Attachment: EML with link to credential phishing page
Attachment: HTML smuggling - QR Code with suspicious links
Attachment: PDF with suspicious link and action-oriented language
Attachment: QR code with credential phishing indicators
Brand impersonation: DocuSign branded attachment lure with no DocuSign links
Brand impersonation: Figma with malicious document access overlay
Credential phishing content and link (untrusted sender)
Credential phishing link (unknown sender)
Free subdomain link with credential theft indicators
Free subdomain link with login or captcha (untrusted sender)
Google Accelerated Mobile Pages (AMP) abuse
Google Drive abuse: Credential phishing link
Issuu document with suspicious embedded link
Link: Adobe share with suspicious indicators
Link: chatbot.page platform abuse
Link: Credential harvesting with excess padding evasion
Link: Credential phishing link with undisclosed recipients
Link: Credential theft with invisible Unicode character in page title from unsolicited sender
Link: Cryptocurrency fraud with suspicious links
Link: Figma design deck with credential theft language
Link: HR impersonation with suspicious domain indicators and credential theft
Link: Microsoft device code authentication with suspicious indicators
Link: Microsoft Dynamics 365 form phishing
Link: Multistage landing - FreshDesk knowledge base abuse
Link: Multistage landing - Ludus presentation
Link: Multistage landing - Scribd document
Link: Multistage landing - Trello board abuse
Link: Spam website with evasion indicators
Link to auto-downloaded file with Adobe branding
Link to auto-downloaded file with Google Drive branding
Link: Unsolicited email contains link to page containing Tycoon URI structure
Service abuse: Formester with suspicious link behavior
Suspicious recipient pattern and language with low reputation link to login
Suspicious recipients pattern with no Compauth pass and suspicious content