File Type and Unpacker Release Notes
Last Revision:
July 06, 2026
The File Type and Unpacker modules are used by MailMarshal (SEG), ECM, and WebMarshal. Updates are made available for recent versions through the Automatic
Updates service. Each product release includes the current update of
File Type and Unpacker.
For details of the File Type and Unpacker versions published for each product version, see
Knowledgebase article
Q20446.
Note: File extensions are provided in this document for
reference only. File Type is determined based on file structure, and not by
the file name or extension.New Features
For more information about additional minor features and bug fixes,
see the
release history.
Features new in 2026.02.01
- Additional types recognized
- AV1 Image File Format (.AVIF)
- OpenOffice PrinterSettings.bin (DEVMODE)
Features new in 2026.01.01
- Additional types recognized
- S/Mime authEnvelopedData (P7A)
- AAC files with ADTS stream (raw) data
Features new in 2025.03.01
- Additional types recognized
Features new in 2025.02.01
- Additional types recognized
- Scalable Vector Graphic (.SVG)
- An updated version of the PDF unpacker is included
Features new in 2024.02.01
- Additional types recognized
- PGP Public Key (.ASC)
- Power BI Report (.PBIX) and internal component files
- Power BI Report files are unpacked.
- An updated version of the PDF unpacker is included.
Features new in 2023.03.01
- Unpacker release versions now are numbered by the calendar
year and quarter.
- Where a RAR archives contains some passworded files and some
unpassworded files, the unpassworded files will be unpacked.
- An updated version of the PDF unpacker is included.
For earlier updates, see previous versions of Release Notes linked
from Knowledgebase article
Q20446.
Release History
The following items have been changed or updated in the
specific build versions of File Type and Unpacker listed.
2026.03.01 (July 06, 2026)
|
FTU-488 |
Specific data could cause the
product engines to stop when checking certain file types. Fixed. |
2026.02.01 (June 16, 2026)
|
FTU-485 |
OpenOffice PrinterSettings.bin files are recognized. |
|
FTU-486 |
AV1 Image File Format files are recognized. |
2026.01.01 (April 13, 2026)
|
FTU-275 |
Some HTML files were incorrectly identified as XML. Fixed. |
|
FTU-366 |
File sizes greater than 2GB were not correctly reported. Fixed. |
|
FTU-400 |
Recognition of JavaScript files is improved. |
|
FTU-412 |
Additional variants of the AAC file type (ADTS streams) are
recognized. |
|
FTU-449 |
URLs containing User Info parts (credentials) were not correctly
recognized. Fixed. |
|
FTU-463 |
S/Mime authEnvelopedData arts are recognized. |
|
FTU-468 |
Header lines in messages were unpacked as email body parts in
some cases. Fixed. |
2025.04.03 (February 24, 2026)
|
FTU-470 |
Failed URL extraction from QR images could result in messages
being deadlettered. Fixed. |
|
FTU-471 |
Certain PDF files were not correctly extracted, resulting in
messages being deadlettered. Fixed. |
2025.04.02 (December 3, 2025)
|
FTU-464 |
Email addresses in calendar invites could be incorrectly
rewritten in some cases. Fixed. |
2025.04.01 (December 2, 2025)
|
FTU-453 |
In release 2025.03.01, extraction of URLs from third party links
was not thread safe. Fixed. |
|
FTU-454 |
In release 2025.03.01, the setting to enable or disable
extraction of URLs from third party links was not fully honored.
Fixed. |
|
FTU-455 |
URLs rewritten by additional third party URL scanning services can be
extracted to be checked by MailMarshal technologies. The
rewritten URLs are not altered. |
2025.03.01 (October 15, 2025)
|
FTU-382 |
Zstandard archives are recognized and unpacked. |
|
FTU-428 |
Header lines in attached email messages were counted as part of
the headers of the parent message when calculating header
length. Fixed. |
|
FTU-431 |
Certain MST files were incorrectly recognized as MSI. Fixed. |
|
FTU-433 |
URLs rewritten by some third party URL scanning services can be
extracted to be checked by MailMarshal technologies. The
rewritten URLs are not altered. |
|
FTU-434 |
The "editdata.mso" component in documents does not use the mso
format and caused messages to be deadlettered. Fixed. |
|
FTU-437 |
Excel files with a missing relationship target were deadlettered.
Fixed. |
|
FTU-439 |
Some XML files extracted from Office 2007+ documents can be very
large and can cause the "massively redundant data" calculation
to trigger. Fixed: these files no longer are part of the
compression calculations. |
|
FTU-440 |
Some documents created by LibreOffice were deadlettered because
they contain invalid CustomXML relative paths. Fixed: the
relative part of the path is ignored. |
2025.02.01 (July 7, 2025)
|
FTU-385 |
An updated version of the PDF unpacker is included. |
|
FTU-372 |
SVG graphic files are recognized. |
|
FTU-408 |
PDF files with very long file names are unpacked correctly. |
2024.04.01 (December 5, 2024)
|
FTU-384 |
Messages attracting more than one repacking action could
become malformed. Fixed. |
2024.03.01 (July 17, 2024)
|
FTU-374 |
Messages containing an attachment but no body part could
become malformed when repacked. Fixed. |
2024.02.01 (May 7, 2024)
|
FTU-294 |
Power BI Report files are and internal components are recognized
and unpacked. |
|
FTU-297 |
PGP Public Key files are recognized. |
|
FTU-326 |
An updated version of the WebP library is included. |
|
FTU-348 |
Extraction of URLs for URLDeep evaluation is improved. |
|
FTU-363 |
An updated version of the PDF unpacker is included. |
|
FTU-364 |
Password extraction for encrypted archives has been enhanced. |
2023.03.01 (September 26, 2023)
|
FT-281 |
RAR archives with only some files password encrypted are
correctly detected and usable files are passed to the unpacker. |
|
FT-290 |
File Type release versions now are numbered by the calendar
year and quarter. |
|
FT-292 |
P12 and PFX certificate files are recognized. |
|
FT-295 |
Specific Windows executable files were not recognized.
Fixed. |
|
FT-296 |
Specific message body text was incorrectly treated as an
attached email message. Fixed. |
|
UNPACK-380 |
Unpacker release versions now are numbered by the calendar year
and quarter. |
|
UNPACK-383 |
Unpacking did not honor the content-disposition Attachment in
specific cases. Fixed. |
|
UNPACK-384 |
An updated version of the PDF unpacker is included. |
|
UNPACK-387 |
Password extraction for encrypted archives could cause the
MailMarshal Engine to stop unexpectedly. Fixed. |
For earlier updates, see previous versions of Release Notes linked from
Knowledgebase article
Q20446.
Legal Notice
©
2026
Trustwave Holdings, Inc..
About LevelBlue
LevelBlue reduces risk and builds lasting resilience so organizations can innovate and advance their mission with confidence.
As the world’s most analyst-recognized and largest pure-play managed security services provider, LevelBlue elevates client outcomes that matter:
stronger defense, faster response, and sustained business continuity. LevelBlue combines AI-powered security operations, advanced threat intelligence,
and elite human expertise to provide the most comprehensive portfolio of strategic advisory, managed security,
offensive security, and incident response services..