HTML attachments as a phishing tool

More in Phishing & sandbox
- ⚡Fake news — THAT'S ALL
⚡Fake news — B U L L S H I T PT ESC specialists discovered an…
- PT ESC cyber intelligence group presented an overview of cyberattacks for Q2 2026 ✍️
PT ESC Cyber Intelligence Group presented an overview of cyberattacks for Q2 2026 ✍️ The report…
- Citizen, update yourself 🫵
Citizen, update yourself 🫵 Recently, a sample mir-pay.apk flew into our sandbox. At first glance, nothing…
- NetMedved: summer campaign against Russian organizations
NetMedved: Summer Campaign Against Russian Organizations 🐻👍 The PT ESC cyber intelligence group has recorded a…
- AI-95 with a malicious additive ⛽️
AI-95 with a malicious additive ⛽️ In mid-June, the Threat Intelligence team discovered several resources at…
HTML attachments as a phishing tool 🤑
Delivery of HTML-like email attachments containing various techniques for opening third-party web content, interacting with it, and sending data to third-party servers is becoming a popular tool among attackers.
In this post, we will examine a couple of examples of HTML-like attachments delivered for the purpose of credential theft.
1️⃣ The first phishing sample is aimed at invoking methods that, when it is opened, allow displaying the content of a third-party web page with which the recipient can interact.
At the beginning of the JavaScript code (screenshot 1), the constants P and W are defined, which are the encryption key and the encrypted text, as well as the decryption function k. The resulting decrypted instructions are placed into the constant Y and have the form shown in screenshot 2.
As can be understood from these instructions, they create an iframe element whose content is obtained from a phishing URL (its value is encoded in base64); CSS styles are also set that allow the received content to occupy the entire available screen area. In addition, in these instructions we see a call to the document.write method to place the received content on the browser tab.
So far this is just a set of text. Let us separately focus on the method of launching the instructions from the constant Y. To do this, the following part of the script is called from the attachment (screenshot 3).
When defining the constant H, a reference is created to the global object o, which in the JavaScript code is window. The call o[X] (in X, the word Function is simply encoded) is equivalent to calling the Function property on the global object, and when parameters are passed to it, they will be executed as new functions. As we see further in the code, the decoded instructions from the constant Y are passed into the object.
To further complicate detection of the execution of malicious script code, the attackers create an empty function y, override its toString method, supplementing it with a call to the aforementioned global object window. Then the line U = ${y}: y is executed, is converted to a string, invoking the overridden toString, inside which the loading of content is already launched.
Suspicious markers when analyzing such samples are the overriding of standard methods (like toString); mapping words from a numeric array via a call to the fromCharCode function (in the constant X), as well as the definition of long numeric and text constants with the subsequent definition of functions to decode them.
2️⃣ Another sample that caught our interest contains interesting “anti-debugging” methods, but more on them a bit later. It is a credential entry form for opening a blurred pdf document.
The HTML sample contains two scripts. The first, after a simple validation of the presence of an email address in the input field, contains a POST method that sends the credentials to a third-party server (screenshot 4).
As we can see, the URL link has the number of attempts as a query parameter. Naturally, no authentication is performed based on the data entered in the form; it simply leaks to the specified address. At the same time, the attempt parameter is incremented, and on the third attempt to enter some data into the form, a redirect is made to a legitimate web resource. Thanks to the authors for the code comments that made it possible to understand what is even happening.
The second script, which we mentioned earlier, has the following form, shown in screenshot 5.
This script monitors the invocation of the context menu, key presses that invoke the browser’s built-in developer tool, as well as attempts to select, cut, or copy text from the loaded page, open the file source, and save it to a separate file. Probably, in the attackers’ opinion, limiting the ability to interact with the loaded interface will more likely force the victim to enter the password into the only available element on the page.
Besides invoking POST methods to unfamiliar web resources, in our opinion, an analyst’s attention may be drawn to the definition of such restrictive methods that prohibit invoking debug tools, as well as additional interaction with the page interface.




#phishing #detect #tip
@ptescalator
More in Phishing & sandbox
- ⚡Fake news — THAT'S ALL
⚡Fake news — B U L L S H I T PT ESC specialists discovered an…
- PT ESC cyber intelligence group presented an overview of cyberattacks for Q2 2026 ✍️
PT ESC Cyber Intelligence Group presented an overview of cyberattacks for Q2 2026 ✍️ The report…
- Citizen, update yourself 🫵
Citizen, update yourself 🫵 Recently, a sample mir-pay.apk flew into our sandbox. At first glance, nothing…
- NetMedved: summer campaign against Russian organizations
NetMedved: Summer Campaign Against Russian Organizations 🐻👍 The PT ESC cyber intelligence group has recorded a…
- AI-95 with a malicious additive ⛽️
AI-95 with a malicious additive ⛽️ In mid-June, the Threat Intelligence team discovered several resources at…







