HTML Application file running embedded script when opened
HTML Application (HTA) files are a favored phishing payload: a single .hta file runs embedded VBScript or JavaScript with full user-level privileges the moment a user opens it. Attackers disguise them as invoices, resumes, or support documents in email, and the script downloads and executes further malware — a classic user-execution vector (T1204.002). Deep CDR does not rely on detection alone: it disassembles the HTA, removes executable script content, and rebuilds a sanitized file that preserves only the document's benign structure. The demo HTA only launches Calculator, so the file is safe to handle and demonstrates remediation without risk.
Attack Technique
HTA script execution
MITRE ATT&CK
T1204.002 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗