Skip to main content

What to do now

Suspicious email attachment: check the file before you open it

Last checked

Attachments are one of the most common ways viruses spread: an invoice you don’t recognise, a delivery notice, a shared document. Leave the file closed while you check.

Do this now

  1. Already opened it? Disconnect and scan

    On a work device, call your IT team first and follow their instructions. On your own device: disconnect it from the internet, run a full antivirus scan and change your passwords from another device.
  2. Otherwise, leave it closed

    Don’t open it, and don’t forward it to someone else to open.
  3. Ask the sender another way

    Call or message them using a number or address you already had, not the one in the email. If they sent nothing, report the email, then delete it.
  4. Look at what the file really is

    Programs and scripts (.exe, .js, .vbs, .bat, .scr), shortcuts (.lnk) and disk images (.iso) are not documents: Outlook blocks them as attachments because they can carry viruses. In a .zip archive, they still get through. A name such as invoice.pdf.exe is a program, not a PDF.
  5. Never enable content or macros to read it

    If a document opens with a banner asking you to enable content or macros, close it: enabling them is what lets its code run.
  6. For a second opinion, check its hash

    Save the file without opening it and compute its SHA-256 with Get-FileHash in PowerShell on Windows, shasum -a 256 in Terminal on a Mac, or sha256sum on Linux, followed by the file’s path. Paste the result into the file hash lookup below.
  7. Report the email

    Send it to the services below, then delete it.
On this page07

Check it with isMalicious

isMalicious compares what you paste with the threat intelligence sources it collects. It does not scan your device and cannot undo what already happened.

File hash lookup

Paste the file’s SHA-256, SHA-1 or MD5 into the file hash lookup. Only the hash leaves your device: isMalicious does not receive, open or run the file. A match means a threat source lists this exact file.

What it does not mean
No match is common for new or targeted malware, and changing a single byte of a file changes its hash. A file that NIST’s software reference library knows is identified as published software, which says what it is, not that it is harmless.

Report it

Keep the message, the link or the number until you have reported it: you will need them. These are the services that handle each case.

In the United States

In the United Kingdom

Somewhere else? Report to your national police or your country’s cybercrime reporting service.

In France? The French version of this guide lists the French services.

How to spot the next one

  • You weren’t expecting it, even if it comes from someone you know: their account may have been hacked.
  • You expected a document and received an archive (.zip) or a disk image (.iso).
  • The document says it can only be displayed once you enable content or macros.
  • The file name has two extensions, such as invoice.pdf.exe.

Questions

Does isMalicious scan the file?

No. The file hash lookup checks the file’s hash against threat listings; it does not upload or run the file the way a malware sandbox does.

How do I get a file’s SHA-256?

On Windows, open PowerShell and run Get-FileHash followed by the path to the file: SHA-256 is its default. On a Mac, run shasum -a 256 followed by the path in Terminal. On Linux, run sha256sum followed by the path.

The hash is not listed. Can I open the file?

Not on that basis alone: new or targeted malware is often unlisted. Open it once the sender has confirmed they sent it, and never enable content or macros.

I opened it on a work computer. Should I tell IT even if nothing happened?

Yes, straight away. Tell them what you opened and when: the UK’s NCSC asks anyone in that situation to contact their IT department immediately.

Sources

Free account

Keep checking with a free account

Without an account, checks stop at 10 an hour. With a free account you skip that wait and can run up to 60 a minute, and you can save up to 10 reports every 30 days.

Create free account

No credit card required