Attachment: HTML smuggling with decimal encoding
Attachment: HTML smuggling with embedded base64-encoded ISO
Attachment: HTML smuggling with embedded base64 streamed file download
Attachment: HTML smuggling with eval and atob
Attachment: HTML smuggling with excessive line break obfuscation
Attachment: HTML smuggling with fromCharCode and other signals
Attachment: HTML smuggling with hex strings
Attachment: HTML smuggling with high entropy and other signals
Attachment: HTML smuggling with raw array buffer
Attachment: HTML smuggling with RC4 decryption
Attachment: HTML smuggling with ROT13
Attachment: HTML smuggling with setTimeout
Attachment: HTML with hidden body
Attachment: HTML with JavaScript functions for HTTP requests
Attachment: ICS calendar file with base64 encoded recipient address in URL parameters
Attachment: ICS calendar file with QR code containing recipient email address
Attachment: ICS calendar file with recipient address in UID field
Attachment: ICS calendar file with suspicious product identifier
Attachment: ICS calendar file with suspicious UID domain
Attachment: ICS calendar invite with bid/RFP lure and suspicious link
Attachment: ICS calendar invite with financial lure and suspicious link
Attachment: ICS calendar invite with photo/file share lure
Attachment: ICS file with AWS Lambda URL
Attachment: ICS file with excessive custom properties
Attachment: ICS file with non-Gregorian calendar scale
Attachment: ICS invite meeting lure
Attachment: ICS voicemail lure with suspicious link
Attachment: ICS with employee policy review lure
Attachment: Identity Confirmation With Document Unlock Code
Attachment: Image-only docx/pptx callback phishing
Attachment: Invoice and W-9 PDFs with suspicious creators
Attachment: Legal themed message or PDF with suspicious indicators
Attachment: Link to Doubleclick.net open redirect
Attachment: LNK with embedded content
Attachment: Macro with suspected use of COM ShellBrowserWindow object for process creation
Attachment: Malicious OneNote commands
Attachment: Malicious zip file matching zipline campaign
Attachment: Microsoft 365 credential phishing
Attachment: Microsoft OAuth credential harvesting via EML with embedded malicious links
Attachment: Office document with VSTO add-in
Attachment: Office file with credential phishing URLs
Attachment: Office file with document sharing and browser instruction lures
Attachment: OLE external relationship containing file scheme link to executable filetype
Attachment: OLE external relationship containing file scheme link to IP address
Attachment: PDF bid/proposal lure with credential theft indicators
Attachment: PDF file with recipient domain and ATT eCheckRun pattern
Attachment: PDF Grant Payment lure with embedded link
Attachment: PDF with a suspicious string and single URL
Attachment: PDF with bolded passcode
Attachment: PDF with credential theft language and invalid reply-to domain