Link: Direct link to gamma.app document with mode parameter
Link: Direct link to keap.app contact-us page
Link: Direct MSI download from low reputation domain
Link: Display text matches subject line
Link: Display text with excessive right-to-left mark characters
Link: Excessive URL rewrite encoders
Link: Executable file download with suspicious message content
Link: Fake forwarded message with suspicious URL in plain text
Link: Fake secure message notification template
Link: Figma design deck with credential theft language
Link: File sharing pretext with suspicious body and link
Link: Flagged bit.ly link
Link: Free file hosting with undisclosed recipients
Link: Generic financial document with proceedural timeline template
Link: Google Cloud Storage hosted credential harvesting page
Link: Google Cloud Storage link with index.php in URL
Link: Google Cloud Storage link with redirect.html in URL
Link: Google Cloud Storage redirect to external domain
Link: Google Cloud Storage with short-path link delivery
Link: Google Cloud Storage with suspicious URL pattern
Link: Google Firebase dynamic link that redirects to new domain (<7 days old)
Link: GoPhish query param values
Link: Hotel booking spoofed display URL
Link: HTML file with suspicious binary fragment ending pattern
Link: Invalid reply-to with recipient details in subject, body, and encoded link
Link: IPv4-mapped IPv6 address obfuscation
Link: JavaScript obfuscation with Telegram bot integration
Link: Landing page with search-ms protocol redirect
Link: Mamba 2FA phishing kit
Link: Microsoft device code authentication with suspicious indicators
Link: Microsoft Dynamics 365 form phishing
Link: Microsoft protected message with matching sender and recipient addresses
Link: Mixed case HTTPS protocol
Link: Multiple HTTP protocols in single URL
Link: Multistage landing - Abused Adobe frame.io
Link: Multistage landing - Abused Docusign
Link: Multistage landing - Abused Google Drive
Link: Multistage landing - ClickUp abuse
Link: Multistage landing - JotForm abuse
Link: Multistage landing - Ludus presentation
Link: Multistage landing - Scribd document
Link: Non-standard port 8443 in display URL
Link: Numeric IP obfuscation in URL
Link: Obfuscation via userinfo with excessive URL padding
Link: Obfuscation via userinfo with suspicious indicators
Link: .onion From Unsolicited Sender
Link: PDF display text with fake copyright claim template
Link: PDF file disguised as HTML page
Link: PDF filename impersonation with credential theft language
Link: QR code in EML attachment with credential phishing indicators