Link: Google Cloud Storage with short-path link delivery
Link: Google Cloud Storage with suspicious URL pattern
Link: Jensi file preview link from unsolicited sender
Link: Multistage landing - Abused Adobe frame.io
Link: Multistage Landing - Abused Buildin.ai
Link: Multistage landing - Abused Docusign
Link: Multistage landing - Abused Google Drive
Link: Multistage landing - ClickUp abuse
Link: Multistage landing - Published Google Doc
Link: Multistage landing - Scribd document
Link: Multistage landing - Trello board abuse
Link: PDF and financial display text to free file host
Link: Personalized URL with recipient address on commonly abused web service
Link: Scribd fullscreen link from suspicious sender
Link: Secure SharePoint file share from new or unusual sender
Link: SharePoint OneNote or PDF link with self sender behavior
Link: Suspicious SharePoint document name
Link: Suspicious Sharepoint folder share
Link: Tax document lure Portuguese/Spanish with suspicious domains
Link: URL redirecting to blob URL
Link: Webflow link from unsolicited sender
Link: Zoho form link from unsolicited sender
Low reputation link to auto-downloaded HTML file with smuggling indicators
Mismatched links: Free file share with urgent language
Notion suspicious file share
Open redirect: JustPaste.it
Service abuse: Adobe Creative Cloud share from an unsolicited sender address
Service abuse: Behance document sharing with suspicious language
Service abuse: Citrix ShareFile impersonation via Outlook plugin
Service abuse: DocSend share from an unsolicited reply-to address
Service abuse: DocSend share from newly registered domain
Service abuse: DocuSign share from an unsolicited reply-to address
Service abuse: Dropbox Paper with copy-paste instructions
Service abuse: FileMail callback scam
Service abuse: FlipHTML5 with attachment deception and credential theft language
Service abuse: Formester with suspicious link behavior
Service abuse: GitHub notification with excessive mentions and suspicious links
Service abuse: Google account notification with links to free file host
Service abuse: Google application integration redirecting to suspicious hosts
Service abuse: Google Drive share from an unsolicited reply-to address
Service abuse: Google Drive share from new reply-to domain
Service abuse: Google OAuth with suspicious redirect destination
Service abuse: HelloSign from an unsolicited sender address
Service abuse: Linode Objects HTML file hosting
Service abuse: SendThisFile with credential theft and financial language
Service abuse: Square marketing with suspicious QR code
Service abuse: SurveyMonkey survey from newly registered domain
Service abuse: Suspicious Zoom Docs link
Spam: Campaign with excessive space/char obfuscation and free file hosted link