HTA/VBScript document executes code assembled from DOM text.
A branded page submits email credentials to a generic form collector and redirects to a trusted decoy.
HTML script instantiates ActiveX or COM objects.
HTML references COM objects commonly used for execution or payload download.
Standalone HTML contains a VBScript script block.
HTML sign-in form loads assets from or posts to a free dynamic-DNS/tunnel host.
HTML script dynamically creates objects and invokes execution/open methods.
A contiguous or constant-concatenated base64 value inside an inline script decodes to a complete archive, executable, document or HTA.
Inline script base64-decodes a blob, XORs it byte-by-byte, and evals the result.
HTML script contains a long or constant-concatenated base64-like blob.
HTML script repeatedly builds strings from small fragments.
Page pairs a CHEQ cloaking handler with an ad-network channel tracking iframe.
A URL was recovered by decoding a long base64 blob inside an inline script.