# Suspicious ZIP file attached to email

**URL:** <https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079>\
**Category:** Factual Questions\
**Created:** [June 17, 2009, 4:02pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079 "2009-06-17T16:02:08Z")\
**Posts on this page:** 8\
**Page:** 2

<div class="post-metadata">

**Author:** ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)\
**Post date:** [June 18, 2009, 11:23am UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/21 "2009-06-18T11:23:52Z")

</div>

> [@Stealth\_Potato](#):
>
> They just wanted to make it abundantly clear that this was _your_ United Parcel Service (you know, of _America_), and not somebody else’s. 😃

That’s probably why the [UPS website](http://www.ups.com/) has the same thing in its copyright notice:

> [@](#):
>
> Copyright © 1994-2009 United Parcel Service **of America** , Inc. All rights reserved.

---

<div class="post-metadata">

**Author:** ![Casserole](https://avatars.discourse-cdn.com/v4/letter/c/b77776/32.png) [@Casserole](https://boards.straightdope.com/u/Casserole)\
**Post date:** [June 18, 2009, 1:04pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/22 "2009-06-18T13:04:43Z")

</div>

> [@chrisk](#):
>
> I may be way too techy to grasp this, but - by default, will windows show .pdf at the end? Might it not actually register as a danger sign unto the clueless that .pdf actually shows up at the end of the filename?

It’s less of a technical thing, and has more of a social engineering aspect to it.

Because many computer users don’t simply use their own computer, they are exposed to multiple setups with differing options. Some are set up to show extensions, and some are not. In essence, we become so desensitized to the presence (or absence) or extensions that we don’t find it weird then it shows up unexpectedly.

---

<div class="post-metadata">

**Author:** ![sailor](https://avatars.discourse-cdn.com/v4/letter/s/a587f6/32.png) [@sailor](https://boards.straightdope.com/u/sailor)\
**Post date:** [June 18, 2009, 1:48pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/23 "2009-06-18T13:48:34Z")

</div>

> [@Chronos](#):
>
> And the next step is to put a password on the zip file (given in the e-mail) so an antivirus program _can’t_ even scan it.

On the other hand there is such thing as too much precaution because I have experienced the case where I was trying to send a legitimate exe file to someone and it was pretty much impossible. Whether exe or zip Messenger would not allow it nor their email program. Just based on the file type, not because of any perceived virus threat. Renaming it to .txt wouldn’t work either. I remember wasting a lot of time trying to get around that. That is just ridiculous.

> [@CookingWithGas](#):
>
> This “feature” of Windows just kills me. The first thing I do on a new machine is to set it up to show extensions.

Yup. Trey helping someone over the phone and tell them “double click on the file called d123” and the answer is “which one? There’s 3 files with that name.”

I also hate how windows pretty much autoruns everything you connect and it makes it almost impossible to disable autorun. I am still trying to figure this one out.

> [@Rigamarole](#):
>
> Maybe you’re just being cute, but virii has [never been a word](http://en.wikipedia.org/wiki/Virus_(plural)#Virus), in English or in Latin, now or ever. It never had a plural form in Latin, and as a second declension neuter noun, the plural form was unestablished. In Neo-Latin the plural form is _vira_, following neuter rules, but in English the plural is simply _viruses_.

Yup. I hate it when people want to pretend they’re speaking Latin and make up all sorts of pig-Latin plurals for anything that sounds like it could remotely maybe be Latin. Like forum, octupus, etc. I just wish people would stop trying to speak Latin and just speak good English.

> [@Casserole](#):
>
> It’s less of a technical thing, and has more of a social engineering aspect to it.
> 
> Because many computer users don’t simply use their own computer, they are exposed to multiple setups with differing options. Some are set up to show extensions, and some are not. In essence, we become so desensitized to the presence (or absence) or extensions that we don’t find it weird then it shows up unexpectedly.

There is another aspect. I have my computer set up the way I like it and I feel comfortable with it but when I am using another computer I just feel clumsy because everything is different and that means it is easier to get something past by me.

---

<div class="post-metadata">

**Author:** ![HorseloverFat](https://avatars.discourse-cdn.com/v4/letter/h/8e8cbc/32.png) [@HorseloverFat](https://boards.straightdope.com/u/HorseloverFat)\
**Post date:** [June 18, 2009, 3:43pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/24 "2009-06-18T15:43:25Z")

</div>

> [@](#):
>
> I have experienced the case where I was trying to send a legitimate exe file to someone and it was pretty much impossible.

Because email admins dont see email as a software distrubution system. Its an email system. We do this for a couple reasons:

1. I cant see any legitimate reason for my users to ever have to run an .exe from anyone.

2. I dont want to take chances. Like I said earlier its trivial to write up a malicious little program and send it to a select group of people. You have several days before the antivirus apps detect it.

3. Even someone running as non-admin can be exploited. Lets say I write a script to copy all your documents in My Documents and all the documents in your companies network shares, zip it up, and ftp it to me. Now I have all your internal info.

Personally, I think any attempt to send an exe should put that person on a blacklist for 24 hours or so, the same way we do with spammers.

---

<div class="post-metadata">

**Author:** ![sailor](https://avatars.discourse-cdn.com/v4/letter/s/a587f6/32.png) [@sailor](https://boards.straightdope.com/u/sailor)\
**Post date:** [June 18, 2009, 4:16pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/25 "2009-06-18T16:16:32Z")

</div>

> [@HorseloverFat](#):
>
> Because email admins dont see email as a software distrubution system. Its an email system. We do this for a couple reasons:
> 
> 1. I cant see any legitimate reason for my users to ever have to run an .exe from anyone.
> 
> 2. I dont want to take chances. Like I said earlier its trivial to write up a malicious little program and send it to a select group of people. You have several days before the antivirus apps detect it.
> 
> 3. Even someone running as non-admin can be exploited. Lets say I write a script to copy all your documents in My Documents and all the documents in your companies network shares, zip it up, and ftp it to me. Now I have all your internal info.
> 
> Personally, I think any attempt to send an exe should put that person on a blacklist for 24 hours or so, the same way we do with spammers.

Except that this is not on anyone’s private network but we were both connected to the Internet directly and I _am_ the Administrator here. I do not need Microsoft Messenger or Hotmail putting those hurdles in my way.

---

<div class="post-metadata">

**Author:** ![HorseloverFat](https://avatars.discourse-cdn.com/v4/letter/h/8e8cbc/32.png) [@HorseloverFat](https://boards.straightdope.com/u/HorseloverFat)\
**Post date:** [June 18, 2009, 7:03pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/26 "2009-06-18T19:03:45Z")

</div>

Yes, but its a social good for Hotmail and Gmail to do this when 99.999999999999% of the email with executables are malware. Admins can use ftp and direct their clients to log in. No need for executables over email ever.

---

<div class="post-metadata">

**Author:** ![Rigamarole](https://avatars.discourse-cdn.com/v4/letter/r/77aa72/32.png) [@Rigamarole](https://boards.straightdope.com/u/Rigamarole)\
**Post date:** [June 18, 2009, 7:09pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/27 "2009-06-18T19:09:20Z")

</div>

> [@sailor](#):
>
> Yup. I hate it when people want to pretend they’re speaking Latin and make up all sorts of pig-Latin plurals for anything that sounds like it could remotely maybe be Latin. Like forum, octupus, etc. I just wish people would stop trying to speak Latin and just speak good English.

Well in fairness, _forum_ is a legit Latin word which is pluralized _fora_, and in English either _forums_ or _fora_ are acceptable. _Octopus_ of course is not, but enough people have said “octopi” that it’s in the dictionary as an English plural.

---

<div class="post-metadata">

**Author:** ![sailor](https://avatars.discourse-cdn.com/v4/letter/s/a587f6/32.png) [@sailor](https://boards.straightdope.com/u/sailor)\
**Post date:** [June 18, 2009, 7:28pm UTC](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079/28 "2009-06-18T19:28:56Z")

</div>

> [@HorseloverFat](#):
>
> Yes, but its a social good for Hotmail and Gmail to do this when 99.999999999999% of the email with executables are malware. Admins can use ftp and direct their clients to log in. No need for executables over email ever.

Well, that’s your take. In my case I did need to send an executable and I was trying email because Messenger was blocking my different attempts to get around it.

I have no problem with them scanning for malware but when they just block everything they are just a nuisance.

[Previous page](https://boards.straightdope.com/t/suspicious-zip-file-attached-to-email/500079.md?page=1)
