-
Notifications
You must be signed in to change notification settings - Fork 534
Open
Labels
buguse for describing something not working as expecteduse for describing something not working as expectedconnector: hybrid analysis
Description
Description
Hybrid Analysis appears to be assigning very inaccurate scores after malware analysis.
We enriched StixFile observable with hash 3524ec77985e390acf9d07d81b1b44305165d711bbca770f7458ea0a78751f82 with Hybrid Analysis. It shows as suspicious on Hybrid Analysis but only 2% score:
However, on OpenCTI, it set the score to 69/100:
The malware analysis entity itself shows no verdict for maliciousness:
Environment
6.9.1
Reproducible Steps
Create observable as above and enrich with Hybrid Analysis
Expected Output
Score set to reflect analysis, which as above should have been a very low score.
Actual Output
Inaccurate high score
Metadata
Metadata
Assignees
Labels
buguse for describing something not working as expecteduse for describing something not working as expectedconnector: hybrid analysis