Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: InfoSec Handlers Diary Blog InfoSec Handlers Diary Blog


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

ZIP With Comment

Published: 2016-11-21
Last Updated: 2016-11-22 19:51:51 UTC
by Didier Stevens (Version: 1)
14 comment(s)

I got hold of a malicious document e-mailed inside a password protected ZIP file.

This time I'm not going to write about the maldoc, but about the ZIP file. The password for the ZIP file was mentioned with instructions in the e-mail spammed to many recipients. Obviously this is done in an attempt to bypass detection by e-mail scanners, but with the hope that the recipients would follow the instructions and provide the password when the ZIP application asks for it.

Now I'm coming to the point: this ZIP file also contained a comment that mentioned the password:

And I hope you can help me with my question: what Windows application does display the ZIP comment by default when a ZIP file is opened?

I tried Windows Explorer, WinZip and 7-Zip, but without success.

If you have an idea, please post a comment.

Update: WinRAR displays comments by default.

Didier Stevens
Microsoft MVP Consumer Security
blog.DidierStevens.com DidierStevensLabs.com
NVISO

Keywords: comment ZIP
14 comment(s)
Diary Archives