Archive contains a bundled executable

ARCHIVE_CONTAINS_EXECUTABLE

← All detection heuristics · Archive

low ARCHIVE_CONTAINS_EXECUTABLE

What it means

A native executable (PE/ELF/Mach-O or .exe/.dll/.scr/…) is bundled inside the archive alongside documents.

Why it fires

The document-analysis pipeline does not deep-inspect executable payloads, but a bundled executable in a document-delivery archive is a common dropper / phishing pattern, so it is surfaced for visibility. ClamAV is run on the executable; this finding means ClamAV did not flag it (legitimate software archives also carry executables), so it is informational and does not by itself convict the archive.

Other Archive heuristics

ARCHIVE_CHILD_MALICIOUS ARCHIVE_MALICIOUS_EXECUTABLE ARCHIVE_AUTOCAD_AUTOLISP_BUNDLE ARCHIVE_JAVA_RESOURCE_EXECUTABLE_LAUNCH ARCHIVE_ENCRYPTED_KNOWN_PASSWORD ARCHIVE_ENCRYPTED_SUSPICIOUS_DELIVERY ARCHIVE_TRUNCATED_EXECUTABLE_MEMBER ARCHIVE_DOCUMENT_DOUBLE_EXTENSION_EXECUTABLE ARCHIVE_ANDROID_PACKED_DYNAMIC_DEX ARCHIVE_SCAN_INCOMPLETE ARCHIVE_COMPILED_AUTOLISP_CODE ARCHIVE_CORRUPT ARCHIVE_ENCRYPTED ARCHIVE_RECOVERED_MEMBER_IOCS ARCHIVE_PE_ZIP_POLYGLOT ARCHIVE_SIZE_LIMIT ARCHIVE_TRUNCATED_PARTIAL_CONTENTS ARCHIVE_ANDROID_RESOURCE_ONLY_SPLIT ARCHIVE_LIMIT ARCHIVE_LARGE_ENTRY