[Misdetection] HTA file misdetected as HTML
- Dominant language
- Rust
- Stars
- 18.6k
- Forks
- 1.2k
- Avg merge
- 3d 12h
- Merged PRs (30d)
- 20
Description
**What should the file have been detected as? What has the file been misdetected as?**
Hard case:
HTA **malware** are being mistaken for generic HTML
**Please link or attach the misdetected file below** (Do NOT upload PII!)
https://www.virustotal.com/gui/search/magika%253Ahtml%2520name%253A*.hta%2520fs%253A7d%252B%2520not%2520name%253Apayload%2520p%253A10%252B?type=files
```
29fde995c8e3e487db9afc241277b0a90e7a334f341ce8e4c4523468da62a312
181ee39752f0cc3e6c39dfb2ff2659c83e5be830dfb3a01e61e2f758d1b824d2
0591552e526327721c9194d6f839f89996a253ad27ab0ef03af30fb9eece2316
180c8394f4186040dc83d9068bda7f2c058035ec3f77aabf055c4160f73e4709
dc8a1d6408d07ba645609c831fdc262a10ab4d45efabe2448268272b8303a460
```
**Additional context**
Add any other context or screenshots about the feature request here.
Contributor guide
Research direction
Start with the VirusTotal search link and the five provided hashes, then trace how Magika distinguishes HTML-like files. No source file or test is named, so first identify the relevant detector or model evaluation entry point and reproduce the reported classifications. Done means the supplied HTA malware samples are no longer reported as generic HTML, with regression coverage for the behavior.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- html, rust
- Domain
- machine-learning, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100