Recently I’ve seen a number of good looking malicious emails pretending to be from various orgs, all with included company logos.
Looking over the HTML of the emails I noticed an image URL common to all of them, logo.clearbit[.]com. It was in the image tag for logo.
It’s a company logo API that uses logo.clearbit[.]com/“domain.whatever” for logo creation.
Might be a domain you want to start filtering for, as the API is clearly being abused thanks to it being absolutely free.