Heavy Obfuscation Used By Fake Antivirus Websites
ID: 677f8c8a-bf26-58cd-8581-676935d08ef7
STIX ID: report--677f8c8a-bf26-58cd-8581-676935d08ef7
Feed Name: Zscaler Security Research Blog
Threat Score
This report analyzes a set of malicious fake‑antivirus web pages that use multi-layer, randomized JavaScript obfuscation to render frightening security warnings and coerce visitors into downloading fake AV installers that lead to further malware. The author decodes the layered scripts with Malzilla, documents the consistent obfuscation structure (only variable names randomized), and highlights that the heavy obfuscation reduces detection by antivirus solutions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
