Compiled HTML Help file executing script on open
Compiled HTML Help (CHM) files are legitimate Windows documentation containers that double as a weapon: their help engine can execute embedded scripts and launch programs when the file is opened, so attackers abuse the format to run code while appearing to deliver harmless documentation (MITRE T1218.001). A crafted CHM can call out to the Windows Script Host or spawn child processes from its content pages, and because it looks like a standard help file, users and many scanners treat it as benign. Deep CDR parses the CHM container, removes all executable script content, and reconstructs a clean help file that displays documentation only - no code can run on open. The demo uses a benign CHM whose script merely opens Calculator, safe to run on any Windows machine.
Attack Technique
CHM compiled help abuse
MITRE ATT&CK
T1218.001 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗