Quick & Dirty Obfuscated JavaScript Analysis, (Sun, Nov 24th)
ID: 97ac5926-01ad-52a8-9992-9e0a827649cf
STIX ID: report--97ac5926-01ad-52a8-9992-9e0a827649cf
Feed Name: SANS ISC Diary
Threat Score
This brief analysis by Didier Stevens demonstrates a quick dynamic technique to analyze a phishing SVG with obfuscated JavaScript: running the SVG in Edge inside an offline VM, using Developer Tools and the Network tab to capture the deobfuscated download URL and payload. The write-up includes screenshots and links to the sample on VirusTotal and serves as a practical method to extract indicators from obfuscated phishing SVG attachments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
