ZIP With Comment
I got hold of a malicious document e-mailed inside a password protected ZIP file.
This time I'm not going to write about the maldoc, but about the ZIP file. The password for the ZIP file was mentioned with instructions in the e-mail spammed to many recipients. Obviously this is done in an attempt to bypass detection by e-mail scanners, but with the hope that the recipients would follow the instructions and provide the password when the ZIP application asks for it.
Now I'm coming to the point: this ZIP file also contained a comment that mentioned the password:
And I hope you can help me with my question: what Windows application does display the ZIP comment by default when a ZIP file is opened?
I tried Windows Explorer, WinZip and 7-Zip, but without success.
If you have an idea, please post a comment.
Update: WinRAR displays comments by default.
Didier Stevens
Microsoft MVP Consumer Security
blog.DidierStevens.com DidierStevensLabs.com
NVISO
Comments
Anonymous
Nov 21st 2016
8 years ago
I think it's because you are referring to a comment associated with the embedded file, while in this sample it is a comment associated with the ZIP archive, not with a particular file inside the ZIP file.
Anonymous
Nov 21st 2016
8 years ago
Anonymous
Nov 21st 2016
8 years ago
In WinZip 21.0, Settings -> WinZip Options -> Advanced -> File Handling -> Show comments when opening Zip files
In WinRAR 5.31, Settings -> General -> Show archive comment
Anonymous
Nov 21st 2016
8 years ago
Anonymous
Nov 21st 2016
8 years ago
Anonymous
Nov 21st 2016
8 years ago
winrar does.
Anonymous
Nov 21st 2016
8 years ago
http://www.peazip.org
Anonymous
Nov 21st 2016
8 years ago
Could it just be an artefact from the malware generation process?
Anonymous
Nov 21st 2016
8 years ago
Anonymous
Nov 22nd 2016
7 years ago