: Inside the ZIP is usually a heavily obfuscated script (like Javascript) or an executable file.

: The email comes from an address you don't recognize.

: Always have an offline backup of your important data.