Attachment: HTML smuggling with embedded base64-encoded ISO
Attachment: HTML smuggling with embedded base64 streamed file download
Attachment: HTML smuggling with eval and atob
Attachment: HTML smuggling with excessive line break obfuscation
Attachment: HTML smuggling with fromCharCode and other signals
Attachment: HTML smuggling with hex strings
Attachment: HTML smuggling with high entropy and other signals
Attachment: HTML smuggling with raw array buffer
Attachment: HTML smuggling with RC4 decryption
Attachment: HTML smuggling with ROT13
Attachment: HTML smuggling with setTimeout
Attachment: HTML with hidden body
Attachment: HTML with JavaScript functions for HTTP requests
Attachment: ICS calendar file with base64 encoded recipient address in URL parameters
Attachment: ICS calendar file with QR code containing recipient email address
Attachment: ICS calendar file with recipient address in UID field
Attachment: ICS calendar file with suspicious product identifier
Attachment: ICS calendar file with suspicious UID domain
Attachment: ICS file with AWS Lambda URL
Attachment: ICS file with excessive custom properties
Attachment: ICS file with non-Gregorian calendar scale
Attachment: ICS with employee policy review lure
Attachment: Invoice and W-9 PDFs with suspicious creators
Attachment: Legal themed message or PDF with suspicious indicators
Attachment: Link to Doubleclick.net open redirect
Attachment: LNK with embedded content
Attachment: Macro with suspected use of COM ShellBrowserWindow object for process creation
Attachment: Malicious OneNote commands
Attachment: Malicious zip file matching zipline campaign
Attachment: Microsoft 365 credential phishing
Attachment: Microsoft OAuth credential harvesting via EML with embedded malicious links
Attachment: Office document with VSTO add-in
Attachment: Office file with credential phishing URLs
Attachment: Office file with document sharing and browser instruction lures
Attachment: OLE external relationship containing file scheme link to executable filetype
Attachment: OLE external relationship containing file scheme link to IP address
Attachment: PDF bid/proposal lure with credential theft indicators
Attachment: PDF file with recipient domain and ATT eCheckRun pattern
Attachment: PDF with a suspicious string and single URL
Attachment: PDF with credential theft language and invalid reply-to domain
Attachment: PDF with fake invoice using suspicious font sizing
Attachment: PDF with link to DMG file download
Attachment: PDF with link to zip containing a wsf file
Attachment: PDF with Microsoft Purview message impersonation
Attachment: PDF with password in filename matching body text
Attachment: PDF with personal Microsoft OneNote URL
Attachment: PDF with QR code containing recipient-specific credential theft content
Attachment: PDF with secure document acknowledgment prompt
Attachment: PDF with suspicious document view lure
Attachment: PDF with suspicious internal object reference identifier