Do not open an unexpected file. Confirm the sender through a separate trusted channel, show the full file extension and scan the file with Microsoft Defender. A digital signature, SHA-256 hash and static pre-check add context, but no single result guarantees that a file is safe.
Before you do anything else
If the attachment appears to come from someone you know, verify it using a phone number or account you already trust. Do not simply reply to the suspicious message.
1. Confirm the sender and the reason for the file
Ask whether you expected this exact document. A familiar sender address is not proof: accounts can be compromised and display names can be copied. Check the project, invoice number, language and any unusual pressure to act quickly.
CISA recommends verifying a doubtful message with the apparent sender before opening an attachment.
2. Show the complete file extension
In File Explorer, select View → Show → File name extensions. A file presented as “Invoice.pdf” may turn out to be “Invoice.pdf.exe”. Microsoft explains that the extension identifies the file type; renaming it does not convert its contents.
Be especially careful with executable or script-capable types such as .exe, .msi, .scr, .bat, .cmd, .js, .vbs, .ps1, macro-enabled Office files such as .docm, .xlsm, and archives that may contain them.
3. Scan the individual file with Microsoft Defender
Right-click the file, choose Show more options if needed, and select Scan with Microsoft Defender. Review the result in Windows Security → Virus & threat protection → Protection history.
4. Check the publisher and digital signature
For executable files, open Properties → Digital Signatures. Microsoft’s Sigcheck utility can display version data, certificate-chain details and file hashes.
A valid signature improves traceability, but it does not prove that the file belongs to your particular request. A missing signature is not automatic proof of malware either. Consider origin, expected purpose, scan result and technical details together.
5. Record a SHA-256 hash
A SHA-256 hash identifies the exact file version without running it. In PowerShell, use Get-FileHash -Algorithm SHA256 "C:\Path\File". Even a small change produces a different value.
A hash is not a safety verdict. It helps compare a vendor-published value or identify the same sample in a support case. Do not upload confidential customer documents or personal data to a public scanning service without considering the privacy impact.
6. Add a static Shield pre-check
The free Shield checker examines supported Office, PDF and ZIP files for technical warning signs without executing their contents. Without an account, the file is not stored in a personal workspace. Open the full checker (the analysis form currently uses German labels).
This pre-check complements the local antivirus scan. It does not replace Microsoft Defender, sender verification or professional incident response.
7. If doubt remains, do not open it
Delete or quarantine the file and ask for a fresh copy through a verified channel. On a managed work device, let your IT or security contact decide.
If you already opened the file and then notice unusual processes, connections or remote control, disconnect the PC from the network. Continue with the Windows remote-access checklist. CMC Sentinel brings local process, connection and remote-access signals into one view, but it does not replace antivirus protection or forensic analysis.