logo

More And More Obfuscation Being Used In The Malicious Script

ID: 9f2ae52b-6c2a-5628-a8cb-d35bbccadc98

STIX ID: report--9f2ae52b-6c2a-5628-a8cb-d35bbccadc98

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report documents discovery and manual deobfuscation of a heavily obfuscated JavaScript injection that loads a malicious PDF from a remote URL; the PDF exploits multiple Adobe Reader vulnerabilities. Automated tools struggled with the obfuscation, the author details step-by-step decoding to reveal the exploit chain, and network capture confirms retrieval of the malicious PDF which had low detection rates on VirusTotal.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.