Ad-fraud / traffic-cloaking doorway

HTML_AD_FRAUD_CLOAKING

← All detection heuristics · HTML

low HTML_AD_FRAUD_CLOAKING

What it means

Page pairs a CHEQ cloaking handler with an ad-network channel tracking iframe.

Why it fires

The rule fires on the conjunction of a CHEQ anti-bot/cloaking handler ("nCheqResponse") and an ad-network channel tracking iframe ("/ns/<hex>.html?ch=<channel>-iFrame", usually inside <noscript>). Together these are the monetized ad-arbitrage / click-fraud doorway pattern: the page shows automated crawlers and real humans different content and routes visitors through an affiliate channel. It is traffic cloaking / ad fraud rather than code execution, so it is scored low — surfaced for triage and campaign clustering without inflating the document's verdict.

Other HTML heuristics

HTML_HTA_VBSCRIPT_DOM_EXECUTE HTML_THIRD_PARTY_CREDENTIAL_HARVEST HTML_ACTIVEX_OBJECT HTML_WINDOWS_SCRIPTING_OBJECT HTML_VBSCRIPT HTML_CREDENTIAL_PHISH_DYNDNS HTML_SCRIPTED_COM_EXECUTION HTML_SMUGGLED_PAYLOAD HTML_XOR_BASE64_EVAL_INJECTION HTML_LONG_BASE64_SCRIPT_PAYLOAD HTML_OBFUSCATED_STRING_BUILDER HTML_BASE64_PAYLOAD_URL