
Compares Windows archiver support for Mark of the Web propagation, helping teams assess which tools preserve MOTW and mitigate macro-based malware delivery.
English | Japanese
On 3 March 2022, Microsoft announced that the default behavior of Office applications on Windows will be changed to block macros in files from the internet (such as email attachment).
An excerpt from the announcement:
VBA macros are a common way for malicious actors to gain access to deploy malware and ransomware. Therefore, to help improve security in Office, we’re changing the default behavior of Office applications to block macros in files from the internet.
...
This change only affects Office on devices running Windows and only affects the following applications: Access, Excel, PowerPoint, Visio, and Word.
The change will begin rolling out in Version 2203, starting with Current Channel (Preview) in early April 2022. Later, the change will be available in the other update channels, such as Current Channel and Monthly Enterprise Channel.
This is a great improvement of defense against malicious Office document files.
According to the announcement, whether blocking macro or not is determined based on MOTW (Mark of the Web) attribute of the file. Applications such as web browsers and email clients put MOTW on downloaded files and email attachments that come from the internet. MOTW is stored in Zone.Identifier NTFS alternate data stream.
To block macro of malicious Office document files that are extracted from archive files, an archiver software has to propagate MOTW to extracted files when an archive file has MOTW. If archiver software does not propagate MOTW, malicious Office documents in archive files can circumvent blocking.
A question came up: "What archiver software can propagate MOTW to extracted files?" So I tested some archiver software and summarized the result.
| Name | Tested version | License | MOTW propagation | Enabled by default | Note |
|---|---|---|---|---|---|
| "Extract all" built-in function of Windows Explorer | Windows 11 25H2 | proprietary | Yes ✔️ | Yes ✔️ | |
| 7-Zip | 26.02 | GNU LGPL | Yes ✔️ | No ❌ *1 | |
| Bandizip | Standard Edition 7.45 | freeware | Yes ✔️ | Yes ✔️ | Only for specific file extensions *2 |
| CubeICE | 3.6.1 | freeware / proprietary | Yes ✔️ | Yes ✔️ | |
| Explzh | 10.01 | proprietary for commercial use | Yes ✔️ | Yes ✔️ | |
| File Compact | 8.00 | proprietary | Yes ✔️ | Yes ✔️ | |
| NanaZip | 6.5.1767.0 | MIT | Yes ✔️ | Yes ✔️ | Configurable to propagate for specific file extensions *3 |
| PeaZip | 11.2.0 | GNU LGPL | Yes ✔️ | Yes ✔️ | |
| TC4Shell | 21.3.0 (trial) | proprietary | Yes ✔️ | Yes ✔️ | |
| Total Commander | 11.58 (trial) | proprietary | Yes ✔️ | Yes ✔️ | |
| WinRAR | 7.23 (trial) | proprietary | Yes ✔️ | Yes ✔️ | Only for specific file extensions by default *4 |
| WinZip | 77.0 (trial) | proprietary | Yes ✔️ | Yes ✔️ | |
| Ashampoo ZIP Free | 1.0.7 | freeware (registration required) | No ❌ | ||
| CAM UnZip | 5.25.4.0 | proprietary for commercial use | No ❌ | ||
| Expand-Archive cmdlet of PowerShell | 7.6.4 | MIT | No ❌ | ||
| Express Zip | 11.28 | proprietary for commercial use | No ❌ | ||
| IZArc | 4.6 | freeware | No ❌ | Despite the availability of the"Propagate Mark of the Web" option *5 | |
| LhaForge | 2.0.1 | MIT | No ❌ | ||
| Lhaplus | 1.74 | freeware | No ❌ | ||
| PowerArchiver | 22.10.02 (trial) | proprietary | No ❌ | ||
| StuffIt Expander | 15.0.8 | freeware | No ❌ | ||
| tar.exe (bsdtar) of Windows 11 | 3.8.4 | BSD 2-clause | No ❌ | ||
| Universal Extractor 2 | 2.0.0 RC 3 | GNU GPLv2 | No ❌ | ||
| ZipGenious | 6.3.2.3116 | freeware | No ❌ | ||
| Zipware | 1.6 | freeware | No ❌ |
*1: Though 7-Zip has supported MOTW propagation since version 22.00, it is disabled by default. You can enable it for 7-Zip GUI with the "Propagate Zone Id stream:" option in "Tools" -> "Options" -> "7-Zip" of 7-Zip File Manager.

When you set the option to Yes, 7-Zip propagates MOTW to all extracted files. When you set it to "For Office files", 7-Zip propagates MOTW to files with the following file extensions:
You can also enable MOTW propagation by setting the registry HKEY_CURRENT_USER\SOFTWARE\7-Zip\Options\WriteZoneIdExtract DWORD to 1.
For 7-Zip CLI, -snz switch is required to propagate MOTW regardless of the option above.
*2: Accoring to the document of Bandizip, Bandizip propagates MOTW to files with the following file extensions:
I previously tested Bandizip with a ZIP archive file that contained only text files, and I misunderstood that Bandizip does not propagate MOTW.
*3: NanaZip has enabled MOTW propagation by default since version 6.0 Preview 1, You can configure it with the "Propagate Zone Id stream" option in "Options" -> "Integration" of NanaZip GUI.

When you set it to "For unsafe files", NanaZip propagate MOTW to files with the following file extensions:
NanaZip supports system-wide policies with registry. These policies override user settings.
*4: WinRAR 7.0 introduced the "Propagate Mark of the Web" option. You can choose the following values:
The option is supported only by WinRAR GUI. WinRAR CLI does not propagate MOTW regardless of the option.