← All detection heuristics · HTML
info
HTML_BASE64_PAYLOAD_URL
What it means
A URL was recovered by decoding a long base64 blob inside an inline script.
Why it fires
Static URL extraction cannot see inside an encoded blob, so this destination would otherwise never reach reputation scoring or campaign clustering. CDN, font and standards boilerplate is filtered out so only candidate infrastructure is reported.
Other HTML heuristics
HTML_HTA_VBSCRIPT_DOM_EXECUTE HTML_THIRD_PARTY_CREDENTIAL_HARVEST HTML_ACTIVEX_OBJECT HTML_WINDOWS_SCRIPTING_OBJECT HTML_VBSCRIPT HTML_CREDENTIAL_PHISH_DYNDNS HTML_SCRIPTED_COM_EXECUTION HTML_SMUGGLED_PAYLOAD HTML_XOR_BASE64_EVAL_INJECTION HTML_LONG_BASE64_SCRIPT_PAYLOAD HTML_OBFUSCATED_STRING_BUILDER HTML_AD_FRAUD_CLOAKING