Detection Method: Archive analysis

Archive analysis is the process of unpacking compressed files like ZIPs, RARs, or TARs to find threats hidden inside. Attackers often bury malicious payloads in multiple layers of archives to bypass basic scanning. This method digs into those layers to expose what’s really inside.
Security systems use recursive unpacking to detect things like:
  • Scripts or executables hidden in nested ZIPs
  • Macro-enabled documents disguised inside archive chains
  • Encrypted files used to evade detection
For example, an attacker might send a ZIP file that contains another ZIP, which holds a Word document with malicious macros. Archive analysis unpacks each layer and inspects the contents individually.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: Gzip-archived with nested HTML file containing image and button link
13d ago
Sep 3rd, 2026
Sublime Security
Attachment: GZ archive with credential theft content
14d ago
Sep 2nd, 2026
Sublime Security
Attachment: ZIP filename mismatch
16d ago
Aug 31st, 2026
Sublime Security
Attachment: ZIP containing Office binary with embedded DLL
23d ago
Aug 24th, 2026
Sublime Security
Attachment: Targeted DOCX with personalized recipient acknowledgement lure
1mo ago
Aug 4th, 2026
Sublime Security
Attachment: Malicious zip file matching zipline campaign
2mo ago
Jun 25th, 2026
Sublime Security
Attachment with auto-executing macro (unsolicited)
3mo ago
Jun 5th, 2026
Sublime Security
Attachment: Embedded VBScript in MHT file
4mo ago
May 14th, 2026
Sublime Security
Attachment with unscannable encrypted zip
4mo ago
Apr 30th, 2026
Sublime Security
Adobe branded PDF file linking to a password-protected file from untrusted sender
4mo ago
Apr 29th, 2026
Sublime Security
MalwareBazaar: Malicious attachment hash in archive (trusted reporters)
4mo ago
Apr 29th, 2026
Sublime Security
Non-RFC compliant calendar files from unsolicited sender
4mo ago
Apr 28th, 2026
Sublime Security
Attachment: Double base64-encoded zip file in HTML smuggling attachment
4mo ago
Apr 27th, 2026
@ajpc500
Attachment: File execution via Javascript
4mo ago
Apr 27th, 2026
Sublime Security
Attachment: HTML smuggling Microsoft sign in
4mo ago
Apr 27th, 2026
Sublime Security
Attachment: TAR file with RAR type
4mo ago
Apr 24th, 2026
Sublime Security
Attachment: Encrypted ZIP containing VHDX file
5mo ago
Apr 3rd, 2026
Sublime Security
Attachment: EML with QR code redirecting to Cloudflare challenges
5mo ago
Apr 1st, 2026
Sublime Security
Attachment: ZIP file with CVE-2026-0866 exploit
6mo ago
Mar 20th, 2026
Sublime Security
Attachment: Archive containing HTML file with file scheme link
6mo ago
Mar 17th, 2026
Sublime Security