Skip to content

[hybrid-analysis] enrichment score inaccurate #5545

@dominictory

Description

@dominictory

Description

Hybrid Analysis appears to be assigning very inaccurate scores after malware analysis.

We enriched StixFile observable with hash 3524ec77985e390acf9d07d81b1b44305165d711bbca770f7458ea0a78751f82 with Hybrid Analysis. It shows as suspicious on Hybrid Analysis but only 2% score:

Image

However, on OpenCTI, it set the score to 69/100:

Image

The malware analysis entity itself shows no verdict for maliciousness:

Image

Environment

6.9.1

Reproducible Steps

Create observable as above and enrich with Hybrid Analysis

Expected Output

Score set to reflect analysis, which as above should have been a very low score.

Actual Output

Inaccurate high score

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions