logo

Quick & Dirty Obfuscated JavaScript Analysis, (Sun, Nov 24th)

ID: 97ac5926-01ad-52a8-9992-9e0a827649cf

STIX ID: report--97ac5926-01ad-52a8-9992-9e0a827649cf

Feed Name: SANS ISC Diary

Threat Score
45/100

Date Published: 2024-11-24

Date Updated: 2026-04-19

...
...

This brief analysis by Didier Stevens demonstrates a quick dynamic technique to analyze a phishing SVG with obfuscated JavaScript: running the SVG in Edge inside an offline VM, using Developer Tools and the Network tab to capture the deobfuscated download URL and payload. The write-up includes screenshots and links to the sample on VirusTotal and serves as a practical method to extract indicators from obfuscated phishing SVG attachments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.