Obfuscated JavaScript, scam emails, and American Express
blog.jonlu.ca
blog.jonlu.ca
1. it would filter out security savvy individuals from the actual payload, who might report the scam.
2. it would map to the least security conscious individuals who would be the most likely to fall for it.
https://www.microsoft.com/en-us/research/publication/why-do-...
> By sending an email that repels all but the most gullible the scammer gets the most promising marks to self-select, and tilts the true to false positive ratio in his favor.
I mean the people who take the time to troll the scammer back want enjoyment out of it, and the chance of getting that enjoyment would seem to be heightened if the scammer seems more likely to be an idiot.
I did get an IRS scam VOIP number shutdown last week in about 15 minutes.
I remember many years ago I was sent a keylogger. I reversed it, found it was configured to upload keylogs to an FTP server on a free webhost, and promptly replaced the existing contents of it with as many copies of The Bible as would fit in the few MB of space available.
Unless of course they were clever enough to embed some fake cookie to track responses to specific emails...
The purpose of the obfuscation is 1) to prevent automated scanners and 2) prevent debugging of the script.
Since we did static analysis it did not impact the result.
(American Express is in fairness the one site that continued working ok as I recall)