Archive Child Malicious

ARCHIVE_CHILD_MALICIOUS

← All detection heuristics · Archive

critical ARCHIVE_CHILD_MALICIOUS

What it means

Archive contains a child file that was independently classified as malicious.

Why it fires

A file extracted from the archive triggered malicious static-analysis evidence. The archive is therefore treated as a malicious carrier, even if the outer container has little suspicious structure on its own.

Other Archive heuristics

ARCHIVE_MALICIOUS_EXECUTABLE ARCHIVE_AUTOCAD_AUTOLISP_BUNDLE ARCHIVE_JAVA_RESOURCE_EXECUTABLE_LAUNCH ARCHIVE_ENCRYPTED_KNOWN_PASSWORD ARCHIVE_ENCRYPTED_SUSPICIOUS_DELIVERY ARCHIVE_TRUNCATED_EXECUTABLE_MEMBER ARCHIVE_DOCUMENT_DOUBLE_EXTENSION_EXECUTABLE ARCHIVE_ANDROID_PACKED_DYNAMIC_DEX ARCHIVE_SCAN_INCOMPLETE ARCHIVE_COMPILED_AUTOLISP_CODE ARCHIVE_CORRUPT ARCHIVE_ENCRYPTED ARCHIVE_RECOVERED_MEMBER_IOCS ARCHIVE_PE_ZIP_POLYGLOT ARCHIVE_SIZE_LIMIT ARCHIVE_TRUNCATED_PARTIAL_CONTENTS ARCHIVE_CONTAINS_EXECUTABLE ARCHIVE_ANDROID_RESOURCE_ONLY_SPLIT ARCHIVE_LIMIT ARCHIVE_LARGE_ENTRY