Link: Scribd fullscreen link from suspicious sender
Link: Secure SharePoint file share from new or unusual sender
Link: SharePoint OneNote or PDF link with self sender behavior
Link: Suspicious SharePoint document name
Link: Suspicious Sharepoint folder share
Link: Tax document lure Portuguese/Spanish with suspicious domains
Link: URL redirecting to blob URL
Link: Webflow link from unsolicited sender
Link: Zoho form link from unsolicited sender
Low reputation link to auto-downloaded HTML file with smuggling indicators
Mismatched links: Free file share with urgent language
Notion suspicious file share
Service abuse: Adobe Creative Cloud share from an unsolicited sender address
Service abuse: Behance document sharing with suspicious language
Service abuse: DocSend share from an unsolicited reply-to address
Service abuse: DocSend share from newly registered domain
Service abuse: DocuSign share from an unsolicited reply-to address
Service abuse: FlipHTML5 with attachment deception and credential theft language
Service abuse: Formester with suspicious link behavior
Service abuse: GitHub notification with excessive mentions and suspicious links
Service abuse: Google account notification with links to free file host
Service abuse: Google application integration redirecting to suspicious hosts
Service abuse: Google Drive share from an unsolicited reply-to address
Service abuse: Google Drive share from new reply-to domain
Service abuse: Google OAuth with suspicious redirect destination
Service abuse: HelloSign from an unsolicited sender address
Service abuse: SendThisFile with credential theft and financial language
Service abuse: SurveyMonkey survey from newly registered domain
Service abuse: Suspicious Zoom Docs link
Spam: Campaign with excessive space/char obfuscation and free file hosted link
Spoofable internal domain with suspicious signals
Suspicious DocuSign share from new domain
Suspicious Links to Cloudflare R2 and Edge Services
Suspicious SharePoint file sharing
Zoom Events newsletter abuse