Skip to main content
← Back to Demos
Extension Mismatch advanced · 15 min

Deliberately corrupted ZIP header evading simple scanners

Obfuscated files hide real intent behind misdescribed structure. A deliberately corrupted ZIP header makes the file look broken or benign to lightweight tools, which give up and let it pass, while the actual container still holds embedded content ready to extract. Attackers also use header mismatches to blur the line between a document and a container — a .docx is itself a ZIP archive, so fiddling with the header can confuse scanners about what is really inside. In this demo a benign .docx is altered to emulate that evasion. The FileType Engine goes beyond surface headers, recovering the true file type from structural content and flagging inconsistencies. MetaDefender then routes the corrected identification to the appropriate deep-analysis engines for proper inspection.

Attack Technique

Corrupted header evasion

MITRE ATT&CK

T1027.001 ↗

Platforms

linuxwindows

File Types

.docx

MetaDefender Capabilities

FileType Engine

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---