Archive Encrypted Suspicious Delivery

ARCHIVE_ENCRYPTED_SUSPICIOUS_DELIVERY

← All detection heuristics · Archive

high ARCHIVE_ENCRYPTED_SUSPICIOUS_DELIVERY

What it means

Archive uses encrypted delivery with suspicious carrier context.

Why it fires

The archive is password-protected or otherwise encrypted in a context that resembles malware delivery. This can hide embedded documents, scripts, or executables from normal inspection.

Other Archive heuristics

ARCHIVE_CHILD_MALICIOUS ARCHIVE_MALICIOUS_EXECUTABLE ARCHIVE_AUTOCAD_AUTOLISP_BUNDLE ARCHIVE_JAVA_RESOURCE_EXECUTABLE_LAUNCH ARCHIVE_ENCRYPTED_KNOWN_PASSWORD ARCHIVE_TRUNCATED_EXECUTABLE_MEMBER ARCHIVE_DOCUMENT_DOUBLE_EXTENSION_EXECUTABLE ARCHIVE_ANDROID_PACKED_DYNAMIC_DEX ARCHIVE_SCAN_INCOMPLETE ARCHIVE_COMPILED_AUTOLISP_CODE ARCHIVE_CORRUPT ARCHIVE_ENCRYPTED ARCHIVE_RECOVERED_MEMBER_IOCS ARCHIVE_PE_ZIP_POLYGLOT ARCHIVE_SIZE_LIMIT ARCHIVE_TRUNCATED_PARTIAL_CONTENTS ARCHIVE_CONTAINS_EXECUTABLE ARCHIVE_ANDROID_RESOURCE_ONLY_SPLIT ARCHIVE_LIMIT ARCHIVE_LARGE_ENTRY