Observed IOC: Malicious domains in body links
Observed IOC: Malicious reply-to domains
Observed IOC: Malicious reply-to email addresses
Observed IOC: Malicious reply-to root domains
Observed IOC: Malicious root domains in body links
Observed IOC: Malicious sender domains
Observed IOC: Malicious sender email addresses
Observed IOC: Malicious sender root domains
Observed IOC: Malicious URLs in body links
Open redirect: City of Calgary
Open redirect: giving.lluh.org
Open redirect: marketing.edinburghairport.com
Open redirect: people.anuneo.com
Open redirect: queue.swytchbike.com
Open redirect: Recipient address embedded in redirect URL pointing to newly registered domain
Open redirect: slubnaglowie.pl
Open redirect: typedrawers.com
Potential prompt injection attack in body HTML
QR code to auto-download of a suspicious file type (unsolicited)
QR Code with suspicious indicators
Reconnaissance: Email address harvesting attempt
Reconnaissance: Empty message from uncommon sender
Reconnaissance: Empty subject with mismatched reply-to from new sender
Reconnaissance: Fake real estate inquiry with empty body
Reconnaissance: Hotel booking reply-to redirect
Reconnaissance: Short generic greeting message
Recruitee Infrastructure Abuse
Salesforce infrastructure abuse
Scam: Fake estate sale offering welding equipment and tools
Scam soliciting employer review/rating
Self-impersonation: Sender matches recipient with bolded name and suspicious link
Self-sender with copy/paste instructions and suspicious domains (French/Français)
Self-sent fake PDF attachment with misleading link
Service abuse: Adobe Creative Cloud share from an unsolicited sender address
Service abuse: Adobe legitimate domain with document approval language
Service abuse: Adobe Sign notification from an unsolicited reply-to address
Service abuse: Amazon invitation with suspected callback phishing
Service abuse: Apple TestFlight with suspicious developer reference
Service abuse: AppSheet infrastructure with suspicious indicators
Service abuse: AWS SNS callback scam impersonation
Service abuse: Behance document sharing with suspicious language
Service Abuse: Box file sharing with credential phishing intent
Service abuse: Calendly callback scam detection
Service abuse: Callback phishing via Microsoft Teams invite
Service abuse: Cisco secure email service with financial request