← All detection heuristics · HTML
high
HTML_SCRIPTED_COM_EXECUTION
What it means
HTML script dynamically creates objects and invokes execution/open methods.
Why it fires
Dynamic object creation followed by execution-like calls is a staged script malware pattern, especially when hidden inside a file with a document extension.
Other HTML heuristics
HTML_HTA_VBSCRIPT_DOM_EXECUTE HTML_THIRD_PARTY_CREDENTIAL_HARVEST HTML_ACTIVEX_OBJECT HTML_WINDOWS_SCRIPTING_OBJECT HTML_VBSCRIPT HTML_CREDENTIAL_PHISH_DYNDNS HTML_SMUGGLED_PAYLOAD HTML_XOR_BASE64_EVAL_INJECTION HTML_LONG_BASE64_SCRIPT_PAYLOAD HTML_OBFUSCATED_STRING_BUILDER HTML_AD_FRAUD_CLOAKING HTML_BASE64_PAYLOAD_URL