Adobe branded PDF file linking to a password-protected file from untrusted sender
Attachment: 7z Archive Containing RAR File
Attachment: Any HTML file within archive (unsolicited)
Attachment: Archive containing disallowed file type
Attachment: Archive containing HTML file with file scheme link
Attachment: Archive contains DLL-loading macro
Attachment: Archive with embedded CHM file
Attachment: Archive with embedded EXE file
Attachment: Archive with pdf, txt and wsf files
Attachment: Base64 encoded bash command in filename
Attachment: cmd file extension
Attachment: CVE-2021-40444 - MSHTML Remote Code Execution Vulnerability
Attachment: CVE-2025-24071 - Microsoft Windows File Explorer Spoofing Vulnerability
Attachment: DocX embedded binary
Attachment: DOCX with hyperlink targeting recipient address
Attachment: Double base64-encoded zip file in HTML smuggling attachment
Attachment: Embedded Javascript in SVG file
Attachment: Embedded VBScript in MHT file (unsolicited)
Attachment: EML with Encrypted ZIP
Attachment: EML with QR code redirecting to Cloudflare challenges
Attachment: Emotet heavily padded doc in zip file
Attachment: Encrypted Microsoft Office file (unsolicited)
Attachment: Encrypted ZIP containing VHDX file
Attachment: Encrypted zip file with payment-related lure
Attachment: Excel Web Query File (IQY)
Attachment: Fake Slack installer
Attachment: Fake Zoom installer
Attachment: File execution via Javascript
Attachment: Filename containing Unicode braille pattern blank character
Attachment: Filename containing Unicode right-to-left override character
Attachment: HTML attachment with Javascript location
Attachment: HTML attachment with login portal indicators
Attachment: HTML file contains exclusively Javascript
Attachment: HTML smuggling 'body onload' linking to suspicious destination
Attachment: HTML smuggling 'body onload' with high entropy and suspicious text
Attachment: HTML smuggling Microsoft sign in
Attachment: HTML smuggling with atob and high entropy
Attachment: HTML smuggling with auto-downloaded file
Attachment: HTML smuggling with base64 encoded JavaScript function
Attachment: HTML smuggling with base64 encoded ZIP file
Attachment: HTML smuggling with concatenation obfuscation
Attachment: HTML smuggling with decimal encoding
Attachment: HTML smuggling with embedded base64-encoded executable
Attachment: HTML smuggling with embedded base64-encoded ISO
Attachment: HTML smuggling with embedded base64 streamed file download
Attachment: HTML smuggling with eval and atob
Attachment: HTML smuggling with excessive line break obfuscation
Attachment: HTML smuggling with fromCharCode and other signals
Attachment: HTML smuggling with hex strings
Attachment: HTML smuggling with high entropy and other signals