How to Scan Zip Files for Malware Threats | Votiro (2024)

Antivirus solutions and antivirus scanning is the status quo for preventing malware in files. Hackers realize this and have developed techniques for concealing viruses and other malware in complex compound files, such as zip files and archives. While zip files are not inherently dangerous, they have become a favorite format for cybercriminals running phishing campaigns, injecting ransomware, and deploying other malicious actions to unleash malware on unsuspecting individuals.

This article discusses why zip files make excellent vectors for hiding malicious code, reviews how to scan a zip file for viruses and malware threats, why existing detection-based solutions are falling behind, and provides an overview of how content disarm and reconstruction prevents evasive malware in zip files.

Why Hackers Love Zip Files

Zip files have been “zipped” or compressed to reduce their size. Once you create a .zip file, you must “unzip” or extract the files within before accessing them.

These zipped, or archived files present a challenge for reliable threat detection. That’s because scanning a zip file might not show that infected or suspicious files exist within it because of the threats hidden within layers of the archive. Detecting viruses and other malware hidden in a zip file requires first unpacking the archived file. Antivirus solutions often don’t unzip files, and therefore malicious zip files pass by undetected.

Why isn’t antivirus software effective against zip files?

Antivirus software continuously checks a repository of known malware signatures to identify suspicious or malicious files to quarantine or destroy them before they can cause damage.

Zip files are usually an enigma to AV

Some antivirus software can scan zip files, not all antivirus products are created equal:

  • Some antivirus software can temporarily decompress the zip files and scan the contents.
  • Most AV vendors can only scan the file contents once the files have been fully extracted – zipped files are essentially “unscannable” and unprotected by AV.

Only protecting against known signatures

In addition, even the antivirus softwares that are able to unzip a file can only protect against known threats. Security teams must regularly update software versions, and the software vendor must maintain a current library of malware signatures. It is almost impossible for antivirus software to keep up with the ever-changing risk surface that includes unknown threats and zero-day exploits that can weaponize zip files. Read here an example of how hackers hid malicious code in a password-protected and encrypted zip file that traditional malware scanners deemed “unscannable.”

AI/ML = high volumes of false positives

Lastly, as antivirus software becomes more sophisticated and attempts to identify unknown and never-before-seen malware using AI or machine learning, it commonly returns a high volume of false positives, disrupting business productivity and wasting users’ time.

Reduced business productivity

When organizations use a blocklist for zip files, it is disruptive to IT admins who regularly must go in and recover files that were expected but auto-blocked, adding additional overhead to their job. In addition, blocklisting creates disruptions for end users who are expecting files from third parties, like partners and customers and need to address them quickly, rather than waiting for it to be unblocked by IT.

Scanning Zip Files Today

There are two approaches to dealing with hidden threats in zip files. One way requires making manual configuration changes to harden endpoints against these threats, while the other uses automated analysis and content disarm and reconstruction to eliminate threats.

Legacy tips to scan zip files for viruses to protect yourself

One approach to managing hidden threats in zip files is to improve each endpoint to be more secure and scan files and emails automatically. The following are some steps you can take to help protect yourself from viruses and malware that may hide in zip files:

  1. Update WinZip – Ensure you are running the latest version of WinZip, as it includes critical security-related fixes and enhancements.
  2. Update your antivirus program – Having the latest definitions is crucial for keeping updated with the latest signatures. Researchers discover new malware daily, and the latest signatures will have the most current discoveries but may still miss Zero Day threats.
  3. Configure your antivirus – Adjust the program to scan ALL files and emails, quarantining any suspected infected messages.
  4. Disable “hidden file name extensions” This stops Windows from concealing file name extensions such as .EXE, .DOC, and .ZIP or other file types it recognizes. For example, a malicious invoice.jpg.zip may appear as invoice.jpg, concealing that it is a zip file that could be harmful when opened.
  5. Add a Password – Protecting zip files by applying a password makes them more challenging for cybercriminals to alter. In Windows, Right-click the zip file, select Send to, then Zip folder (compressed). Follow the prompts to save the folder.
  6. Establish Best Practices – Never open a zip file attached to an email from an unknown source, or download a zip file from untrusted websites. Of course, that might not be possible with your line of work, or may slow things down quite a bit!

While this process is effective for protecting yourself against viruses, it is also a time-consuming and manual approach. It does not scale well to protect multiple users. Modern organizations require a more automated approach that is fast and efficient with the ability to scale for multiple users.

Sanitizing Files with Content Disarm & Reconstruction Technology

Just because your organization currently lacks sufficient protection against all hidden threats in zip files does not mean you must remain unprotected. Votiro takes care of pesky number 4 in the list above: Disable “hidden file name extensions”. The first step to sanitize files with Votiro is to TrueType the file. Hidden extensions and purposely obfuscated files will be analyzed and corrected to their actual extension.

Votiro is an API that integrates seamlessly with your existing environment. Rather than having users take steps they could forget when sanitizing a file, as files pass through organizational boundaries, they are sanitized and cleansed of malware automatically, ensuring that content is always safe to use, share, edit, download, and access. Request your 30-day free trial today.

How Votiro Combats the Threat to Zip Files

The only tried-and-true way to stop weaponized zip files from penetrating your network is by taking a zero-trust approach to files – including zip files. With Votiro, every file element passes through a file sanitization process. Files are deconstructed and rebuilt from only trusted parts known to be safe, eliminating any malicious content in the process. The new file is rebuilt with all of the safe functionality of the original but without hidden threats.

To learn more about implementing Votiro’s patented file sanitization technology to secure your network against malicious zip files and other threats, please schedule a demo today.

How to Scan Zip Files for Malware Threats | Votiro (2024)

FAQs

How to scan a zip file for malware? ›

You can do this by right-clicking on the zip file and selecting "Extract Here," or by using file archiving software such as WinZip. Right-click on the folder containing the extracted files and select "Scan with [name of your antivirus software]" from the context menu.

Can malware be found in zip files? ›

While zip files are not inherently dangerous, they have become a favorite format for cybercriminals running phishing campaigns, injecting ransomware, and deploying other malicious actions to unleash malware on unsuspecting individuals.

How can I scan a file for malware? ›

Run a malware scan manually

If you're worried about a specific file or folder on your local device, you can right-click the file or folder in File Explorer, then select Scan with Microsoft Defender.

Can Windows Security scan zip files? ›

Windows Defender does real-time scans on all files downloaded through Microsoft Edge at the time of download and routinely scans the Downloads folders for new files to scan regardless of how they got there. It scans . zip, . rar, and .

How do I verify a zip file? ›

To access the test function, open the Unzip tab (the Zip pane must be the active pane). Click the top part of the Diagnostics button to test the Zip file and view a summary report. To receive a more detailed report, click on the bottom half of the Diagnostics button and click Detailed on the dropdown menu.

Does a Virus scan pick up malware? ›

Although details may vary between packages, anti-virus software scans files or your computer's memory for certain patterns that may indicate the presence of malicious software (i.e., malware).

Are zip files easily corrupted? ›

Damaged data can affect the entire Zip file, multiple member files, or just one member file. There are many possible causes for data damage. Among the most common is a transfer error when downloading a Zip file from the internet. Such an error can introduce invalid data into a Zip file.

Is 7zip trustworthy? ›

7-zip is generally considered safe to use. It has been widely used for many years, and its source code has been reviewed by security experts due to its open-source nature. However, like any software, it's important to download it from trusted sources and keep it up to date to minimize any potential security risks.

Can Norton scan zip files? ›

Scan files with antivirus software like Norton 360 Deluxe before you unzip them to help detect threats like zip bombs and other types of malware.

What is the free tool to scan for malware? ›

The easiest way to remove malware from your Windows PC is to use a free virus removal tool like Avast One, which scans for and removes existing malware, as well as prevents future infections. Avast One is compatible with all devices, so you can scan for, detect, and remove malware on Mac, iPhone, and Android too.

How do I scan for hidden malware? ›

Open your Windows Security settings. Select Virus & threat protection > Scan options. Select Microsoft Defender Antivirus (offline scan), and then select Scan now.

Can you scan a file for viruses before downloading it? ›

Check Files Before Downloading Them Using an Online Scanner Such As VirusTotal. VirusTotal is one of the most accurate and closest to real-time analyzers of files, URLs, domains, and IP addresses on the web. It's a free and easy-to-use tool that doesn't require you to download anything.

How do I check for malware on a zip file? ›

Check the file extension

Look at the file extension of the file inside the zip folder. If it's an executable file, such as .exe or . bat, be cautious as these types of files are commonly used for malware. Threat actors may sometimes hide the fact that a file is an executable.

Does VirusTotal scan zip files? ›

The currently supported file types are Microsoft Office Files, PDFs, HTMLs, HTMs, LNKs, JScripts, ISOs, IMGs, VHDs, VCFs, and archives(. zip, . rar, . 7z etc.).

Can Malwarebytes scan zip files? ›

Scan within archives: When enabled, Malwarebytes scans two levels deep within archive zip, rar, 7z, cab and msi files. If disabled, archives are excluded from scans. By default, this setting is On.

Can a zip file get corrupted? ›

Another major reason behind a corrupted ZIP file is during the downloading process. There are several circ*mstances where some unreadable data gets attached to the ZIP file, making it hard for the program to extract the data.

Does WinZip scan for viruses? ›

If you click "Scan for Threats", assuming you have one of the following anti-virus applications installed, WinZip will then tell you if you have any files infected with a virus or malware.

How do I scan and remove malware? ›

How to remove malware from a PC
  1. Step 1: Disconnect from the internet. ...
  2. Step 2: Enter safe mode. ...
  3. Step 3: Check your activity monitor for malicious applications. ...
  4. Step 4: Run a malware scanner. ...
  5. Step 5: Fix your web browser. ...
  6. Step 6: Clear your cache.

Is 7 zip malware? ›

Both 7-Zip and WinRAR have an expansive number of malicious opportunities. Two options allow attackers to set a password on the archive or delete files after archiving. These two weaponization strategies make both applications fully functional Ransomware Encryptors.

Top Articles
Marie Forleo's Everything Is Figureoutable Review: 10 Top Lessons - Finance Over Fifty
Best Ways to Financially Prepare for a Baby
Tiffany's Breakfast Portage
Home Store On Summer
Renfield Showtimes Near Amc Kent Station 14
Www Craigslist Com Wisconsin Milwaukee
Survivor Australia Wiki
Amazon Ups Drop Off Locations Near Me
Dr. med. Dupont, Allgemeinmediziner in Aachen
Cvs Tb Testing Cost
Find The Eagle Hunter High To The East
National Weather Service Monterey
Cooktopcove Com
Websites erstellen, benennen, kopieren oder löschen
Mr Seconds Geneseo Ny
Huniepop Jessie Questions And Answers
라이키 유출
Ck3 Diplomatic Range
Staffing crisis: Restaurants struggle to find help in Orange County
Costco Gas Price City Of Industry
Review: 'Letters From Iwo Jima' a masterpiece - CNN.com
Scrap Metal Prices in Indiana, Pennsylvania Scrap Price Index,United States Scrap Yards
Nicolas Alexander Portobanco
Realidades 2 Workbook Answer Key
Walgreens Pharmacy | Manage Prescriptions, Transfers, and Refills
Craigslist.nashville
FirstLight Power to Acquire Leading Canadian Renewable Operator and Developer Hydromega Services Inc. - FirstLight
Costco Gas Price Fort Lauderdale
Taylorsince1909
Nenas Spa San Salvador
South Park Old Fashioned Gif
Sam's Club Stafford Gas Price
Persona 5 R Fusion Calculator
Www Muslima Com
Waive Upgrade Fee
Odawa Hypixel
8662183887
How To Use DeSmuME Emulator To Play Nintendo DS Games?
Sep Latest Version
Kutty Com Movies
Doublelist Aiken Sc
Kytty_Keeet
California wildfires: Bridge Fire explodes in size; man arrested in connection with Line Fire
Rydell on LinkedIn: STARTING TODAY you no longer have to wait in a long line to get your oil…
Ap Bio Unit 2 Progress Check Mcq
Hexanaut.io – Jouez en ligne sur Coolmath Games
Ucla Football 247
Portmanteau Structure Built With Cans
Buzzn Dispensary
Chase Bank Time Hours
Dean Dome Seating Chart With Rows And Seat Numbers
Corn-Croquant Dragées 43%
Latest Posts
Article information

Author: Msgr. Refugio Daniel

Last Updated:

Views: 5975

Rating: 4.3 / 5 (74 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: Msgr. Refugio Daniel

Birthday: 1999-09-15

Address: 8416 Beatty Center, Derekfort, VA 72092-0500

Phone: +6838967160603

Job: Mining Executive

Hobby: Woodworking, Knitting, Fishing, Coffee roasting, Kayaking, Horseback riding, Kite flying

Introduction: My name is Msgr. Refugio Daniel, I am a fine, precious, encouraging, calm, glamorous, vivacious, friendly person who loves writing and wants to share my knowledge and understanding with you.