Link: Google Cloud Storage hosted credential harvesting page
Link: Google Cloud Storage impersonating with googledrive in URL path
Link: Google Cloud Storage link with index.php in URL
Link: Google Cloud Storage link with redirect.html in URL
Link: Google Cloud Storage redirect to external domain
Link: Google Cloud Storage with short-path link delivery
Link: Google Cloud Storage with suspicious URL pattern
Link: Jensi file preview link from unsolicited sender
Link: Mismatched free file host links with document lure
Link: Multistage landing - Abused Adobe frame.io
Link: Multistage Landing - Abused Buildin.ai
Link: Multistage landing - Abused Docusign
Link: Multistage landing - Abused Google Drive
Link: Multistage landing - ClickUp abuse
Link: Multistage landing - Published Google Doc
Link: Multistage landing - Scribd document
Link: Multistage landing - Trello board abuse
Link: PDF and financial display text to free file host
Link: Personalized URL with recipient address on commonly abused web service
Link: Scribd fullscreen link from suspicious sender
Link: Secure SharePoint file share from new or unusual sender
Link: SharePoint OneNote or PDF link with self sender behavior
Link: Suspicious SharePoint document name
Link: Suspicious Sharepoint folder share
Link: Tax document lure Portuguese/Spanish with suspicious domains
Link: Telegraph-hosted content
Link: URL redirecting to blob URL
Link: Webflow link from unsolicited sender
Link: Zoho form link from unsolicited sender
Low reputation link to auto-downloaded HTML file with smuggling indicators
Mismatched links: Free file share with urgent language
Notion suspicious file share
Open redirect: JustPaste.it
Service abuse: Adobe Creative Cloud share from an unsolicited sender address
Service abuse: Behance document sharing with suspicious language
Service abuse: Citrix ShareFile impersonation via Outlook plugin
Service abuse: DocSend share from an unsolicited reply-to address
Service abuse: DocSend share from newly registered domain
Service abuse: DocuSign share from an unsolicited reply-to address
Service abuse: Dropbox Paper with copy-paste instructions
Service abuse: FileMail callback scam
Service abuse: FlipHTML5 with attachment deception and credential theft language
Service abuse: Formester with suspicious link behavior
Service abuse: GitHub notification with excessive mentions and suspicious links
Service abuse: Google account notification with links to free file host
Service abuse: Google application integration redirecting to suspicious hosts
Service abuse: Google Drive share from an unsolicited reply-to address
Service abuse: Google Drive share from new reply-to domain
Service abuse: Google OAuth with suspicious redirect destination