@malware_traffic @bartblaze I received a view phishes this morning with weak obfuscation:
http://pastebin.com/masR2Nmy & http://pastebin.com/ZfCHYPtr
-
-
Replying to @thlnk3r
@malware_traffic@bartblaze I included the .js contents in the pastebin. Look for "rwqjG.open". You can easily deobfuscate the URL lol1 reply 0 retweets 0 likes -
Replying to @thlnk3r
@malware_traffic@bartblaze I believe these ultimately lead to Locky2 replies 0 retweets 0 likes
Replying to @thlnk3r
@thlnk3r @malware_traffic Yep, see also: https://isc.sans.edu/forums/diary/Locky+JavaScript+Deobfuscation/20749/ …
5:32 AM - 11 Mar 2016
0 replies
0 retweets
1 like
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.