Skip to content

Malicious Activity Observed During Browser Interaction

It indicates that malicious behavior was detected only during dynamic browser interaction—such as JavaScript execution, redirects, or AJAX calls—rather than in static content. This suggests the domain hides its payload or redirects until a real browser session is established.

Also surfaces as:
Risky Domain Accessed During Browser InteractionDirect IP Connection Initiated During Browser Interaction
Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'Malicious Activity Observed During Browser Interaction' mean?

It indicates that malicious behavior was detected only during dynamic browser interaction—such as JavaScript execution, redirects, or AJAX calls—rather than in static content. This suggests the domain hides its payload or redirects until a real browser session is established.

Why it matters02

Why is this considered a strong indicator of malicious activity?

Threat actors often embed payloads that activate only when real browsers trigger specific events or cookies. This technique helps them evade static crawlers and signature-based detections, making such findings highly suspicious in SOC and CTI investigations.

How analysts use it03

What does 'Direct IP Connection Initiated During Browser Interaction' indicate?

It means the browser established a direct connection to a raw IP address instead of a domain. This is often used to bypass DNS-based detection and is a known tactic in malicious web infrastructure.

Often paired with:alert_only
Evidence shape

What Malicious Activity Observed During Browser Interaction looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "browser_interaction",
  "name": "Malicious Activity Observed During Browser Interaction",
  "group": "http_crawling_history",
  "subgroup": "web_behavior_structure",
  "direction": "malicious",
  "evidence": {
    "url_shortener_chain": false,
    "auto_refresh_seconds": null,
    "direct_ip_link": false,
    "browser_interaction_required": true
  }
}
See in API reference
Siblings

Peers in Web Behavior & Structure

7 other signals share the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Injected Iframe

An injected iframe refers to an HTML frame embedded within a web page that loads content from an external or malicious d

MaliciousCore
Malicious Redirect Behavior

It refers to the automatic forwarding of a user or system request from one domain to another destination. Redirects can

MaliciousCore
Direct Connection to an IP Address

It refers to the action of accessing a resource using a direct IP address instead of a domain name. Threat actors often

Malicious
HTTP Service on Non-standard Port

It refers to a web server or website delivering HTTP or HTTPS content through ports other than the standard 80 (HTTP) an

Malicious
Show 3 more in Web Behavior & Structure
In the wild

See Malicious Activity Observed During Browser Interaction fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to Malicious Activity Observed During Browser Interaction. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.