Explanation
In this case, attackers pretend to be sending a remittance invoice document. By clicking on “VIEW DOC” in the email, the victim is lead to a page that shows a blurred image of a document in the background.
Clicking on “Open”, the phishing page that asks for the Microsoft credentials appears.
Example