← All detection heuristics · HTML
low
HTML_AD_FRAUD_CLOAKING
What it means
Page pairs a CHEQ cloaking handler with an ad-network channel tracking iframe.
Why it fires
The rule fires on the conjunction of a CHEQ anti-bot/cloaking handler ("nCheqResponse") and an ad-network channel tracking iframe ("/ns/<hex>.html?ch=<channel>-iFrame", usually inside <noscript>). Together these are the monetized ad-arbitrage / click-fraud doorway pattern: the page shows automated crawlers and real humans different content and routes visitors through an affiliate channel. It is traffic cloaking / ad fraud rather than code execution, so it is scored low — surfaced for triage and campaign clustering without inflating the document's verdict.
Other HTML heuristics
HTML_HTA_VBSCRIPT_DOM_EXECUTE HTML_THIRD_PARTY_CREDENTIAL_HARVEST HTML_ACTIVEX_OBJECT HTML_WINDOWS_SCRIPTING_OBJECT HTML_VBSCRIPT HTML_CREDENTIAL_PHISH_DYNDNS HTML_SCRIPTED_COM_EXECUTION HTML_SMUGGLED_PAYLOAD HTML_XOR_BASE64_EVAL_INJECTION HTML_LONG_BASE64_SCRIPT_PAYLOAD HTML_OBFUSCATED_STRING_BUILDER HTML_BASE64_PAYLOAD_URL