About this tool
Break down a suspicious invoice email: double extensions, macro lures, password-protected archives and lookalike sender domains.
The Invoice Attachment Phishing Anatomy takes apart a suspicious invoice email and names the specific trick each part is using — a double extension such as Invoice.pdf.lnk, a Unicode right-to-left override that reverses the visible file name, a password in the body that stops your gateway scanning the archive, or a Reply-To on a different domain from the From. It scores what you paste against the attachment classes Microsoft blocks in Outlook and the wording used to talk people into clicking Enable Content, then lists the verification steps that actually settle the question. Everything runs in your browser; nothing is uploaded.
Open Invoice Attachment Phishing Anatomy on AltFTool — it loads instantly in your browser.
Enter the Attachment file name (for example Invoice_4417.pdf.lnk), the From address, any Reply-To address and the Supplier domain you expect.
Add the Subject line and paste the Message body, then read the Red-flag score out of 100 and the band beneath it.
Check the File name with formatting tricks removed row and the listed findings, then press Copy result to record why the invoice was held.
Every finding says which technique is in play — double extension, bidi override, HTML smuggling, password-protected archive — not just a risk colour.
Bank-change wording is flagged even when there is no malware at all, which is how most invoice fraud actually loses money.
The file name, addresses and body you paste are analysed locally, so a live phishing message is never forwarded anywhere new.
Look at the final extension, not the icon. Anything ending .exe, .scr, .js, .vbs, .lnk, .hta, .iso or a macro-enabled Office type (.docm, .xlsm, .xlsb) executes code and has no business being an invoice. Windows hides known extensions by default, so Invoice.pdf.lnk is displayed as Invoice.pdf — check the full name in the attachment properties.
Because Office blocks macros in files that came from the internet. Since 2022 Microsoft blocks VBA macros by default in documents carrying the Mark of the Web, so the only way the payload runs is if you disable that protection yourself. A legitimate invoice never needs macros enabled.
Yes, when the password is printed in the same email. Encryption stops your mail gateway and antivirus opening the archive to scan it, which is the entire point of sending it that way. Genuine encrypted files are shared with a password sent over a different channel and agreed in advance.
Yes. The From header is free text and can be forged unless the sending domain publishes an enforcing DMARC policy, and a supplier's mailbox can also be compromised outright so the mail is genuinely theirs. Treat any change of bank details as a separate request and confirm it by calling a number from your own records, not one in the email. This is general guidance — follow your organisation's own payment controls.