.. /.Bz2

Phishing
Double Click
File Archiver

Contributors:

Adithya - @arvooriadithya

Description:

Compressed archive created by bzip2, a file compression program often found on Unix-based systems; incorporates the Burrows-Wheeler compression algorithm as well as Run-Length Encoding (RLE) for high levels of compression; often used for Linux software package distributions. Same could be opened on Windows machines via compression software like Winrar, 7-Zip etc., These archive file types can contain malicious files.

OS:

Windows
Linux
Mac

Recommendation:

After validating business usage, monitor & block the download and execution of bz2 archive files on email & web gateways and endpoints . Whitelist as required.

Resources:

File Samples:

https://any.run/report/c0d3574a4c99d94a21fdce3ff06f1186ef8980372320fa45603fc10f2dd496a5/2e49ea5f-1e86-4de6-9c5c-f9e5e2d10c08
https://bazaar.abuse.ch/sample/11480cf5c47c57040f917412a67d741bd7827ebe3c35779ab90199b4ab6280b8/