A polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)
ID: f335dff0-5c6f-5e7f-9aad-58cc8b6786a4
STIX ID: report--f335dff0-5c6f-5e7f-9aad-58cc8b6786a4
Feed Name: SANS ISC Diary
This report examines a polymorphic phishing page that serves credential‑stealing HTML generated in varying obfuscated forms per visit. The analyst found that randomized JavaScript variants produced unique source code and identifiers; in a small number of samples a bug (shared undeclared global loop counter) caused an infinite decode loop, rendering the page non‑functional. The writeup describes the obfuscation techniques, the impact on detection, and considers (but does not confirm) whether an LLM or a conventional obfuscator generates the variants.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
