Archive contains a child file that was independently classified as malicious.
A native executable bundled in the archive was identified as malware by ClamAV.
An archive places verified compiled AutoLISP under a reserved AutoCAD startup name beside DWG drawings.
A Java class copies a bundled payload, marks it executable, and starts it with ProcessBuilder.
Archive is encrypted with a known malware-delivery password.
Archive uses encrypted delivery with suspicious carrier context.
A damaged or truncated archive declares a native executable member that cannot necessarily be recovered completely.
Executable disguised with a document double extension
high
ARCHIVE_DOCUMENT_DOUBLE_EXTENSION_EXECUTABLE
An archive member uses a document-looking name such as invoice.pdf.exe but is executable code.
An Android package combines a packer wrapper, dynamic DEX installation, concealed data, native code, and sensitive permissions.
Archive could not be fully unpacked or scanned.
An archive member has a verified compiled FAS executable-code header.
The file has a ZIP signature but could not be opened.
The archive is password-protected with an unknown password.
Network indicators were recovered from members that remain readable in a truncated archive.
A valid Windows executable host contains a later validated ZIP archive.
The total decompressed size exceeded the safety limit.
Archive members are partially recoverable but the container ends early or has damaged headers.
A native executable (PE/ELF/Mach-O or .exe/.dll/.scr/…) is bundled inside the archive alongside documents.
The APK contains resources and a manifest but no executable code.
Only a limited number of files were scanned from the archive.
An entry in the archive exceeds the per-file size limit.