Fake Emails with a Malicious Zip File Attached that Contains a Virus

Fake Emails with a Malicious Zip File Attached that Contains a Virus

We have noticed that cyber-criminals are sending out thousands of fake email messages with an attached Zip or compressed file (a file with name ending with '.zip', '.rar', ".gz", or '.cab') that contains a virus or a Trojan horse. The files are sent in a compressed or Zip format to help prevent anti-virus software from detecting and deleting them. And, any attempt by the recipients to open the malicious attachment will result in their computers getting infected with a virus, Trojan horse or some other computer malware.

Advertisements - Continue reading below

The cyber-criminals behind the fake and malicious emails, make them look convincing, by making the emails look as if they were sent from a legitimate company, family or friend, by using a technique called email spoofing.

Email spoofing allows someone to send an email message, and make that message appears as if it came from someone else.

For example:

I can send an email message from my personal email account to my friend, and make the email message appear as if it was sent from “president@whitehouse .gov”. This can be easily done by just changing the "From" address of the email message. So, it doesn't mean that an email message was sent from someone because their email address appears in the "From" address line of the message.

Now, because of this, unexpected email messages with a compressed or Zip file attached should never be opened, regardless of who they appear to have been sent from.

Also, click here for a list of email attachments that you should never open, regardless of who the email message appears to have been sent from.

Now, if you have received one of the fake email messages and have opened the malicious attachment, please do a full scan of your computer with the antivirus software installed on it. If you don’t have antivirus software installed on your computer, please click here for a list of free antivirus software.

Check the comment section below for additional information, share what you know, or ask a question about this article by leaving a comment below. And, to quickly find answers to your questions, use our search engine.Search
Write commentWrite your comment or view the ones below.    +
Was this article helpful?
Advertisements - Continue reading below
Comments, Answers, Reviews or Questions
To protect your privacy, please remove sensitive or identifiable information from your comments, questions, or reviews. Please keep conversations courteous and on-topic.

Comments(27)

Jan. 5, 2021 at 8:58 PM by
Fake Emails with a Malicious Zip File Attached that Contains a Virus
an anonymous user from: Downtown Redmond, Redmond, Washington, United States

What if the file was attempted to be opened on an iPhone?

Delete

Jan. 5, 2021 at 9:38 PM by
Fake Emails with a Malicious Zip File Attached that Contains a Virus
info

The files are used to target Windows computers, not Apple iOS that your iPhone uses, therefore, your phone will not get infected.

Delete

Mar. 4, 2019 at 8:32 AM by
Fake Emails with a Malicious Zip File Attached that Contains a Virus
info

Here is another scam:

"PO / New Order

Mon 04/03/2019 09:24

From: "Skylite Royal Group"

To: Recipients

Attachments1

Please find attached PO copy for subject mentioned Order.

Regards,

Skylite Royal Group"

Delete

Jun. 23, 2017 at 12:04 AM by
Fake Emails with a Malicious Zip File Attached that Contains a Virus
info

Here is another malicious email:

"PO#1036-1

Thu 22/06/2017 23:44

From: Joselito

To: undisclosed-recipients:

-

Good day.

Kindly find the attached our Company official PO#1036-1 dated:22-06-2017 and please confirm on receipts.

I will send the swift copy of payment once I received the message from our bank.

Note: we will make PO for the item 29-34 once you confirm the availability. ( awaiting for your quotation.)

Thanks’

Joselito"

Delete

Jan. 8, 2017 at 12:33 AM by
Fake Emails with a Malicious Zip File Attached that Contains a Virus
an anonymous user from: Mesa, Arizona, United States

Here's a couple we got over the holidays:

FedEx Priority Solutions <bradley.byrd@walkingthemedicinewheel.com>

To: [deleted]

Parcel #00965297 shipment problem, please review

Dear Customer,

We can not deliver your parcel arrived at December 25.

You can find more details in this e-mail attachment!

With gratitude,

Bradley Byrd,

Office Clerk.

Delivery-Receipt-00965[#].zip

- - -

USPS Ground Support <lee.cunningham@lassalinas.es>

To: [deleted]

Notification status of your delivery (USPS 0934#)

Dear Customer,

We can not deliver your parcel arrived at December 15.

Please check the attachment for details!

Yours sincerely,

Lee Cunningham,

USPS Senior Office Manager.

Delivery-Receipt-0934[#].zip

Delete

Sep. 29, 2016 at 10:05 AM by
Fake Emails with a Malicious Zip File Attached that Contains a Virus
info

Here is another malicious email message that should be deleted if received:

"Subject: Temporarily blocked

From: Kelly Conrad (Conrad.415@constructionlawseminars.com)

Sent: Thu 9/29/16 9:02 AM

Attachment: debit_card_37763763.zip (11.0 KB)

Dear info,

this is to inform you that your Debit Card is temporarily blocked as there were unknown transactions made today.

We attached the scan of transactions. Please confirm whether you made these transactions.

King regards,

Kelly Conrad

Technical Manager - Online Banking

e-mail: Conrad.415@constructionlawseminars.com"

Delete

Sep. 29, 2016 at 8:39 AM by
Fake Emails with a Malicious Zip File Attached that Contains a Virus
info

Here is another malicious email message:

"From: Marcella Gibson (Gibson.533@pldt.net)

Sent: Wed 9/28/16 9:19 PM

Attachment: contract_scan_9727a6f53.zip (10.7 KB)

Dear, thanks for working with us.

We are sending the contract that we agreed on last week.

Please read through the attachment and return us the scan of the signed contract.

King regards,

Marcella Gibson

Managing Director

e-mail: Gibson.533@pldt.net"

Delete

Sep. 28, 2016 at 9:31 AM by
Fake Emails with a Malicious Zip File Attached that Contains a Virus
info

Here is another malicious email message:

"From: Gregg Reeves (Reeves.57@wellchosenwords.biz)

Sent: Wed 9/28/16 7:50 AM

Attachment: proposal_form_2d3dc889.zip

Dear,

You are receiving this email because the company has assigned you as part of the approval team.

Please review the attached proposal form and make your approval decision.

If you have any problem regarding the submission, please contact Charmaine.

Best regards,

Gregg Reeves

Head of Finance UKGI Planning"

Delete

Sep. 25, 2016 at 9:45 AM by
Fake Emails with a Malicious Zip File Attached that Contains a Virus
info

Here is another malicious email:

"From: Global Service Exchange <no_replay@idmsa-gsx-support.com>

Subject: Your Apple ID has been locked for security reasons

Date: Sun 9/25/16 7:36 AM

Attachment: Case ID_1000531542.zip

Your Apple ID has been locked for security reasons.

Dear user,

You must unlock your account before signing in please download attached file in email .

Your Case ID: 1000531542

Apple Support"

Delete

Sep. 22, 2016 at 7:11 PM by
Fake Emails with a Malicious Zip File Attached that Contains a Virus
info

Here is another malicious email:

"From: Corina Dunn (Dunn.168@avertex.com)

Sent: Thu 9/22/16 5:25 PM

Attachment: 34bbdfd04ad.zip (11.0 KB)

Dear info, thank you very much for your order!

Total amount of $354.57 was charged for your order #D-1732005.

All the details are in the attachment. Delivery will arrive at 15:00 coming Monday."

Delete

Sep. 22, 2016 at 7:42 AM by
Fake Emails with a Malicious Zip File Attached that Contains a Virus
info

Here is another malicious email:

"From: Mona wilson-barkworth <Mona.wilson-barkworth041@irec.se>

Subject: Receipt of payment

Date: Wed 9/21/16 9:58 PM

Attachment: Receipt.zip (7.8 KB)

Good afternoon,

Thank you for you call this afternoon.

Please find attached your receipt of payment.

If you need anything else please feel free to contact me on the details below.

Kind regards.

Mona wilson-barkworth

Credit Controller

IB GIBL Credit Control"

Delete

Advertisements - Continue reading below

waiting
Write Your Comment, Answer, Review or Question

Advertisements - Continue reading below
Advertisements - Continue reading below
Advertisements - Continue reading below
Advertisements - Continue reading below
Advertisements - Continue reading below
Advertisements - Continue reading below
Advertisements - Continue reading below
Advertisements - Continue reading below
Fake Emails with a Malicious Zip File Attached that Contains a Virus