Total decompression limit reached

ARCHIVE_SIZE_LIMIT

← All detection heuristics · Archive

medium ARCHIVE_SIZE_LIMIT

What it means

The total decompressed size exceeded the safety limit.

Why it fires

To protect against zip bombs (archives that decompress to enormous sizes), the analyzer caps total decompressed output. Some files in the archive may not have been scanned.

Other Archive heuristics

ARCHIVE_CHILD_MALICIOUS ARCHIVE_MALICIOUS_EXECUTABLE ARCHIVE_AUTOCAD_AUTOLISP_BUNDLE ARCHIVE_JAVA_RESOURCE_EXECUTABLE_LAUNCH ARCHIVE_ENCRYPTED_KNOWN_PASSWORD ARCHIVE_ENCRYPTED_SUSPICIOUS_DELIVERY ARCHIVE_TRUNCATED_EXECUTABLE_MEMBER ARCHIVE_DOCUMENT_DOUBLE_EXTENSION_EXECUTABLE ARCHIVE_ANDROID_PACKED_DYNAMIC_DEX ARCHIVE_SCAN_INCOMPLETE ARCHIVE_COMPILED_AUTOLISP_CODE ARCHIVE_CORRUPT ARCHIVE_ENCRYPTED ARCHIVE_RECOVERED_MEMBER_IOCS ARCHIVE_PE_ZIP_POLYGLOT ARCHIVE_TRUNCATED_PARTIAL_CONTENTS ARCHIVE_CONTAINS_EXECUTABLE ARCHIVE_ANDROID_RESOURCE_ONLY_SPLIT ARCHIVE_LIMIT ARCHIVE_LARGE_ENTRY