HWP unreferenced opaque trailing data

OLE_APPENDED_OPAQUE_DATA

← All detection heuristics · Office / HWP

low OLE_APPENDED_OPAQUE_DATA

What it means

An HWP file has a short high-entropy suffix outside declared CFB streams without a recoverable payload structure.

Why it fires

The bytes remain visible for investigation, but an unreferenced opaque suffix is not called executable unless a valid PE/archive/script, loader marker, or active document reference corroborates it.