Attachment: Calendar invite with suspicious link leading to an open redirect
Attachment: EML file with IPFS links
Attachment: EML with link to credential phishing page
Attachment: Fake scan-to-email
Attachment: ICS file with AWS Lambda URL
Attachment: PDF bid/proposal lure with credential theft indicators
Attachment: PDF with multistage landing - ClickUp abuse
Attachment: PDF with self-service platform links with self sender or blank recipients
Attachment: Romance scam with image lure and advance-fee or suspicious link indicators
Attachment: Single-page PDF with S3-hosted HTML link
Brand impersonation: Fake Fax
Brand impersonation: Microsoft quarantine release notification in image attachment
Brand impersonation: Microsoft with low reputation links
Canva design with suspicious embedded link
Catbox.moe link from untrusted source
Cloud storage impersonation with credential theft indicators
Credential phishing: Engaging language with IPFS link
Credential phishing: Hyper-linked image leading to free file host
Deceptive Dropbox mention
DocuSign impersonation via CloudHQ links
Fake scan-to-email message
Fake shipping notification with link to free file hosting
File sharing link from suspicious sender domain
File sharing link with a suspicious subject
Google Drive abuse: Credential phishing link
Google Drive direct download link from unsolicited sender
Google share notification with suspicious comments
Impersonation: Fake product discount promotion
Invoicera infrastructure abuse
Issuu document with suspicious embedded link
Link: Abused Adobe Express
Link: Adobe share from unsolicited sender
Link: Adobe share with suspicious indicators
Link: Commonly Abused Web Service redirecting to ZIP file
Link: Direct link to gamma.app document with mode parameter
Link: Direct link to keap.app contact-us page
Link: Direct link to limewire hosted file
Link: Direct link to riddle.com hosted showcase
Link: Document sharing invitation template
Link: Figma design deck with credential theft language
Link: Financial account issue with suspicious indicators
Link: Free file hosting with undisclosed recipients
Link: Free file host links from suspicious support sender with credential theft language
Link: Free file host link with 'Important Viewing Note' lure
Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender
Link: Google Cloud Storage hosted credential harvesting page
Link: Google Cloud Storage impersonating with googledrive in URL path
Link: Google Cloud Storage link with index.php in URL
Link: Google Cloud Storage link with redirect.html in URL
Link: Google Cloud Storage redirect to external domain