ZIP With Comment

Published: 2016-11-21
Last Updated: 2016-11-22 19:51:51 UTC
by Didier Stevens (Version: 1)
14 comment(s)

I got hold of a malicious document e-mailed inside a password protected ZIP file.

This time I'm not going to write about the maldoc, but about the ZIP file. The password for the ZIP file was mentioned with instructions in the e-mail spammed to many recipients. Obviously this is done in an attempt to bypass detection by e-mail scanners, but with the hope that the recipients would follow the instructions and provide the password when the ZIP application asks for it.

Now I'm coming to the point: this ZIP file also contained a comment that mentioned the password:

And I hope you can help me with my question: what Windows application does display the ZIP comment by default when a ZIP file is opened?

I tried Windows Explorer, WinZip and 7-Zip, but without success.

If you have an idea, please post a comment.

Update: WinRAR displays comments by default.

Didier Stevens
Microsoft MVP Consumer Security
blog.DidierStevens.com DidierStevensLabs.com
NVISO

Keywords: comment ZIP
14 comment(s)
ISC Stormcast For Tuesday, November 22nd 2016 https://isc.sans.edu/podcastdetail.html?id=5263
ISC Stormcast For Monday, November 21st 2016 https://isc.sans.edu/podcastdetail.html?id=5261

Comments


Diary Archives