About this tool
Break down a suspicious invoice email: double extensions, macro lures, password-protected archives and lookalike sender domains.
This tool takes apart a suspicious invoice email and names the specific trick each part is using — a double extension such as Invoice.pdf.lnk, a Unicode right-to-left override that reverses the visible file name, a password in the body that stops your gateway scanning the archive, or a Reply-To on a different domain from the From. It scores what you paste against the attachment classes Microsoft blocks in Outlook and the wording used to talk people into clicking Enable Content, then lists the verification steps that actually settle the question. Everything runs in your browser; nothing is uploaded.
Open Invoice Attachment Phishing Anatomy on AltFTool — it loads instantly in your browser.
Add your input to the workspace.
Adjust the options until the result looks right.
Copy or download the output and put it to work.
Every finding says which technique is in play — double extension, bidi override, HTML smuggling, password-protected archive — not just a risk colour.
Bank-change wording is flagged even when there is no malware at all, which is how most invoice fraud actually loses money.
The file name, addresses and body you paste are analysed locally, so a live phishing message is never forwarded anywhere new.
Look at the final extension, not the icon. Anything ending .exe, .scr, .js, .vbs, .lnk, .hta, .iso or a macro-enabled Office type (.docm, .xlsm, .xlsb) executes code and has no business being an invoice. Windows hides known extensions by default, so Invoice.pdf.lnk is displayed as Invoice.pdf — check the full name in the attachment properties.
Because Office blocks macros in files that came from the internet. Since 2022 Microsoft blocks VBA macros by default in documents carrying the Mark of the Web, so the only way the payload runs is if you disable that protection yourself. A legitimate invoice never needs macros enabled.
Yes, when the password is printed in the same email. Encryption stops your mail gateway and antivirus opening the archive to scan it, which is the entire point of sending it that way. Genuine encrypted files are shared with a password sent over a different channel and agreed in advance.
Yes. The From header is free text and can be forged unless the sending domain publishes an enforcing DMARC policy, and a supplier's mailbox can also be compromised outright so the mail is genuinely theirs. Treat any change of bank details as a separate request and confirm it by calling a number from your own records, not one in the email. This is general guidance — follow your organisation's own payment controls.