You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A feature to attempt to unzip password protected files using a known list of password, or a password that could be extracted from the message, would be interesting. I'm seeing a recent wave of malware that is being spread using password protected ZIPs, which I block by default, but then I go through and have to determine if it is a legitimate message, if there is a password in the message that could be used to scan the file, etc. From what I've seen, a significant number of these malicious password protected ZIPs use the same or limited set of passwords (though I expect that to change as things often do).
Just brainstorming, but it might be a useful function in some cases/environments.
The text was updated successfully, but these errors were encountered:
This is an interesting idea, especially considering the malicious actor would need to supply the password, which is typically done in the message itself.
A feature to attempt to unzip password protected files using a known list of password, or a password that could be extracted from the message, would be interesting. I'm seeing a recent wave of malware that is being spread using password protected ZIPs, which I block by default, but then I go through and have to determine if it is a legitimate message, if there is a password in the message that could be used to scan the file, etc. From what I've seen, a significant number of these malicious password protected ZIPs use the same or limited set of passwords (though I expect that to change as things often do).
Just brainstorming, but it might be a useful function in some cases/environments.
The text was updated successfully, but these errors were encountered: