Attachment: HTML smuggling with hex strings
Attachment: HTML smuggling with high entropy and other signals
Attachment: HTML smuggling with raw array buffer
Attachment: HTML smuggling with RC4 decryption
Attachment: HTML smuggling with ROT13
Attachment: HTML smuggling with setTimeout
Attachment: HTML smuggling with unescape
Attachment: HTML with emoji-to-character map
Attachment: HTML with hidden body
Attachment: HTML with JavaScript functions for HTTP requests
Attachment: HTML with obfuscation and recipient's email in JavaScript strings
Attachment: ICS calendar file with base64 encoded recipient address in URL parameters
Attachment: ICS calendar file with QR code containing recipient email address
Attachment: ICS calendar file with recipient address in UID field
Attachment: ICS calendar file with suspicious product identifier
Attachment: ICS calendar file with suspicious UID domain
Attachment: ICS calendar invite with bid/RFP lure and suspicious link
Attachment: ICS calendar invite with financial lure and suspicious link
Attachment: ICS calendar invite with photo/file share lure
Attachment: ICS calendar with embedded file from internal sender with SPF failure
Attachment: ICS file with AWS Lambda URL
Attachment: ICS file with credential theft indicators
Attachment: ICS file with excessive custom properties
Attachment: ICS file with links to newly registered domains
Attachment: ICS file with meeting prefix
Attachment: ICS file with non-Gregorian calendar scale
Attachment: ICS invite meeting lure
Attachment: ICS Link With Valueless Base64 Query Parameter
Attachment: ICS voicemail lure with suspicious link
Attachment: ICS with embedded document
Attachment: ICS with embedded Javascript in SVG file
Attachment: ICS with employee policy review lure
Attachment: Image-only docx/pptx callback phishing
Attachment: Invoice and W-9 PDFs with suspicious creators
Attachment: JavaScript file with suspicious base64-encoded executable
Attachment: JPEG with gd-jpeg creator and suspicious file name
Attachment: Legal themed message or PDF with suspicious indicators
Attachment: Link file with UNC path
Attachment: Link to Doubleclick.net open redirect
Attachment: LNK with embedded content
Attachment: Macro files containing MHT content
Attachment: Macro with suspected use of COM ShellBrowserWindow object for process creation
Attachment: Malformed OLE file
Attachment: Malicious OneNote commands
Attachment: Microsoft 365 credential phishing
Attachment: Microsoft impersonation via PDF with link and suspicious language
Attachment: Microsoft OAuth credential harvesting via EML with embedded malicious links
Attachment: Microsoft SharePoint Impersonation via images in macro-enabled attachment
Attachment: MSI installer file