Link: Document-themed link to newly registered domain
Link: Executable file download with suspicious message content
Link: Fake forwarded message with suspicious URL in plain text
Link: Fake RFP/bid reference number lure
Link: Fake secure message notification template
Link: Fake video link from newly registered domain
Link: Fake webmail hosting
Link: Figma design deck with credential theft language
Link: File sharing impersonation with suspicious language and sending patterns
Link: File sharing pretext with suspicious body and link
Link: Financial account issue with suspicious indicators
Link: Flare-branded credential harvesting via Cloudflare tunnels
Link: Fraudulent state business filing notice
Link: Free file host links from suspicious support sender with credential theft language
Link: Free file host link with 'Important Viewing Note' lure
Link: Generic financial document with proceedural timeline template
Link: Gmail phishkit with suspicious recipient
Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender
Link: Google Cloud Storage hosted credential harvesting page
Link: Google Cloud Storage redirect to external domain
Link: Google Cloud Storage with short-path link delivery
Link: Google Drawings link from new sender
Link: Google Forms link with credential theft language
Link: Hotel booking spoofed display URL
Link: HR impersonation with suspicious domain indicators and credential theft
Link: /index.php enclosed in three asterisks
Link: Intuit link abuse with file share context
Link: Invalid reply-to with recipient details in subject, body, and encoded link
Link: Invoice or receipt from freemail sender with customer service number
Link: Job recruitment lure from unsolicited sender with suspicious hosting
Link: Mamba 2FA phishing kit
Link: Microsoft device code authentication with suspicious indicators
Link: Microsoft impersonation using hosted png with suspicious link
Link: Microsoft protected message with suspicious recipient patterns
Link: Mismatched free file host links with document lure
Link: Mismatched Shopify template button href
Link: Multistage landing - Abused Adobe Acrobat hosted PDF
Link: Multistage Landing - Abused Buildin.ai
Link: Multistage landing - FreshDesk knowledge base abuse
Link: Multistage landing - JotForm abuse
Link: Multistage landing - Ludus presentation
Link: Multistage landing - Microsoft Forms abuse
Link: Multistage landing - Published Google Doc
Link: Multistage landing - Scribd document
Link: Multistage landing - Trello board abuse
Link: MyActiveCampaign Link Abuse
Link: Observed malicious URL path /redirect/redirect/
Link: .onion From Unsolicited Sender
Link: PDF and financial display text to free file host
Link: PDF filename impersonation with credential theft language