Spotting Malicious JavaScript in a Page
ID: 6ab1ba93-9680-54ef-96f1-e6bfbece9dff
STIX ID: report--6ab1ba93-9680-54ef-96f1-e6bfbece9dff
Feed Name: Zscaler Security Research Blog
This report explains common attacker techniques for concealing malicious JavaScript on hijacked sites—pulling scripts from external domains, placing SCRIPT tags in unexpected locations (before <html>, after </body>, inside TITLE), using inconsistent coding styles, injecting code into existing JS files or CSS (expression()), and employing evasion checks such as IP denylisting, cookies, and Referer checks; examples and sample domains/file names are provided to illustrate detection cues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
