• Branquinho@lemmy.eco.br
      link
      fedilink
      English
      arrow-up
      2
      ·
      20 hours ago

      It’s something called ADS (Alternate Data Stream) which you can see as some kind of second hidden file content. Browsers create an ADS with name Zone.Identifier when downloading a file and attach it to the downloaded file. The content of the ADS is the information where the file was downloaded from, i.e. the Zone (3 for Internet) and usually the URL.

      Programs and Windows usually use the existence of the Zone.Identifier to show you a warning that a file was downloaded and may pose a risk to your system when opening/exexuting it.

  • Alphane Moon@lemmy.worldOP
    link
    fedilink
    English
    arrow-up
    4
    ·
    1 day ago

    I once got a really nasty cryptominer that shut down all attempt to remove it via a fully patched WinRar opening an archive with what seemed to mostly JPEGs (maybe some PDFs as well). Perhaps this vulnerablility the root enabler of the cryptominer.