Stepping Through JavaScript Obfuscation
ID: 68be76e9-5330-508d-8c1e-1d8b8090b95e
STIX ID: report--68be76e9-5330-508d-8c1e-1d8b8090b95e
Feed Name: Zscaler Security Research Blog
Threat Score
The report analyzes an instance of malicious IFRAME injection on a reputable website by demonstrating how obfuscated JavaScript (a long hex-encoded string decoded two characters at a time) can be deobfuscated to reveal the embedded iframe payload; the author walks through renaming functions, adding whitespace, and converting hex pairs to ASCII to show that JavaScript obfuscation is surmountable for analysts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
