML with SharePoint files shared from GoDaddy federated tenants
Attachment: EML with Sharepoint link likely unrelated to sender
Attachment: Fake Slack installer
Attachment: Fake voicemail via PDF
Attachment: Fake Zoom installer
Attachment: GZ archive with credential theft content
Attachment: Gzip-archived with nested HTML file containing image and button link
Attachment: HTML smuggling 'body onload' linking to suspicious destination
Attachment: HTML smuggling Microsoft sign in
Attachment: HTML smuggling - QR Code with suspicious links
Attachment: HTML smuggling with atob and high entropy
Attachment: HTML smuggling with auto-downloaded file
Attachment: ICS calendar file with base64 encoded recipient address in URL parameters
Attachment: ICS calendar file with QR code containing recipient email address
Attachment: ICS calendar invite with bid/RFP lure and suspicious link
Attachment: ICS calendar invite with financial lure and suspicious link
Attachment: ICS calendar invite with photo/file share lure
Attachment: ICS file with AWS Lambda URL
Attachment: ICS file with credential theft indicators
Attachment: ICS file with links to newly registered domains
Attachment: ICS invite meeting lure
Attachment: ICS Link With Valueless Base64 Query Parameter
Attachment: ICS voicemail lure with suspicious link
Attachment: Legal themed message or PDF with suspicious indicators
Attachment: Link to Doubleclick.net open redirect
Attachment: Microsoft OAuth credential harvesting via EML with embedded malicious links
Attachment: Office document loads remote document template
Attachment: Office document with VSTO add-in
Attachment: Office file contains OLE relationship to credential phishing page
Attachment: Office file with credential phishing URLs
Attachment: PDF Attachment with links to workers.dev
Attachment: PDF bid/proposal lure with credential theft indicators
Attachment: PDF credential phishing via wkhtmltopdf/Qt with suspicious link
Attachment: PDF file with link to fake Bitcoin exchange
Attachment: PDF file with low reputation link to ZIP file (unsolicited)
Attachment: PDF Grant Payment lure with embedded link
Attachment: PDF proposal with credential theft indicators
Attachment: PDF with a suspicious string and single URL
Attachment: PDF with credential theft language and link to a free subdomain (unsolicited)
Attachment: PDF with dub.sh shortened link
Attachment: PDF with link to DMG file download