{"id":219,"date":"2025-03-03T15:48:07","date_gmt":"2025-03-03T20:48:07","guid":{"rendered":"https:\/\/freshphish.info\/?p=219"},"modified":"2025-03-03T15:48:59","modified_gmt":"2025-03-03T20:48:59","slug":"malicious-svg-attachment","status":"publish","type":"post","link":"https:\/\/freshphish.info\/?p=219","title":{"rendered":"Malicious SVG Attachment"},"content":{"rendered":"\n<p>I&#8217;ve known for some time that .svg email attachments could be malicious, but this is the first time I&#8217;ve actually run across one. First, what is a .svg file? It&#8217;s a Scalable Vector Graphic file. Even though it&#8217;s typically displayed as an image, if you look at the source of the file, it&#8217;s essentially an xml file. I alerted my team of the possibility of these files being malicious a few months ago. I didn&#8217;t post here because I didn&#8217;t have an example of a malicious svg file. Now I do, so here it is.<\/p>\n\n\n\n<p>First, here is the email. It was sent from what appears to be a compromised email account since it was sent from hosts authorized in the SPF record to send using this domain. However, the domain isn&#8217;t protected by DMARC so it&#8217;s unlikely they take email security seriously. It&#8217;s posing as an Adobe shared file, saying to use the attachment to access the files.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"613\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2025\/03\/EmailScreenshot-1024x613.jpg\" alt=\"\" class=\"wp-image-220\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2025\/03\/EmailScreenshot-1024x613.jpg 1024w, https:\/\/freshphish.info\/wp-content\/uploads\/2025\/03\/EmailScreenshot-300x179.jpg 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2025\/03\/EmailScreenshot-768x459.jpg 768w, https:\/\/freshphish.info\/wp-content\/uploads\/2025\/03\/EmailScreenshot.jpg 1130w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Looking at the source of the .svg file attachment, you can see the xml. It contains a script designating the source in the included base64 text. You&#8217;ll see I removed portions of the text that specify the email address of the recipient.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"897\" height=\"537\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2025\/03\/svgattachment-1.jpg\" alt=\"\" class=\"wp-image-223\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2025\/03\/svgattachment-1.jpg 897w, https:\/\/freshphish.info\/wp-content\/uploads\/2025\/03\/svgattachment-1-300x180.jpg 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2025\/03\/svgattachment-1-768x460.jpg 768w\" sizes=\"auto, (max-width: 897px) 100vw, 897px\" \/><\/figure>\n\n\n\n<p>Decoding the base64, you can see an obfuscated script:<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"618\" height=\"218\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2025\/03\/decryptedbase64script.jpg\" alt=\"\" class=\"wp-image-222\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2025\/03\/decryptedbase64script.jpg 618w, https:\/\/freshphish.info\/wp-content\/uploads\/2025\/03\/decryptedbase64script-300x106.jpg 300w\" sizes=\"auto, (max-width: 618px) 100vw, 618px\" \/><\/figure>\n\n\n\n<p>If you load it into a browser, which I did through Any.Run, you can see it ends up at a phishing page posing as an M365 signin page.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"541\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2025\/03\/landingpage1-1024x541.jpg\" alt=\"\" class=\"wp-image-224\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2025\/03\/landingpage1-1024x541.jpg 1024w, https:\/\/freshphish.info\/wp-content\/uploads\/2025\/03\/landingpage1-300x158.jpg 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2025\/03\/landingpage1-768x406.jpg 768w, https:\/\/freshphish.info\/wp-content\/uploads\/2025\/03\/landingpage1.jpg 1053w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>I&#8217;d love to block all SVG files due to how easy it is to put together a malicious file, much like wanting to do this with html files, it&#8217;s not feasible since they are too commonly used in legitimate emails.<\/p>\n\n\n\n<p>&#8211;Matt<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I&#8217;ve known for some time that .svg email attachments could be malicious, but this is the first time I&#8217;ve actually<\/p>\n<p><a href=\"https:\/\/freshphish.info\/?p=219\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\">Malicious SVG Attachment<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[12],"tags":[60,58,61,57,4,59,56],"class_list":["post-219","post","type-post","status-publish","format-standard","hentry","category-phish","tag-adobe","tag-attachment","tag-base64","tag-malicious","tag-phish","tag-scalable-vector-graphic","tag-svg"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.9 - aioseo.com -->\n\t<meta name=\"description\" content=\"I&#039;ve known for some time that .svg email attachments could be malicious, but this is the first time I&#039;ve actually run across one. First, what is a .svg file? It&#039;s a Scalable Vector Graphic file. Even though it&#039;s typically displayed as an image, if you look at the source of the file, it&#039;s essentially an\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Matt\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/freshphish.info\/?p=219\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.9\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Fresh Phish - All the freshest phish\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Malicious SVG Attachment - Fresh Phish\" \/>\n\t\t<meta property=\"og:description\" content=\"I&#039;ve known for some time that .svg email attachments could be malicious, but this is the first time I&#039;ve actually run across one. First, what is a .svg file? It&#039;s a Scalable Vector Graphic file. Even though it&#039;s typically displayed as an image, if you look at the source of the file, it&#039;s essentially an\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/freshphish.info\/?p=219\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-03-03T20:48:07+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-03-03T20:48:59+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Malicious SVG Attachment - Fresh Phish\" \/>\n\t\t<meta name=\"twitter:description\" content=\"I&#039;ve known for some time that .svg email attachments could be malicious, but this is the first time I&#039;ve actually run across one. First, what is a .svg file? It&#039;s a Scalable Vector Graphic file. Even though it&#039;s typically displayed as an image, if you look at the source of the file, it&#039;s essentially an\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=219#blogposting\",\"name\":\"Malicious SVG Attachment - Fresh Phish\",\"headline\":\"Malicious SVG Attachment\",\"author\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?author=1#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/freshphish.info\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/EmailScreenshot.jpg\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=219\\\/#articleImage\",\"width\":1130,\"height\":676},\"datePublished\":\"2025-03-03T15:48:07-05:00\",\"dateModified\":\"2025-03-03T15:48:59-05:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=219#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=219#webpage\"},\"articleSection\":\"Phish, Adobe, attachment, base64, malicious, phish, scalable vector graphic, svg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=219#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/freshphish.info\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?cat=12#listItem\",\"name\":\"Phish\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?cat=12#listItem\",\"position\":2,\"name\":\"Phish\",\"item\":\"https:\\\/\\\/freshphish.info\\\/?cat=12\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=219#listItem\",\"name\":\"Malicious SVG Attachment\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=219#listItem\",\"position\":3,\"name\":\"Malicious SVG Attachment\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?cat=12#listItem\",\"name\":\"Phish\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/#organization\",\"name\":\"Fresh Phish\",\"description\":\"All the freshest phish\",\"url\":\"https:\\\/\\\/freshphish.info\\\/\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?author=1#author\",\"url\":\"https:\\\/\\\/freshphish.info\\\/?author=1\",\"name\":\"Matt\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=219#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/82f14a734f69eb729d8b59b4a2438ea6e14bd793d23b22d4299ec5228b06260a?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Matt\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=219#webpage\",\"url\":\"https:\\\/\\\/freshphish.info\\\/?p=219\",\"name\":\"Malicious SVG Attachment - Fresh Phish\",\"description\":\"I've known for some time that .svg email attachments could be malicious, but this is the first time I've actually run across one. First, what is a .svg file? It's a Scalable Vector Graphic file. Even though it's typically displayed as an image, if you look at the source of the file, it's essentially an\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=219#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?author=1#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?author=1#author\"},\"datePublished\":\"2025-03-03T15:48:07-05:00\",\"dateModified\":\"2025-03-03T15:48:59-05:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/#website\",\"url\":\"https:\\\/\\\/freshphish.info\\\/\",\"name\":\"Fresh Phish\",\"description\":\"All the freshest phish\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Malicious SVG Attachment - Fresh Phish","description":"I've known for some time that .svg email attachments could be malicious, but this is the first time I've actually run across one. First, what is a .svg file? It's a Scalable Vector Graphic file. Even though it's typically displayed as an image, if you look at the source of the file, it's essentially an","canonical_url":"https:\/\/freshphish.info\/?p=219","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/freshphish.info\/?p=219#blogposting","name":"Malicious SVG Attachment - Fresh Phish","headline":"Malicious SVG Attachment","author":{"@id":"https:\/\/freshphish.info\/?author=1#author"},"publisher":{"@id":"https:\/\/freshphish.info\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/freshphish.info\/wp-content\/uploads\/2025\/03\/EmailScreenshot.jpg","@id":"https:\/\/freshphish.info\/?p=219\/#articleImage","width":1130,"height":676},"datePublished":"2025-03-03T15:48:07-05:00","dateModified":"2025-03-03T15:48:59-05:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/freshphish.info\/?p=219#webpage"},"isPartOf":{"@id":"https:\/\/freshphish.info\/?p=219#webpage"},"articleSection":"Phish, Adobe, attachment, base64, malicious, phish, scalable vector graphic, svg"},{"@type":"BreadcrumbList","@id":"https:\/\/freshphish.info\/?p=219#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/freshphish.info#listItem","position":1,"name":"Home","item":"https:\/\/freshphish.info","nextItem":{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?cat=12#listItem","name":"Phish"}},{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?cat=12#listItem","position":2,"name":"Phish","item":"https:\/\/freshphish.info\/?cat=12","nextItem":{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?p=219#listItem","name":"Malicious SVG Attachment"},"previousItem":{"@type":"ListItem","@id":"https:\/\/freshphish.info#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?p=219#listItem","position":3,"name":"Malicious SVG Attachment","previousItem":{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?cat=12#listItem","name":"Phish"}}]},{"@type":"Organization","@id":"https:\/\/freshphish.info\/#organization","name":"Fresh Phish","description":"All the freshest phish","url":"https:\/\/freshphish.info\/"},{"@type":"Person","@id":"https:\/\/freshphish.info\/?author=1#author","url":"https:\/\/freshphish.info\/?author=1","name":"Matt","image":{"@type":"ImageObject","@id":"https:\/\/freshphish.info\/?p=219#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/82f14a734f69eb729d8b59b4a2438ea6e14bd793d23b22d4299ec5228b06260a?s=96&d=mm&r=g","width":96,"height":96,"caption":"Matt"}},{"@type":"WebPage","@id":"https:\/\/freshphish.info\/?p=219#webpage","url":"https:\/\/freshphish.info\/?p=219","name":"Malicious SVG Attachment - Fresh Phish","description":"I've known for some time that .svg email attachments could be malicious, but this is the first time I've actually run across one. First, what is a .svg file? It's a Scalable Vector Graphic file. Even though it's typically displayed as an image, if you look at the source of the file, it's essentially an","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/freshphish.info\/#website"},"breadcrumb":{"@id":"https:\/\/freshphish.info\/?p=219#breadcrumblist"},"author":{"@id":"https:\/\/freshphish.info\/?author=1#author"},"creator":{"@id":"https:\/\/freshphish.info\/?author=1#author"},"datePublished":"2025-03-03T15:48:07-05:00","dateModified":"2025-03-03T15:48:59-05:00"},{"@type":"WebSite","@id":"https:\/\/freshphish.info\/#website","url":"https:\/\/freshphish.info\/","name":"Fresh Phish","description":"All the freshest phish","inLanguage":"en-US","publisher":{"@id":"https:\/\/freshphish.info\/#organization"}}]},"og:locale":"en_US","og:site_name":"Fresh Phish - All the freshest phish","og:type":"article","og:title":"Malicious SVG Attachment - Fresh Phish","og:description":"I've known for some time that .svg email attachments could be malicious, but this is the first time I've actually run across one. First, what is a .svg file? It's a Scalable Vector Graphic file. Even though it's typically displayed as an image, if you look at the source of the file, it's essentially an","og:url":"https:\/\/freshphish.info\/?p=219","article:published_time":"2025-03-03T20:48:07+00:00","article:modified_time":"2025-03-03T20:48:59+00:00","twitter:card":"summary_large_image","twitter:title":"Malicious SVG Attachment - Fresh Phish","twitter:description":"I've known for some time that .svg email attachments could be malicious, but this is the first time I've actually run across one. First, what is a .svg file? It's a Scalable Vector Graphic file. Even though it's typically displayed as an image, if you look at the source of the file, it's essentially an"},"aioseo_meta_data":{"post_id":"219","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"BlogPosting","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2025-03-03 20:48:07","updated":"2025-06-04 04:53:18","seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/freshphish.info\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/freshphish.info\/?cat=12\" title=\"Phish\">Phish<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tMalicious SVG Attachment\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/freshphish.info"},{"label":"Phish","link":"https:\/\/freshphish.info\/?cat=12"},{"label":"Malicious SVG Attachment","link":"https:\/\/freshphish.info\/?p=219"}],"_links":{"self":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/219","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=219"}],"version-history":[{"count":1,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/219\/revisions"}],"predecessor-version":[{"id":225,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/219\/revisions\/225"}],"wp:attachment":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=219"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=219"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=219"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}