MALWARE-OTHER --
MALWARE-OTHER Js.Infostealer.ClickFix download attempt
This rule triggers on an obfuscated javascript payload that is used for a phishing attack. It specifically is looking for the XOR decryption loop used commonly by ClickFix to obfuscate malacious intent.
This rule triggers on an obfuscated javascript payload that is used for a phishing attack
Attacks/Scans seen in the wild
No known false positives
Cisco Talos Intelligence Group
No rule groups
None
No information provided
None