ATTACHMENTS · MACROS · MALWARE
How to analyse a suspicious file before opening it: a cyber safety guide
A PDF invoice, Word document or ZIP archive may accompany an email impersonating a supplier or official organisation. Some attachments try to make you run a program, enable a macro or exploit a vulnerability to install ransomware or a Trojan. A click does not automatically cause an infection, but opening a doubtful file “to see” needlessly exposes your device.
Here is a method to analyse a suspicious file before opening it: recognise misleading presentation, understand technical checks and know when to involve support.
1. Identify extensions and misleading presentation
Double extensions
A name such as Facture_2026.pdf.exe ends in .exe: it identifies an executable even though “PDF” appears in the name. When known extensions are hidden, the display can be misleading. Show extensions in your file manager and do not trust the icon alone. Do not run an unexpected executable.
ZIP, RAR and 7z archives
An archive can contain an unexpected program or script. A password may prevent some automated checks from accessing its contents. Protected archives also have legitimate uses: their presence is not proof of fraud, but an unexpected archive requires verification of its origin.
Macro-enabled documents
Formats such as .docm and .xlsm can contain macros. A request to “Enable content” or “Enable macros” in an unexpected document is a warning sign. Not all macros are malicious; however, never enable them under pressure from a message, and ask your IT team to validate the need.
2. How does technical attachment analysis work?
A suspicious file checker uses static analysis to examine accessible characteristics without running the document. This helps identify indicators before opening, with limitations depending on the format and sources.
Detected format and extension
Static analysis examines format signatures, sometimes called “magic numbers”, and accessible file characteristics. A mismatch with the extension may reveal a disguised file. Some formats share a container structure: this check provides evidence, not a complete assurance of safety.
SHA-256 fingerprint and reputation
A SHA-256 fingerprint enables an exact-match lookup for a previously catalogued file. SecurCheck calculates it and queries MalwareBazaar when configured and available. A modified file generally has a different fingerprint. No match only means that the fingerprint was not found in the queried source, not that the file is safe.
Structural indicators
Checks look for accessible scripts, macros and archive indicators without executing the contents. Encryption, some formats and obfuscation can limit what is observable. The report distinguishes detected signals from unavailable sources and does not replace endpoint antivirus or EDR protection.
Help employees check before opening
A fake invoice can lead to compromise and, depending on access and protections, affect other systems. SecurCheck Business gives your team a practical way to perform an online file scan and identify signals to report to support.
Analysis complements your antivirus, EDR and internal procedures. Timing depends on the file and available sources; it does not automatically block every infection.
Explore our Business offer for protecting your devices3. Three rules for a suspicious document
Do not open or redistribute it
Do not run the file or send it to a colleague to test. Preserve the message context and avoid further handling while waiting for support instructions.
Confirm the delivery through another channel
Call the supposed sender on an established number or use your usual internal messaging channel. Do not use contact details added to the suspicious message. Even a familiar email address may have been compromised.
Report using your organisation’s procedure
Alert your IT or security team with the context, filename and receipt time. Use the reporting button or designated channel for suspicious messages. Only transfer the attachment if IT requests it, using the secure method they specify.
Already opened or run the file? Alert IT immediately and follow the procedure for your situation.
Open the “I clicked — what now?” assistantBreak the pressure before clicking
Urgent requests exploit curiosity and administrative routines. Taking time to confirm the origin, perform appropriate attachment checks and involve IT reduces risk. This habit complements layered protection; it is not an infallible safety net.
Related: how to analyse the email accompanying the file