Tag-set historically associated with malicious files

CORPUS_HISTORICALLY_MALICIOUS

← All detection heuristics · General

high CORPUS_HISTORICALLY_MALICIOUS

What it means

This combination of heuristics has fired multiple times before, mostly on malicious files.

Why it fires

The analyzer keeps a record of every prior scan's heuristic combination. When the same combination has been seen at least three times in the last 90 days and at least 80% of those were classified malicious, the finding reports that measured corpus prior for the current file.

Other General heuristics

POLYGLOT_PDF_APPENDED_ZIP_CVE_BUNDLE EXTRACTED_FILE_CLAMAV POLYGLOT_GIF_PDF_FORCEDENTRY_SHAPE SPEC_DIVERGENCE_HIGH PDF_EXTENSION_MISMATCH POLYGLOT_PDF_ZIP_APPENDED EXTRACTED_FILE_STATIC_TRIAGE POLYGLOT_TEXT_PDF POLYGLOT_ZIP_PREFIXED FORMAT_NEUTRAL_SCAN PPT_FOPT_COMPLEX_DATA_OVERFLOW PPT_FOPT_PROPERTY_TABLE_TRUNCATED CORPUS_RARE_COMBINATION CORPUS_RARE_STRUCTURAL_FEATURE_SET ANALYSIS_TIMEOUT_PARTIAL EMBEDDED_URL MACRO_VALID_PUBLISHER_SIGNATURE SCAN_OPTIONAL_STAGES_SKIPPED POLYGLOT_PDF_APPENDED_ZIP_SCAN_INCOMPLETE SCAN_INCOMPLETE UNKNOWN_FORMAT