HTML credential form on dynamic-DNS host

HTML_CREDENTIAL_PHISH_DYNDNS

← All detection heuristics · HTML

high HTML_CREDENTIAL_PHISH_DYNDNS

What it means

HTML sign-in form loads assets from or posts to a free dynamic-DNS/tunnel host.

Why it fires

A credential-collecting form combined with a free dynamic-DNS or tunnel host (dedyn.io, duckdns.org, no-ip, ngrok, trycloudflare, serveo, and similar) is the standard shape of a phishing kit. Legitimate brand login pages never serve their sign-in assets from throwaway dynamic-DNS domains.

Other HTML heuristics

HTML_HTA_VBSCRIPT_DOM_EXECUTE HTML_THIRD_PARTY_CREDENTIAL_HARVEST HTML_ACTIVEX_OBJECT HTML_WINDOWS_SCRIPTING_OBJECT HTML_VBSCRIPT HTML_SCRIPTED_COM_EXECUTION HTML_SMUGGLED_PAYLOAD HTML_XOR_BASE64_EVAL_INJECTION HTML_LONG_BASE64_SCRIPT_PAYLOAD HTML_OBFUSCATED_STRING_BUILDER HTML_AD_FRAUD_CLOAKING HTML_BASE64_PAYLOAD_URL