Phishing
Double Click
File Archiver
Contributors:
Adithya - @arvooriadithya
Description:
Compressed archive created by bzip2, a file compression program often found on Unix-based systems; incorporates the Burrows-Wheeler compression algorithm as well as Run-Length Encoding (RLE) for high levels of compression; often used for Linux software package distributions. Same could be opened on Windows machines via compression software like Winrar, 7-Zip etc., These archive file types can contain malicious files.
OS:
Windows
Linux
Mac
Recommendation:
After validating business usage, monitor & block the download and execution of bz2 archive files on email & web gateways and endpoints . Whitelist as required.
Resources:
File Samples: