logo

Obfuscated JavaScript or Nothing, (Thu, Apr 9th)

ID: 1b068488-4d27-5e96-8286-4d05f40822df

STIX ID: report--1b068488-4d27-5e96-8286-4d05f40822df

Feed Name: SANS ISC Diary

Threat Score
70/100

Date Published: 2026-04-10

Date Updated: 2026-04-19

...
...

This analysis describes a phishing-delivered, obfuscated Windows JavaScript (SHA256:a8ba9b...) that copies itself, creates scheduled-task persistence, and drops three PNG files; a PowerShell launcher decodes AES-encrypted blobs from those PNGs to produce a .NET DLL (SHA256:53c3e0...) which is injected into MSBuild to load a Formbook infostealer; the chain includes AMSI/ETW patching and provides multiple IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.