CYBER WELFARE

Protect your Digital Privacy

Signs of a dangerous attachment: how to spot one before and after you open it

A dangerous attachment rarely looks threatening. It is called “Invoice”, “Quote” or “Delivery notice”, it comes with a polite message and it looks exactly like a file you might be expecting. The difference lies in a few details: what the file is really called, what kind of file it actually is, who sent it and what it asks you to do once it is open.

This post brings together the signs of a dangerous attachment: what they mean, where you can see them and what to do when you find one. In technical circles they are called indicators of compromise, or IOCs (Indicators of Compromise). Here we use them at two moments: before you open a file, to decide not to, and after you have opened it, to notice in time that something has gone wrong.

It is the diagnostic deep dive on the recommendation about not opening unknown attachments: not opening what you were not expecting is the prevention; recognising the signs helps you tell when a file deserves a second thought, even when it comes from someone you know.

What the signs of a dangerous attachment are

A sign, or indicator, is an observable detail suggesting that a file may not be what it claims to be. The real risk is malware: harmful software that can steal data, spy on what you do or lock up your documents.

A sign is not proof. It is a reason to stop and check, through a different channel from the one the file arrived on: a phone call, or a message on another app. It may have a harmless explanation, or it may point to an attempt to infect your device.

The value of these signs lies in timing: spotting them before you open a file means there is nothing to fix; spotting them straight after means you can step in before the problem spreads.

Why they matter more when the attachment is unexpected

A file you asked for has a context: you know what to expect and you notice if something does not add up. An unexpected file only has the context of the message that comes with it, and that is exactly what the person who prepared it can make up.

What is more, attachments no longer arrive only by email: they also turn up in chats and in messages on social networks. And they come from people you know, when their account has been taken over and used to write to everyone in their contacts. It can happen to you too, as we explain in the recommendation on messages sent in your name.

Finally, an attachment you have downloaded is already on your device. That is why the signs you see before opening it are worth more than the ones you will see afterwards.

Technical indicators: before you open

These are the details you can see in the message and in the file itself, without opening it. First, four terms: the file extension is the last part of a file’s name, after the final full stop (“.pdf”, “.jpg”), and it tells the system which program to open it with; a macro is a small set of automatic instructions contained in some documents; a compressed archive is a file that holds other files, usually a “.zip”; the domain is the part of an email address after the @ sign.

IndicatorWhat it meansWhy it mattersWhere you see itWhat to do
Double extensionThe name ends with two extensions, for example “invoice.pdf.exe”Only the last one counts: what looks like a document is actually a programIn the file’s full name, with extensions made visibleDo not open it; ask the sender, on another channel, what they sent you
Unusual extension for a documentAn “invoice” with extensions such as .exe, .scr, .js, .iso or .lnkThese formats run instructions or contain other filesIn the list of attachments or in your downloadsDo not open it; a genuine document almost always comes in a common format
Password-protected archive, with the password in the messageThe compressed file is locked with a password written in the same messageIt protects nothing: its purpose is to stop email filters from inspecting the contentsIn the body of the message, often “for confidentiality reasons”Do not open it; it is one of the most reliable signs
A request to enable macros or “enable content”You are told you will need to switch something on to see the documentMacros are a common way to launch harmful software from a documentIn the email text or inside the documentDo not enable anything; ordinary documents can be read without switching anything on
Odd sender or domainThe address does not match the display name, or imitates a company’sPeople sending malicious files often pose as a supplier, a courier or a public officeBy tapping the sender’s name to see the full addressCheck through a channel you already know
Unannounced attachmentA file nobody told you to expect, even from a contact you knowIt is the sign that almost all malicious messages have in commonBy asking yourself: did I ask for this? Am I expecting a parcel?Ask for confirmation on another channel before opening it
Attachment that points to an online fileThe document only contains a “View” button that opens a sign-in pageIts purpose is to collect your email or cloud storage passwordIn the file previewDo not enter any credentials; sign in from your bookmark or the official app

Signs you can observe yourself: after opening

If the file has already been opened, many signs show up in the first few seconds or over the following days, simply by using your computer or phone as normal.

SignalWhat it meansWhy it mattersHow you noticeWhat to do
A blank or blurred document asking you to “enable” somethingThe file shows nothing but a prompt to switch on content or editingThere is no “real” content: the request is the file’s only purposeA white page and a bar with an “Enable” buttonClose it without enabling anything and delete the file
Pop-ups that open and close straight awayA pop-up, often black, appears for a split secondThe file may have started instructions in the backgroundA flash on the screen right after openingDisconnect the device from the network and follow the recovery steps
The file “won’t open” or shows an errorA generic error appears, or nothing happens at allSome malicious files fake an error while they get to work“File damaged” on a document you were expectingDo not try again; treat it as a file that has been opened
Sudden slowdownsThe device is sluggish, the fan runs even when it is idleIt may point to a hidden program at workIn everyday use, from the moment of openingA weak clue: read it together with the others
A password request after openingA page opens asking you to sign in to your email or another serviceIts purpose is to steal your credentialsA sign-in page you did not go looking forDo not enter anything; if you did, change the password from another device
Alerts from the system’s built-in protectionThe system reports that it has blocked or quarantined a fileThe automatic check has recognised something suspiciousSecurity notifications from the systemTake the alert seriously and do not restore the file
Files that change name or will not open any moreDocuments and photos with strange extensions and a demand for paymentIt is the sign of ransomware, malware that locks your files to demand a ransomIn your personal folders, often with an “instructions” fileDisconnect the device and get help before doing anything else
Contacts receiving strange messages from youPeople ask you about emails or files you never sentYour account may be spreading the same attachmentSomeone points it out to youChange the password from another device and let your contacts know

On a phone the signs are partly different, and we cover them in the recommendation on spotting the signs of malware on your phone.

A concrete example

Sarah has been waiting for a parcel for a few days. One morning she gets an email: “Missed delivery notice. The document with collection instructions is attached. For confidentiality reasons, the archive password is 2468.” Attached is a compressed file.

Sarah opens it. Inside is a file with a document icon; she opens that too, and the page is almost blank, with a line of text inviting her to enable content to read it. Sarah taps “Enable”. For a moment a black box flashes up, then nothing. She assumes the file is faulty and closes everything.

By the afternoon her laptop is slower than usual and the fan keeps running even when it is idle.

Reading the email again, the signs were all there: an unannounced attachment, an archive with the password written in the message, a document asking her to enable something. Each one, on its own, could have had an explanation; all three together were enough to stop. Sarah realises in time: she disconnects the laptop from the network and follows the steps, in order, without panicking.

What to check right away

Before opening an attachment

  • the sender’s full address, not just the display name;
  • whether the file was expected, and from whom;
  • the file’s full name, extension included;
  • whether it is a password-protected archive, and where the password is.

If you have already opened a doubtful attachment

  • whether the document asked you to enable macros or content, and whether you did;
  • whether pop-ups or sign-in pages opened that you did not go looking for;
  • whether you entered a password after opening it;
  • notifications from the system’s built-in protection.

Over the following days

  • the device’s speed and any unusual behaviour;
  • messages sent from your account that you do not recognise;
  • recent sign-ins to your main email account.

If you find a suspicious indicator

  1. Do not open the file, and if you already have, do not enable anything.
  2. Check with the sender on another channel: a phone call or a different app, never a reply to the same email.
  3. Report and delete the message using your email service’s reporting feature: it helps other users too.
  4. If you opened it and something seems off, disconnect the device from the network and do not type passwords on it until you have checked.
  5. Change your important passwords from another device, starting with your main email, if you entered any credentials.

The full sequence, with the steps in the right order, is in the post on what to do after opening a suspicious attachment. If you would rather understand the mechanisms that produce these signs, we explain them in the post on malware in email attachments.

What is not an indicator

Telling the difference helps you avoid two opposite mistakes: trusting details that guarantee nothing, and being suspicious of every file that arrives.

SituationWhy it is usually not a signal
A PDF or a photo from someone who told you it was comingA common format and an expected context are exactly what make an attachment normal
An archive from a colleague, with the password given in person or on another channelKeeping file and password apart is good practice
A “protected” or “read-only” bar at the top of a downloaded documentThe program opens files from the internet in read-only mode: it is a safeguard
A slowdown after opening a large documentIt only counts if it carries on or comes with other signs
A full-screen warning saying “your device is infected, call this number”It is not a symptom of infection: it is often another scam, designed to frighten you

There are also false signs of safety: a familiar contact’s name as the sender, a polished logo, a line such as “attachment scanned”. None of these, on its own, proves that a file is safe.

The rule of thumb: an unexpected attachment deserves a check; an unexpected attachment with even one technical indicator deserves to stay unopened.

When to run these checks

You do not need a demanding routine. You just need the habit to kick in at the right moments.

MomentWhat to check
Whenever an unexpected attachment arrivesSender, the file’s full name and extension, before you double-click
When a document asks you to enable somethingStop and close the file
When a password-protected archive arrivesWhere the password is: in the same message, it is a strong sign
In the days after opening a doubtful fileThe device’s speed, sent messages, sign-ins to your email
Once, todayMake file extensions visible and check that updates are switched on

Visible extensions are the simplest check in this whole post: once they are switched on, a “document.pdf.exe” can no longer hide. An up-to-date system also reduces the effect of many malicious attachments, as we explain in the recommendation on keeping your software up to date; and you can find out which checks your email service and your system already run for you in the post on how attachment scanning works.

Two important warnings

An indicator is not proof. A colleague may use an unusual format, a supplier may write from a new address, a computer may slow down for a hundred reasons. You do not need to be certain that a file is dangerous: it is enough not to open it until you have checked.

No indicators is not a guarantee. The most carefully made malicious files have a believable name, a common format and come from a contact you know. That is why protection rests on the habit described in the recommendation: what you were not expecting stays closed until you know who sent it and why. The signs help you stop; the habit means you do not have to guess. If the file comes with a request for personal details or a payment, the signs of a fake bank email apply as well.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
SkillsKnowing how to read a file’s full name and extension and recognise the formats that run instructions
AwarenessUnderstanding that an attachment can look like any ordinary document and still come from a familiar contact
Secure BehaviourChecking on another channel before opening, and never enabling content in an unexpected file

Reference level: FL2 — Beginner. This is the level at which you recognise the most common signs of a deceptive file and stop before opening it, even without knowing the technical details of how it was put together.

Conclusion

Spotting a dangerous attachment does not take specialist skills. It takes shifting your attention from how the message looks to three simple questions: was I expecting this, what kind of file is it really, and what is it asking me to do?

What to do right now. Open the folder settings on your computer and switch on file extensions. Then look at the last few attachments you downloaded: you will know what a normal file looks like, and it will be easier to notice one that is not. To see where you stand on the other aspects of your digital security too, you can take the digital resilience self-assessment.

Related resources

Short deep dives from the Resources section, for anyone who wants to focus on a single aspect:

Related content

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.