Based on analysis performed by the PDC, it was determined that each link, while still going to the same base domain, uses specific parameters to determine which web page pull, then overlays the fake login panel on top. Depending on what company the threat actor is targeting, the link will populate the address of the original recipient of the email. This campaign shows that threat actors can and will use any resource available to compromise business accounts. Cofense PhishMeTM offers a simulation template named Email Quarantine Report Alternate.”]
Source: https://cofense.com/message-quarantine-campaign-overlying-potential/