More And More Obfuscation Being Used In The Malicious Script
ID: 9f2ae52b-6c2a-5628-a8cb-d35bbccadc98
STIX ID: report--9f2ae52b-6c2a-5628-a8cb-d35bbccadc98
Feed Name: Zscaler Security Research Blog
Threat Score
This report documents discovery and manual deobfuscation of a heavily obfuscated JavaScript injection that loads a malicious PDF from a remote URL; the PDF exploits multiple Adobe Reader vulnerabilities. Automated tools struggled with the obfuscation, the author details step-by-step decoding to reveal the exploit chain, and network capture confirms retrieval of the malicious PDF which had low detection rates on VirusTotal.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
