google / google/magika

[Misdetection] HTA file misdetected as HTML

Open
#1,133 1 comment 0 reactions 0 assignees View on GitHub
missing content type
Dominant language
Rust
Stars
18.6k
Forks
1.2k
Avg merge
3d 12h
Merged PRs (30d)
20

Description

**What should the file have been detected as? What has the file been misdetected as?**
Hard case:

HTA **malware** are being mistaken for generic HTML

**Please link or attach the misdetected file below** (Do NOT upload PII!)
https://www.virustotal.com/gui/search/magika%253Ahtml%2520name%253A*.hta%2520fs%253A7d%252B%2520not%2520name%253Apayload%2520p%253A10%252B?type=files
```
29fde995c8e3e487db9afc241277b0a90e7a334f341ce8e4c4523468da62a312
181ee39752f0cc3e6c39dfb2ff2659c83e5be830dfb3a01e61e2f758d1b824d2
0591552e526327721c9194d6f839f89996a253ad27ab0ef03af30fb9eece2316
180c8394f4186040dc83d9068bda7f2c058035ec3f77aabf055c4160f73e4709
dc8a1d6408d07ba645609c831fdc262a10ab4d45efabe2448268272b8303a460
```

**Additional context**
Add any other context or screenshots about the feature request here.

Contributor guide

Open the contributing guide

Research direction

Start with the VirusTotal search link and the five provided hashes, then trace how Magika distinguishes HTML-like files. No source file or test is named, so first identify the relevant detector or model evaluation entry point and reproduce the reported classifications. Done means the supplied HTA malware samples are no longer reported as generic HTML, with regression coverage for the behavior.

Written by the indexing model from the issue text.

Assessment

Tech stack
html, rust
Domain
machine-learning, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.