Detection Method: Archive analysis

Archive analysis is the process of unpacking compressed files like ZIPs, RARs, or TARs to find threats hidden inside. Attackers often bury malicious payloads in multiple layers of archives to bypass basic scanning. This method digs into those layers to expose what’s really inside.
Security systems use recursive unpacking to detect things like:
  • Scripts or executables hidden in nested ZIPs
  • Macro-enabled documents disguised inside archive chains
  • Encrypted files used to evade detection
For example, an attacker might send a ZIP file that contains another ZIP, which holds a Word document with malicious macros. Archive analysis unpacks each layer and inspects the contents individually.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: 7z Archive Containing RAR File
4d ago
Nov 8th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-7z-archive-containing-rar-file-1a629bb4
Attachment: EML with Encrypted ZIP
8d ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-eml-with-encrypted-zip-6897a8f7
Attachment: HTML smuggling with atob and high entropy
8d ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-html-smuggling-with-atob-and-high-entropy-03fcac11
HTML smuggling containing recipient email address
8d ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/html-smuggling-containing-recipient-email-address-af32ff2f
QR code to auto-download of a suspicious file type (unsolicited)
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/qr-code-to-auto-download-of-a-suspicious-file-type-unsolicited-eed87ea2
Attachment: Office file with document sharing and browser instruction lures
27d ago
Oct 16th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-office-file-with-document-sharing-and-browser-instruction-lures-b1250a4b
Non-RFC compliant calendar files from unsolicited sender
1mo ago
Oct 1st, 2025
Sublime Security
/feeds/core/detection-rules/non-rfc-compliant-calendar-files-from-unsolicited-sender-9859f100
Attachment: HTML with obfuscation and recipient's email in JavaScript strings
1mo ago
Sep 25th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-html-with-obfuscation-and-recipients-email-in-javascript-strings-1aff486b
Attachment: Base64 encoded bash command in filename
2mo ago
Sep 5th, 2025
@vector_sec
/feeds/core/detection-rules/attachment-base64-encoded-bash-command-in-filename-819f69c8
Attachment: Office file with credential phishing URLs
2mo ago
Sep 2nd, 2025
Sublime Security
/feeds/core/detection-rules/attachment-office-file-with-credential-phishing-urls-b2cae98d
Attachment: WinRAR CVE-2025-8088 exploitation
3mo ago
Aug 12th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-winrar-cve-2025-8088-exploitation-33b3a82b
Attachment: SVG file execution
3mo ago
Aug 8th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-svg-file-execution-084b0cde
Attachment: Embedded Javascript in SVG file
3mo ago
Aug 8th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-embedded-javascript-in-svg-file-f70293bc
Attachment: MSI installer file
3mo ago
Aug 5th, 2025
@ajpc500
/feeds/core/detection-rules/attachment-msi-installer-file-ae17b1a9
Attachment: Double base64-encoded zip file in HTML smuggling attachment
3mo ago
Aug 5th, 2025
@ajpc500
/feeds/core/detection-rules/attachment-double-base64-encoded-zip-file-in-html-smuggling-attachment-61ebb07b
Attachment: Malicious OneNote commands
3mo ago
Aug 5th, 2025
@Kyle_Parrish_
/feeds/core/detection-rules/attachment-malicious-onenote-commands-7319f0eb
Attachment: Macro files containing MHT content
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-macro-files-containing-mht-content-4d54e40b
Attachment: HTML attachment with login portal indicators
3mo ago
Aug 5th, 2025
@ajpc500
/feeds/core/detection-rules/attachment-html-attachment-with-login-portal-indicators-3aabf4a7
Attachment: DocX embedded binary
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-docx-embedded-binary-feff0241
Attachment: Office document with VSTO add-in
3mo ago
Aug 5th, 2025
@vector_sec
/feeds/core/detection-rules/attachment-office-document-with-vsto-add-in-27afa730