Articles in this section

Manage Attachments

Overview

The Manage Attachments page allows for the creation and editing of phishing email attachments. Please contact the Support Team to enable this feature at support@phishingbox.com

Navigate to Templates > Manage Attachments to view, create, and update attachments.

  1. View attachments
  2. Create an attachment
  3. Edit an attachment
  4. Localizations
  5. File types
  6. Hook URL
  7. Add attachment to phishing email

View attachments

Created attachments will be displayed in the Manage Attachments table.

Click the "+ Create Attachment" button to display the create attachment modal. Click the "Edit" button under the "Actions" column for a respective attachment to display the edit attachment modal.

 

Create an attachment

Provide the attachment with a Name, Filename, and locale. Then, give the selected localization an HTML body.

Create Attachment modal after selecting "+ Create Attachment" on the Manage Attachments page

The "ICS Event Subject" is the subject line that will be used for ICS attachments. If the attachment is an ICS attachment and the ICS Event Subject is left blank, the invite subject line will fall back to the phishing email subject. Furthermore, for ICS attachments, the body will become the calendar invite description. 

The "Visible on phishing email template editor" toggle will, when enabled, allow the attachment to be selected as an attachment for any phishing email template. If this is enabled in a Library account, it will become available for all accounts. If this is enabled in a non-library account, it will become available only in the account that owns/created the attachment. 

The "Download Preview" dropdown button allows to download a preview of the attachment that would be amended to a phishing email that leverages the attachment.

Click the "Save" button to save the template.

 

Edit an attachment

The edit attachment popup is similar to the create attachment popup, but there are several localization-related controls that will be enabled.

The "Default Locale" switch allows you to specify which attachment localization will be the default.

Click the trash can icon to delete a localization. The default localization CANNOT be deleted.

Click the addition icon to create a new localization.

Click the globe icon to translate the default localization into different languages (if enabled for the account).

 

Localizations

Localizations give attachments the ability to render in different languages based on the target's preferred language. Each attachment has a default localization that will be used if the target does not have a preferred language set, or the attachment does not have a localization in the target's preferred language.

Attachment localizations behave similarly to phishing email localizations.

 

File types

When attaching a file to a phishing email template, the attachment can be sent as a:

  • PDF file
  • HTML file, or
  • Calendar Invite (ICS). 

For PDF types, the attachment's HTML will be formatted into a PDF if the user selected to send the attachment as a PDF. PDFs will ALWAYS be formatted.

For ICS types, please note the following:

  • Attachment tracking should be enabled so that the calendar invite is generated and tracked through the normal phishing attachment flow. 
  • A {hook_url} can be added in the attachment body to place the tracked phishing link in the invite description. 
  • .ics does NOT need to be added to the localization filename. 
  • Attachment localizations can have their own ICS Event Subject. 
  • When a localization is created from another localization, the Event Subject is copied, along with the Body and Filename. 
  • The generated calendar invite is recipient-specific, and the invite includes the target as the attendee and the phishing email sender as the organizer. 
  • The invite description, location, and URL use the tracked phishing link when {hook_url} is included in the attachment body. 
  • The calendar invite event is automatically scheduled for 10:00 AM on the next weekday using the target's configured timezone (when available), and lasts 30 minutes. 

 

Hook URL

All anchor (<a>) tags in the attachment's HTML will have their href attribute's value set to "{hook_url}" when generated. The "{hook_url}" will be swapped out with a URL that is unique for the target of the phishing email. The URL, when clicked/loaded, will log an "Opened Attachment" action for the target.

 

Add attachment to phishing email

To add an attachment to a phishing email, navigate to the template editor for the preferred phishing email. Under the template's "Tracking Settings" section, enable the "Track an Attachment" option.

If the attachment is library visible, it will appear in the "Select attachment" select menu. Select an attachment and specify the preferred file type. After saving, any phishing emails sent that use the template will include the selected attachment.

 

Back to top

Was this article helpful?
0 out of 0 found this helpful