logo

Use of CSS stuffing as an obfuscation technique?, (Fri, Nov 21st)

ID: 524763a4-2b17-5d24-a91f-a403e0ced079

STIX ID: report--524763a4-2b17-5d24-a91f-a403e0ced079

Feed Name: SANS ISC Diary

Threat Score
30/100

Date Published: 2025-11-21

Date Updated: 2026-04-19

...
...

The report analyzes a phishing credential-harvesting page hosted on Google Firebase Storage that unusually contained hundreds of kilobytes of unused, copy-pasted CSS (including bootstrap) and used <html lang="zxx">; the author proposes this "CSS stuffing" may be an attempt to evade heuristic or machine-learning based security filters by altering the page's statistical profile.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.