s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-js.turla_ff_ext

📛 Threat Title

Malware family: HTML5 Encoding

Category: HTML5 Encoding First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.turla_ff_ext`. Printable name: HTML5 Encoding.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:attack.mitre.org

    Obfuscated Files or Information: HTML Smuggling Other sub-techniques of Obfuscated Files or Information (18) Adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign HTML files.

  • web:github.com

    HtmlSmuggling HTML smuggling is a malicious technique used by hackers to hide malware payloads in an encoded script in a specially crafted HTML attachment or web page. The malicious script decodes and deploys the payload on the targeted device when the victim opens/clicks the HTML attachment/link.

  • web:ieeexplore.ieee.org

    HTML smuggling is a type of web-based attack that exploits vulnerabilities in web applications to deliver malicious content to unsuspecting users. This attack has become increasingly popular in recent years, as cybercriminals continue to look for new ways to circumvent security measures and deliver malware to users.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the HTML5 Encoding malware family including references, samples and yara signatures.

  • web:www.hackingarticles.in

    Learn how HTML Smuggling bypasses firewalls using JS blobs and payloads, with live scripts, attack demos, and mitigation steps.

  • web:www.imperva.com

    What Is HTML Smuggling? HTML smuggling is an innovative attack technique, which abuses HTML5 and JavaScript features to inject or extract data across network boundaries. The data is cloaked in a legitimate file format, which bypasses security checks. This technique is typically used to deliver malware or exfiltrate sensitive data, often undetected by traditional security mechanisms. HTML ...

  • web:www.insecure.in

    This guide explains what HTML Smuggling is, how it works, types of attacks, POC example, detection, prevention and mitigation techniques in cyber security.

  • web:www.itsecuritydemand.com

    Attackers employ obfuscation methods like Base64 encoding , making it challenging for security tools to spot the hidden malicious code. HTML smuggling attacks further bypass web proxy defenses by encoding as binary data within JavaScript, which is decoded into a file object when the user's browser opens it.

  • web:www.microsoft.com

    HTML smuggling, a highly evasive malware delivery technique that leverages legitimate HTML5 and JavaScript features, is increasingly used in email campaigns that deploy banking malware , remote access Trojans (RATs), and other payloads related to targeted attacks.

  • web:www.zscaler.com

    HTML smuggling is a highly evasive malware delivery technique that exploits legitimate HTML5 and JavaScript features to evade detection and deploy remote access trojans (RATs), banking malware and other malicious payloads. HTML smuggling bypasses traditional security controls like web proxy, email gateway, and legacy sandbox. These attacks are difficult to stop and are just one of many ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.