Link: URL path containing /moni/index
Link: URL redirecting to blob URL
Link: URL scheme obfuscation via split HTML anchors
Link: URL shortener with copy-paste instructions and credential theft language
Link: WordPress admin targeting with recipient identifier in URL fragment
Low reputation link to auto-downloaded HTML file with smuggling indicators
macOS malware: Compiled AppleScript with document double-extension
MalwareBazaar: Malicious attachment hash in archive (trusted reporters)
Malware: Pikabot delivery via URL auto-download
Message traversed multiple onmicrosoft.com tenants
Microsoft infrastructure abuse with suspicious patterns
Non-RFC compliant calendar files from unsolicited sender
Notion suspicious file share
Observed IOC: Malicious domains in body links
Observed IOC: Malicious root domains in body links
Observed IOC: Malicious URLs in body links
Open redirect: Cartoon Network
Open redirect: giving.lluh.org
Open Redirect: Google domain with /url path and suspicious indicators
Open redirect: Mailtrack Korea
Open redirect: marketing.edinburghairport.com
Open redirect: people.anuneo.com
Open redirect: Shibboleth SSO Logout Return Parameter
Open redirect: slubnaglowie.pl
Open redirect: typedrawers.com
Open redirect: weblinkconnect.com
Open redirect: Xfinity CMP Redirection to Google AMP
Outlook hyperlink bypass: left-to-right mark (LRM) in base HTML tag
PhaaS: Impact Solutions (Impact Vector Suite)
Potential prompt injection attack in body HTML
QR code to auto-download of a suspicious file type (unsolicited)
Reconnaissance: Empty message from uncommon sender
Reconnaissance: Empty subject with mismatched reply-to from new sender
Request for Quote or Purchase (RFQ|RFP) with HTML smuggling attachment
Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern
Salesforce infrastructure abuse
Self-sender with copy/paste instructions and suspicious domains (French/Français)
Self-sent fake PDF attachment with misleading link
Sender: IP address in local part
Sendgrid onmicrosoft.com domain phishing
Service abuse: Adobe Creative Cloud share from an unsolicited sender address
Service abuse: AppSheet infrastructure with suspicious indicators
Service Abuse: Box file sharing with credential phishing intent
Service abuse: Cisco secure email service with financial request
Service abuse: DocSend share from an unsolicited reply-to address