Save the file to your drive but do not open it.
The "file" may actually be a downloader that installs unwanted toolbars or pop-ups on your system.
Once unzipped (ideally in a Sandbox or Virtual Machine), look for double extensions like image.jpg.exe .
In the worst-case scenario, executing a file from an untrusted source can encrypt your hard drive. 🛡️ Safety Checklist