type.inbound
and any(attachments,
.file_extension in $file_extensions_macros
and any(file.explode(.),
any(.scan.yara.matches, .name == "MALFORMED_OLE_HEADER")
)
)
Playground
Test against your own EMLs or sample data.