Hidden_iframe in syndication.exoclick.com

On 2018-06-06T19:25:09.355342+00:00 we found suspicious pattern Hidden_iframe, type: Suspicious, (Detect JavaScript injecting IFRAME injection using various HTML and CSS attributes to hide it.) in the page http://syndication.exoclick.com/splash.… referenced from http://hdselection.com/ .

The suspicious code sample:

document.write( … <iframe … height: 0 … display:none … hidden

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).

Fully automated RESTful API is now available. Subscribe for your free trial today!