generic_javascript_obfuscation in bohowhepsandked.info

On 2019-05-14T16:04:12.821061+00:00 we found suspicious pattern generic_javascript_obfuscation, type: Suspicious, (JavaScript obfuscation is frequently used to hide malicious code (or with hope to protect intellectual property)) in the page https://bohowhepsandked.info/VmJSTWsNQG…

The suspicious code sample:

b'atob' … b'atob' … b'"abcdwxyzstuvrqponmijklefghABCDWXY"' … b'"ZSTUVMNOPQRIJKLEFGH9876"' … b'"abcdwxyzstuvrqponmijklefghABCDWXYZS"' … b'"TUVMNOPQRIJKLEFGH9876543210+/"' … b'"abcdwxyzstuvrqponmijklefghABCDWXY"' … b'"ZSTUVMNOPQRIJKLEFGH987"' … b'"NOPQRIJKLEFGH9876543210+/"' … b'"QRSTUVWXYZabcdefghijk"' … b'"lmnopqrstuvwxyz0123456789"' … b"'applicationServerKey'" … b'"ZjF5TDQ9E09iAkQdW3sHVAhJfRZKE1tgFlMJQSgDVAdBYVdSAUFhAFRTHWFWUFBIYQwABUB5V1UGTi4HAxNVbgECARgoB1NXVHxQVglUeANXBlR1VlIAVHpVBAccdVBUABwqBkQdWy5bDl4OJFEWQhgiUA1UHWJdCFcWbmk"'

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).

Fully automated RESTful API is now available. Subscribe for your free trial today!