Many thanks Porthos amd definetly not a waste of time.
Exploit code is itself non executable so our engine does not currently support direct sniffing of the file.
However the link(s) supply other information/data/files that we can react too.
The Exploit IP address and any subsequent support or executable files & their IP address can also be assessed for subsequent blocking/detection if they are not already covered.