← All detection heuristics · HTML
high
HTML_ACTIVEX_OBJECT
What it means
HTML script instantiates ActiveX or COM objects.
Why it fires
CreateObject and ActiveXObject let script reach Windows automation interfaces such as WScript.Shell, XMLHTTP, and ADODB.Stream. That is rare in benign documents and common in script malware.
Other HTML heuristics
HTML_HTA_VBSCRIPT_DOM_EXECUTE HTML_THIRD_PARTY_CREDENTIAL_HARVEST HTML_WINDOWS_SCRIPTING_OBJECT HTML_VBSCRIPT HTML_CREDENTIAL_PHISH_DYNDNS HTML_SCRIPTED_COM_EXECUTION HTML_SMUGGLED_PAYLOAD HTML_XOR_BASE64_EVAL_INJECTION HTML_LONG_BASE64_SCRIPT_PAYLOAD HTML_OBFUSCATED_STRING_BUILDER HTML_AD_FRAUD_CLOAKING HTML_BASE64_PAYLOAD_URL