Skip to main content
← Back to Demos
Script Injection beginner · 15 min

HTML Application file running embedded script when opened

HTML Application (HTA) files are a favored phishing payload: a single .hta file runs embedded VBScript or JavaScript with full user-level privileges the moment a user opens it. Attackers disguise them as invoices, resumes, or support documents in email, and the script downloads and executes further malware — a classic user-execution vector (T1204.002). Deep CDR does not rely on detection alone: it disassembles the HTA, removes executable script content, and rebuilds a sanitized file that preserves only the document's benign structure. The demo HTA only launches Calculator, so the file is safe to handle and demonstrates remediation without risk.

Attack Technique

HTA script execution

MITRE ATT&CK

T1204.002 ↗

Platforms

linuxwindows

File Types

.html

MetaDefender Capabilities

Deep CDR

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---