Zscaler Research: Heavy obfuscation used by fake antivirus websites

Just a few days back, I published a post discussing the popularity of fake antivirus websites in 2011. As I mentioned in the blog, attackers are continually creating new domains and websites promoting their fake software using various obfuscation techniques to hide their code from detection by IDS, IPS, antivirus etc.

Great post from Umesh, continuing his discussion of the obfuscation used to try and hide malware sites from prying eyes and to sneak their payload through to unsuspecting browsers.