logo

The Spreadsheet That Arrived Twice: CR/LF Filename Obfuscation and a Base64 Shadow Payload

ID: 44244296-cd28-5e59-b009-42bab05e0d1d

STIX ID: report--44244296-cd28-5e59-b009-42bab05e0d1d

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: [email protected] (Audian Paxson)

...
...

A phishing email delivered an XLSX attachment whose filename contained embedded CR/LF control characters, causing the extraction pipeline to produce a zero-byte artifact while the actual 557,952-byte payload existed as a companion .b64 file; initial SPF/DKIM/DMARC passed at the SocketLabs relay but were invalidated after rewrite by a Cisco IronPort gateway, ARC failed, the sender could not be verified, and the mailbox was quarantined.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.