# Suspicious ZIP file attached to email

**URL:** <https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079>\
**Category:** Factual Questions\
**Created:** [June 17, 2009, 4:02pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079 "2009-06-17T16:02:08Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [June 17, 2009, 4:02pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/1 "2009-06-17T16:02:08Z")

</div>

I have an email from an unknown source that is attempting to impersonate UPS. It has an attachment that is a ZIP file. I don’t intend to open it because it’s from a clearly bogus source.

However, I am curious about why anyone would send it. Can a ZIP file can be dangerous? A self-extracting one can be, but it would have a .exe extension, wouldn’t it? I know that in some cases even an image file has been shown to be dangerous (can’t remember the details, maybe an exploit of an old IE flaw). But can a ZIP file execute active content if opened?

ETA:

> [@bogus email](#):
>
> Dear customer!
> 
> Unfortunately we were not able to deliver the postal package sent on the 25th of May in time because the recipient’s address is inexact.  
> Please print out the invoice copy attached and collect the package at our department.
> 
> Your United Parcel Service of America

---

<div class="post-metadata">

**Author:** ![Terminus\_Est](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/terminus_est/32/3087_2.png) [@Terminus\_Est](https://boards.straightdope.com/u/Terminus_Est)\
**Post date:** [June 17, 2009, 4:46pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/2 "2009-06-17T16:46:23Z")

</div>

The email wants you to print the attached file. ZIP files can’t be printed directly, so of course you’re going to unzip it. Then you double-click the unzipped contents to print it. It could be an innocuous DOC or PDF or a malicious executable. Lots of people don’t pay attention to what they’re clicking. Lots of people don’t even have their file extension set to display.

---

<div class="post-metadata">

**Author:** ![HorseloverFat](https://avatars.discourse-cdn.com/v4/letter/h/8e8cbc/32.png) [@HorseloverFat](https://boards.straightdope.com/u/HorseloverFat)\
**Post date:** [June 17, 2009, 4:51pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/3 "2009-06-17T16:51:19Z")

</div>

First off, zips are almost universally allowed via email unlike .exe.

Secondly, its trivial for me to take a .exe file and give it the icon of an Acrobat file, so you think its a pdf. I can also name it document.pdf.exe. By default windows will not show .exe at the end, so it will look just like a pdf to most people.

This is a common vector of attack and its getting pretty popular. To top it off most people have their antiviruses set to not scan compressed files as its a pretty big performance hit. Personally, id like to see all zip implementations request a virus scan before extraction, but so far none do.

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [June 17, 2009, 5:00pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/4 "2009-06-17T17:00:07Z")

</div>

> [@](#):
>
> This is a common vector of attack and its getting pretty popular. To top it off most people have their antiviruses set to not scan compressed files as its a pretty big performance hit.

And the next step is to put a password on the zip file (given in the e-mail) so an antivirus program _can’t_ even scan it.

---

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [June 17, 2009, 5:28pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/5 "2009-06-17T17:28:28Z")

</div>

> [@Terminus\_Est](#):
>
> Lots of people don’t even have their file extension set to display.

> [@HorseloverFat](#):
>
> By default windows will not show .exe at the end, so it will look just like a pdf to most people.

This “feature” of Windows just kills me. The first thing I do on a new machine is to set it up to show extensions.

---

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [June 17, 2009, 5:29pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/6 "2009-06-17T17:29:45Z")

</div>

OK, so I opened it. And it contains an exe file. \<del\>

---

<div class="post-metadata">

**Author:** ![Khadaji](https://avatars.discourse-cdn.com/v4/letter/k/9e8a1a/32.png) [@Khadaji](https://boards.straightdope.com/u/Khadaji)\
**Post date:** [June 17, 2009, 5:33pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/7 "2009-06-17T17:33:18Z")

</div>

> [@CookingWithGas](#):
>
> This “feature” of Windows just kills me. The first thing I do on a new machine is to set it up to show extensions.

Agreed! I hate that. And I hate when I’m supporting someone on the phone and theirs is turned off and they don’t know how to turn it on.

---

<div class="post-metadata">

**Author:** ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)\
**Post date:** [June 17, 2009, 5:34pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/8 "2009-06-17T17:34:22Z")

</div>

It is a [virus attempt.](http://www.snopes.com/computer/virus/ups.asp)

---

<div class="post-metadata">

**Author:** ![Wheelz](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/wheelz/32/5718_2.png) [@Wheelz](https://boards.straightdope.com/u/Wheelz)\
**Post date:** [June 17, 2009, 6:12pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/9 "2009-06-17T18:12:58Z")

</div>

> [@](#):
>
> Originally Posted by \*\*bogus email \*\*  
> \*Dear customer!
> 
> Unfortunately we were not able to deliver the postal package sent on the 25th of May in time because the recipient’s address is inexact.  
> Please print out the invoice copy attached and collect the package at our department.
> 
> Your United Parcel Service of America\*

Gee, I can’t _imagine_ why you’d be suspicious of this message… “Your United Parcel Service of America”??  
I especially enjoyed the exclamation point.

---

<div class="post-metadata">

**Author:** ![Nanoda](https://avatars.discourse-cdn.com/v4/letter/n/ce73a5/32.png) [@Nanoda](https://boards.straightdope.com/u/Nanoda)\
**Post date:** [June 17, 2009, 6:22pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/10 "2009-06-17T18:22:16Z")

</div>

> [@Terminus\_Est](#):
>
> It could be an innocuous DOC or PDF […]

Nothing innocuous about either of those formats; they’re both capable of harbouring virii.

---

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [June 17, 2009, 6:50pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/11 "2009-06-17T18:50:46Z")

</div>

> [@Nanoda](#):
>
> Nothing innocuous about either of those formats; they’re both capable of harbouring virii.

I know that Word files can contain harmful macros, but didn’t realize PDF files could contain active content. How does \*that \*work?

---

<div class="post-metadata">

**Author:** ![chrisk](https://avatars.discourse-cdn.com/v4/letter/c/6de8d8/32.png) [@chrisk](https://boards.straightdope.com/u/chrisk)\
**Post date:** [June 17, 2009, 6:53pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/12 "2009-06-17T18:53:30Z")

</div>

> [@HorseloverFat](#):
>
> I can also name it document.pdf.exe. By default windows will not show .exe at the end, so it will look just like a pdf to most people.

I may be way too techy to grasp this, but - by default, will windows show .pdf at the end? Might it not actually register as a danger sign unto the clueless that .pdf actually shows up at the end of the filename?

Of course, I realize that this can be resolved by just naming it document.exe and having it show a PDF-like icon.

Like other people, I _insist_ on seeing file extensions myself.

---

<div class="post-metadata">

**Author:** ![Ximenean](https://avatars.discourse-cdn.com/v4/letter/x/aca169/32.png) [@Ximenean](https://boards.straightdope.com/u/Ximenean)\
**Post date:** [June 17, 2009, 7:04pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/13 "2009-06-17T19:04:30Z")

</div>

Generally speaking, opening a file in itself isn’t dangerous. Executing code of unknown origin is dangerous. Of course, some file formats such as .exes and, depending on the configuration of your computer, .docs will cause code to be executed when they are opened. Zip files are not like that, so should in theory been safe to open.

However, it is occasionally possible to get code to run simply when a file is opened, by exploiting things like buffer overruns. A bug in the application that opens files of that type causes code maliciously embedded in the file to be executed. I am not aware of any applications that mishandle .zip files in such a way, though. The attacker has to be aware of the bug and exactly how to craft the file so that the code is successfully executed. It’s a lot harder than just sending someone an .exe and hoping they run it.

---

<div class="post-metadata">

**Author:** ![RitterSport](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/rittersport/32/6326_2.png) [@RitterSport](https://boards.straightdope.com/u/RitterSport)\
**Post date:** [June 17, 2009, 7:08pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/14 "2009-06-17T19:08:14Z")

</div>

> [@CookingWithGas](#):
>
> I know that Word files can contain harmful macros, but didn’t realize PDF files could contain active content. How does \*that \*work?

I think it works through javascript abilities inside PDFs. Here’s something about it:

> **[Adobe Fixes Recent PDF Flaw, But Not Before Auto Exploit - Slashdot](https://it.slashdot.org/story/09/03/11/1722236/adobe-fixes-recent-pdf-flaw-but-not-before-auto-exploit)**
>
> SkiifGeek writes "With Adobe's patch for the JBIG2Decode vulnerability due in a few days time, new methods to target the vulnerability have been discovered that make it far riskier than previously thought. Didier Stevens recently showed the world...

I would think that PDFs are actually less safe than DOCs these days, since Microsoft will disable VBAs/macros by default in Word, but I think that Adobe has Acrobat run scripts by default.

In a similar vein, I loath Acrobat Reader.

---

<div class="post-metadata">

**Author:** ![HorseloverFat](https://avatars.discourse-cdn.com/v4/letter/h/8e8cbc/32.png) [@HorseloverFat](https://boards.straightdope.com/u/HorseloverFat)\
**Post date:** [June 17, 2009, 7:40pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/15 "2009-06-17T19:40:48Z")

</div>

Yep I always do this to acrobat installs:

Edit \> Preferences \> Javascript \> Uncheck Enable Javascript

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [June 17, 2009, 11:07pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/16 "2009-06-17T23:07:05Z")

</div>

> [@HorseloverFat](#):
>
> This is a common vector of attack and its getting pretty popular.

Common at one point, but I doubt it’s gaining any popularity. It’s been out there for at least five years, and all mail antivirus scanners check .zip files as a matter of course. Similarly, the double extension exploit is five-year-old news.

This probably got through because it’s a new virus, not because your gateway scanner didn’t check zip files.

---

<div class="post-metadata">

**Author:** ![HorseloverFat](https://avatars.discourse-cdn.com/v4/letter/h/8e8cbc/32.png) [@HorseloverFat](https://boards.straightdope.com/u/HorseloverFat)\
**Post date:** [June 18, 2009, 12:18am UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/17 "2009-06-18T00:18:43Z")

</div>

In my neck of the woods its used for targeted attacks in my industry. Its not sent via mass mail but to select people in my organization, all of whom deal with money. So its may not make the big “OMG VIRUS” news but its a real threat. As far as checking .zips go, well the attackers wrote a custom virus for us and it was in zero virus databases. I submitted it to all the major vendors that day and didnt see it detected for at least a week. Thats quite of bit of time for it to spread.

I cant vouch for heuristics based scanners, but in my experience theyre pretty lousy and usually that feature is turned off because of false positives.

\>Similarly, the double extension exploit is five-year-old news.

If it works it works.

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [June 18, 2009, 4:33am UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/18 "2009-06-18T04:33:21Z")

</div>

I don’t know about you guys, but back when I had Windows, my antivirus automatically ran any time I opened a ZIP file. In fact, it would hide ZIP files that supposedly had viruses in them. This frustrated me when I discovered that one large zip file just had a single virus file in it, but was otherwise clean. I knew the file was a virus, and knew how to avoid it.

---

<div class="post-metadata">

**Author:** ![Rigamarole](https://avatars.discourse-cdn.com/v4/letter/r/77aa72/32.png) [@Rigamarole](https://boards.straightdope.com/u/Rigamarole)\
**Post date:** [June 18, 2009, 4:58am UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/19 "2009-06-18T04:58:09Z")

</div>

> [@Nanoda](#):
>
> Nothing innocuous about either of those formats; they’re both capable of harbouring virii.

Maybe you’re just being cute, but virii has [never been a word](http://en.wikipedia.org/wiki/Virus_(plural)#Virus), in English or in Latin, now or ever. It never had a plural form in Latin, and as a second declension neuter noun, the plural form was unestablished. In Neo-Latin the plural form is _vira_, following neuter rules, but in English the plural is simply _viruses_.

---

<div class="post-metadata">

**Author:** ![Stealth\_Potato](https://avatars.discourse-cdn.com/v4/letter/s/d78d45/32.png) [@Stealth\_Potato](https://boards.straightdope.com/u/Stealth_Potato)\
**Post date:** [June 18, 2009, 6:31am UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/20 "2009-06-18T06:31:08Z")

</div>

> [@Wheelz](#):
>
> Gee, I can’t _imagine_ why you’d be suspicious of this message… “Your United Parcel Service of America”??

They just wanted to make it abundantly clear that this was _your_ United Parcel Service (you know, of _America_), and not somebody else’s. 😃

[Next page](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079.md?page=2)
