← All detection heuristics · General
info
MACRO_VALID_PUBLISHER_SIGNATURE
What it means
A capability-only Office macro carries a cryptographically valid, CA-issued (non-self-signed) VBA publisher signature and nothing corroborates malice, so its score was downgraded to clean.
Why it fires
A valid, CA-issued publisher signature is a strong benign signal: it ties the VBA project to an accountable, identity-verified author and proves the signed bytes are intact. When that signature verifies AND the same no-corroborator gate the signature gate passes (no obfuscation / download+exec / loader / AV-ML hit / suspicious URL), the verdict is downgraded to clean — clearing legitimately-signed add-ins (e.g. the Microsoft Analysis ToolPak). A valid signature is NOT trusted on its own: a validly-CA-signed but weaponised macro always trips a hard corroborator and stays malicious. Self-signed / unverified / invalid signatures never qualify.
Other General heuristics
POLYGLOT_PDF_APPENDED_ZIP_CVE_BUNDLE EXTRACTED_FILE_CLAMAV POLYGLOT_GIF_PDF_FORCEDENTRY_SHAPE SPEC_DIVERGENCE_HIGH PDF_EXTENSION_MISMATCH POLYGLOT_PDF_ZIP_APPENDED EXTRACTED_FILE_STATIC_TRIAGE CORPUS_HISTORICALLY_MALICIOUS POLYGLOT_TEXT_PDF POLYGLOT_ZIP_PREFIXED FORMAT_NEUTRAL_SCAN PPT_FOPT_COMPLEX_DATA_OVERFLOW PPT_FOPT_PROPERTY_TABLE_TRUNCATED CORPUS_RARE_COMBINATION CORPUS_RARE_STRUCTURAL_FEATURE_SET ANALYSIS_TIMEOUT_PARTIAL EMBEDDED_URL SCAN_OPTIONAL_STAGES_SKIPPED POLYGLOT_PDF_APPENDED_ZIP_SCAN_INCOMPLETE SCAN_INCOMPLETE UNKNOWN_FORMAT