Online Threat Alerts (OTA)
An anti-cybercrime community alerting the public.

.TAR Malicious Email Attachments

Online users who have received unexpected email messages with attached files with names ending with ".tar" are asked not to open them. This is because the attachments are encoded files that may contain malware, malicious programs or viruses. And, any attempt to open the malicious attachments will result in the recipients getting their computers infected with a virus, Trojan horse, spyware, ransomware or other malware.

Advertisements

A Sample of a Malicious ".TAR" Email Message

Swift copy of payment

Thu 3/14/2019 1:42 PM

From: "Accounts officer"

Attachment: Payment.tar (127 KB)

Good Day,

Be informed that we have made the advance payment.

Kindly find the attached swift copy of payment made this morning.

Kindly do the needful.

Thanks

Sarah Cline

Accounts officer

FAZ GENERAL TRADING

Mobile: +966 50 352 7781

Cybercriminals usually store their malware in compressed or '.TAR' files to help prevent antivirus software from detecting them. In other words, they do it because the compressed or encoded malicious email attachments may bypass the recipients' antivirus software.

What is a .TAR file?

Short for Tape Archive, and sometimes referred to as tarball, a file that has the TAR file extension is a file in the Consolidated Unix Archive format.

The TAR file format is common in Linux and Unix systems, but only for storing data, not compressing it. TAR files are often compressed after being created, but those become TGZ files, using the TGZ, TAR.GZ, or GZ extension.

Check the comment section for additional information, or share what you know or ask a question about this article, by clicking the 'View or Write Comment' button below.

Note: Some of the information in samples on this website may have been impersonated or spoofed.

Share this article with others.
Advertisements
Write / View Comments (0)
View on Online Threat Alerts (OTA)
Help Maintain Online Threat Alerts (OTA)