{"success":true,"data":{"id":"href-direct-executable-download","label":"Direct executable download link — .exe / .msi / .bat in an href","description":"An `<a href>` in the body points directly at a binary file — `https://evil.example/invoice.exe`, `https://x.example/setup.msi`, `https://x.example/loader.hta`, etc. Covers 15 Windows/Java/PowerShell/VB/WSH executable extensions. Legitimate companies NEVER link directly at a binary from email — they route users through a product page for tracking, AV scanning, and brand-safety compliance. Malware delivery campaigns use direct executable hrefs specifically to evade scanners that only inspect landing pages. The scope is strictly the URL path, so `.exe` in a query string or fragment does not false-fire.","tier":"danger","category":"other","isThin":false}}