These files often contain executables masquerading as shipping documents (e.g., DhL-FINAL SHIPING DOCUMENTS.exe ). Common payloads include:
The emails delivering "DHL.zip" typically use the following social engineering tactics: DHL Delivery problem NR 3H6JZBN scam email - Kenkai
Analysis of similar "DHL.zip" or related archive attachments has identified several serious threats:
The malware often includes "anti-analysis" features to detect if it is being run in a sandbox or virtual machine, allowing it to hide from some basic antivirus checks. Typical Scam Characteristics