Detection Method: HTML analysis

HTML analysis looks at the HTML code in emails, web pages, or attachments to spot potentially malicious elements or deceptive structures. It examines both what’s visible and hidden in the HTML to uncover tactics often used in phishing or malware attacks.
HTML analysis can help you detect:
  • Hidden scripts or iframes that might run harmful code
  • Obfuscated JavaScript designed to avoid detection
  • Misleading hyperlinks where the displayed text doesn’t match the real URL
  • Forms made to steal credentials or sensitive data
  • Suspicious HTML comments with hidden instructions
  • CSS tricks used to hide malicious content
For example, phishing emails often use HTML to replicate trusted login pages. HTML analysis can catch the hidden forms and scripts trying to steal your credentials.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Callback phishing: Zero-width character obfuscation from freemail sender
2d ago
Aug 5th, 2026
Sublime Security
Body: CSS Hidden text via clip-path
2d ago
Aug 5th, 2026
Sublime Security
Body: CSS zero-value calc() obfuscation
2d ago
Aug 5th, 2026
Sublime Security
Service abuse: Wufoo credential theft
2d ago
Aug 5th, 2026
Sublime Security
HTML: Template placeholders or recipient email in element class attributes
2d ago
Aug 5th, 2026
Sublime Security
Link: Suspicious recipient with timeout redirect
3d ago
Aug 4th, 2026
Sublime Security
Credential phishing: Suspicious e-sign agreement document notification
4d ago
Aug 3rd, 2026
Sublime Security
Body: HTML whitespace stuffing with short initial message
7d ago
Jul 31st, 2026
Sublime Security
Body: CSS clamp() font obfuscation with IP-based links
9d ago
Jul 29th, 2026
Sublime Security
Low reputation link to auto-downloaded HTML file with smuggling indicators
9d ago
Jul 29th, 2026
Sublime Security
Body: Yellow highlighted text markers
10d ago
Jul 28th, 2026
Sublime Security
Credential theft: JavaScript date manipulation in HTML body
10d ago
Jul 28th, 2026
Sublime Security
Credential phishing: Personalized document signing request
11d ago
Jul 27th, 2026
Sublime Security
Open redirect: Shibboleth SSO Logout Return Parameter
11d ago
Jul 27th, 2026
Sublime Security
Attachment: EML with link to credential phishing page
11d ago
Jul 27th, 2026
Sublime Security
Link: Suspicious HTML structure with subject mirrored in body and single link
11d ago
Jul 27th, 2026
Sublime Security
Link: Credential harvesting with excess padding evasion
17d ago
Jul 21st, 2026
Sublime Security
Service abuse: Oracle Cloud Workflow callback scam
28d ago
Jul 10th, 2026
Sublime Security
Credential phishing: Blue button styled link with file-sharing template artifacts
30d ago
Jul 8th, 2026
Sublime Security
Service abuse: SurveyMonkey with suspicious outbound links
30d ago
Jul 8th, 2026
Sublime Security