Obfuscated JavaScript, scam emails, and American Express

Obfuscated JavaScript, scam emails, and American Express

A = Card sequence number (starts with 1 and will increase by 1 each time a new account number is issued, usually due to theft or lost card)

BB = “00” for first primary card on the account. It’s unknown if their service was compromised and used to host malware, whether they’re a fake agency used as a front for distribution, or if they’re the actual ones behind the faux email. It performs an equality check with the first two entries of the array.

Source: blog.jonlu.ca