{"success":true,"data":{"id":"html-comment-prose-payload","label":"Body HTML has a long comment with prose text — classifier-evasion via hidden filler or keyword-stuffing","description":"The HTML body contains an `<!-- ... -->` comment block ≥ 500 characters long with at least 50 alphabetic word chars of prose content. This is a classifier-evasion technique with two attack shapes: (1) **filler text injection** — attackers paste a few hundred chars of clean prose (Wikipedia paragraphs, news headlines) inside a comment to \"balance\" their classifier reputation, while the visible body is a tiny phish CTA; the bag-of-words scanner sees mostly normal text. (2) **keyword-stuffing** — attackers paste known-bad keywords (verify, password, login, urgent) inside a comment to confuse \"did the classifier see suspicious words?\" detectors. Outlook conditional comments (`<!--[if mso]>` / `<!--[if !mso]>` / `<![endif]>`) are explicitly excluded because they're legitimate compatibility markers used by every major ESP. Weighted at +2 — modest because some enterprise mail tooling does include long comment blocks for compatibility shims, so it pairs with other body signals rather than solo-firing.","tier":"danger","category":"other","isThin":false}}