Use of CSS stuffing as an obfuscation technique?, (Fri, Nov 21st)
ID: 524763a4-2b17-5d24-a91f-a403e0ced079
STIX ID: report--524763a4-2b17-5d24-a91f-a403e0ced079
Feed Name: SANS ISC Diary
Threat Score
The report analyzes a phishing credential-harvesting page hosted on Google Firebase Storage that unusually contained hundreds of kilobytes of unused, copy-pasted CSS (including bootstrap) and used <html lang="zxx">; the author proposes this "CSS stuffing" may be an attempt to evade heuristic or machine-learning based security filters by altering the page's statistical profile.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
