Software engineer Alexei Turulin has identified the primary warning signs of dangerous computer files that internet users should avoid opening. Speaking to online news outlet Lenta.ru, the technical systems reliability and security expert outlined how cybercriminals disguise malicious software to compromise personal devices.
Turulin explained that the single most concerning indicator is when a file arrives unexpectedly. Even an ordinary invoice, photograph, or job resume should trigger doubt if the recipient was not expecting the document or if the message content fails to match previous correspondence.

Identifying Fake File Extensions
Before downloading any email attachment, Turulin recommended checking the full filename rather than relying on how it appears. Attackers frequently mask malicious executables as standard documents or images using double extensions, such as Invoice.pdf.exe, Photo.jpg.scr, or Resume.docx.js.
Operating systems like Microsoft Windows often hide file extensions by default, allowing a malicious executable file to display a harmless document icon. A file extension consists of the characters following the final period in a filename, indicating the internal format and which application handles it. Turulin advised users to adjust their operating system settings to ensure full file extensions are always visible.
The expert highlighted specific high-risk file types that require extra caution. Executable files and system installers with extensions such asexe,msi,scr,com, andcpl pose direct risks because they execute code directly on the operating system. Script files includingjs,vbs, andps1, command batch files likebat andcmd, and shortcut files usinglnk can also execute malicious code.
Risks extend across different platforms and mobile operating systems. On Android devices, installation files ending inapk present security threats, while macOS installers usingdmg andpkg require scrutiny. Furthermore, Microsoft Office documents containing macros, such asdocm,xlsm, andpptm, represent distinct dangers, along with older legacy formats likedoc andxls that can host active code.
Recognizing Archive Tricks and Sender Spoofing
Compressed archives can also conceal dangerous attachments, Turulin warned. Files usingzip orrar extensions may hide malicious payloads from security scanners. When an email provides an archive password directly within the message body, users should be particularly suspicious. Password protection prevents automated email services and antivirus software from scanning the archived contents upon arrival.
Macro viruses embedded within office documents execute automated scripts when opened, giving attackers control over a system. Antivirus programs rely on automated scanning tools to inspect incoming email attachments before they reach an inbox. Encrypting an archive with a password creates a barrier that blocks security software from examining the underlying code without the user manually entering the password.
Turulin noted that a file extension alone does not definitively prove a file is infected. Legitimate software is routinely distributed inexe format, while standard PDF documents can be exploited for phishing or software vulnerability attacks. He stressed that security decisions must account for the source, whether the file was expected, the presence of a valid digital signature, system warnings, and the broader communication context.
Psychological Lures and Account Hijacking
Fraudsters frequently disguise dangerous attachments as invoices, banking notifications, job applications, photos, or videos to exploit psychological triggers. Turulin stated these traps rely on fear, curiosity, or an artificial sense of urgency to prompt immediate action.
Urgent phrases designed to pressure recipients should immediately raise suspicion. Turulin highlighted common warning phrases including pay today, your account will be blocked, a loan has been issued in your name, look it is you in the photo, and the document must be signed by the end of the day. He added that requests asking users to disable security protection, turn on macros, or ignore operating system warnings are even clearer signals of malicious intent.
To counter email spoofing, Turulin urged users to verify the actual email address of the sender. The display name showing a bank or trusted company does not guarantee authenticity, as the underlying domain may differ from the official address by a single letter or originate from a free email service. Email spoofing involves manipulating header details so a message appears to come from a legitimate organization while routing from an unauthorized server.
Even messages from known contacts cannot automatically be assumed safe, Turulin warned, because their accounts may have been compromised. If an acquaintance unexpectedly sends an archive or program without a clear explanation, he advised calling them directly or contacting them through an alternative communication channel.
The security warning follows reports that cybercriminals have actively monitored neighborhood and residential building group chats. Scammers use monitoring services to analyze daily queries in local online communities to identify potential fraud targets.
