Skip to main content
← Back to Demos
Country of Origin beginner · 15 min

Archive locale metadata contradicting embedded document language

Masquerading can happen at the container level as well as in the payload. An archive's locale and language metadata — the region, codepage, or comment language — can be deliberately set to mislead, while the documents it contains tell a different story. A file that claims a benign origin but embeds content in an unexpected language or encoding is a red flag worth scrutiny, since attackers often forge metadata to evade geo-based triage and appear trustworthy. In this demo a benign RAR/ZIP sample presents conflicting locale and content-language signals. The Country of Origin module compares container metadata against the language and structure of the embedded documents, exposing the discrepancy. The mismatch is surfaced clearly so analysts can decide whether the file is legitimate or deliberately disguised.

Attack Technique

Language/locale metadata conflict

MITRE ATT&CK

T1036.005 ↗

Platforms

linux

File Types

.zip

MetaDefender Capabilities

Country of Origin

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---