Invoice/Shared-Doc Phishing Email Leading to Device Code Lure Page

This rule detects potential phishing emails themed around financial documents or shared files that contain URLs associated with device-code authorization phishing lures, such as ARToken PhaaS, or links hosted on workers.dev platforms commonly used for such activities.