MEDIUMPhishing
Global

Obfuscated JavaScript or Nothing, (Thu, Apr 9th)

·Source: SANS ISC

Updated:

Executive Summary

I spotted an interesting piece of JavaScript code that was delivered via a phishing email in a RAR archive. The file was called “cbmjlzan.JS” (SHA256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b74c5285) and is only identified as malicious by 15 AV&#x27s on VirusTotal[1].

Analysis

I spotted an interesting piece of JavaScript code that was delivered via a phishing email in a RAR archive. The file was called “cbmjlzan.JS” (SHA256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b74c5285) and is only identified as malicious by 15 AV&#x27s on VirusTotal[1].

Indicators of Compromise (1)

SHA-256 (1)
a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b74c5285
Source Attribution

Originally published by SANS ISC on Apr 10, 2026.

Related Threats