Recently it seems there has been a big outbreak of zip files being emailed to people with a .js file containing code that downloads and executes cryptoware.
How does the .js actually get executed though? Do users have to execute the javascript file itself after extracting it or is it somehow possible to make the javascript file execute upon extraction? I am rather confused on how this causes so many infections.