Impersonation: Suspected supplier impersonation with suspicious content
Inbound message from popular service via newly observed distribution list
Inline image as message with attachment or link
Issuu document with suspicious embedded link
Link: 9WOLF phishkit initial landing URI
Link: Abused Adobe Express
Link: Adobe share from unsolicited sender
Link: Adobe share with suspicious indicators
Link: Apple App Store malicious ad manager themed apps from free email provider
Link: Apple TestFlight from suspicious sender
Link: Base64 encoded recipient address in URL fragment with hex subdomain
Link: Base64 encoded recipient address in URL fragment with subject hash
Link: BEC with newly registered domains and financial keywords
Link: Common hidden directory observed
Link: Commonly Abused Web Service redirecting to ZIP file
Link: Compromised WordPress site redirecting to suspicious root domain
Link: Concatenated display text concealing duplicate URLs with PDF reference
Link: Credential harvesting with excess padding evasion
Link: Credential phishing link with undisclosed recipients
Link: Credential phishing with obfuscated JavaScript redirect
Link: Credential theft with Cloudflare tunnel and recipient targeting
Link: Credential theft with invisible Unicode character in page title from unsolicited sender
Link: Cryptocurrency fraud with suspicious links
Link: CVE-2024-21413 Microsoft Outlook Remote Code Execution Vulnerability
Link: Delimited encoded path parameters (~V~ scheme)
Link: Direct download of executable file
Link: Direct link to gamma.app document with mode parameter
Link: Direct link to keap.app contact-us page
Link: Direct MSI download from low reputation domain
Link: Display text matches subject line
Link: Display text with excessive right-to-left mark characters
Link: Document-themed link to newly registered domain
Link: Double base64-encoded URL path
Link: Excessive URL rewrite encoders
Link: Executable file download with suspicious message content
Link: Fake forwarded message with suspicious URL in plain text
Link: Fake secure message notification template
Link: Figma design deck with credential theft language
Link: File sharing pretext with suspicious body and link
Link: Flagged bit.ly link
Link: Free file hosting with undisclosed recipients
Link: Generic financial document with proceedural timeline template
Link: Gmail phishkit with suspicious recipient
Link: Google Cloud Storage hosted credential harvesting page
Link: Google Cloud Storage link with index.php in URL
Link: Google Cloud Storage link with redirect.html in URL
Link: Google Cloud Storage redirect to external domain
Link: Google Cloud Storage with short-path link delivery
Link: Google Cloud Storage with suspicious URL pattern
Link: Google Firebase dynamic link that redirects to new domain (<7 days old)