generic_javascript_obfuscation in nsevermatold.info

On 2019-07-09T11:32:34.442235+00:00 we found suspicious pattern generic_javascript_obfuscation, type: Suspicious, (JavaScript obfuscation is frequently used to hide malicious code (or with hope to protect intellectual property)) in the page https://nsevermatold.info/LJWNYDZ?tag_i…

The suspicious code sample:

b'atob' … b'"eUl5a0kia0FFfVtlW1x5QHlMXWtVa1tHa0x9Tlt4SHBPWHtJfEtScU17SV5rVWsfWnlBLUoNcFR4Sg15VH1ODypUcUxffFR5QA0tTn9PXHkcLRtJZVsLMA8OPwUqGx87IBQaKkEqKAY/GBYwIzBULg9fDxQiMwksH3AtAhMQfh0iORR/DCoQGgJIDi08AykMDBUAHgEIOyUeOAsMJzNbMTw/AwkcTQY8JgQqP01JZVsqFQQ6HGtVSSoVJgoOa1VrGgcmCixbR3lVa1tHaxooCR8qEShbR2tbZVtJZVtrVQ0oFTocRy8YJQoOZSJrCVprVWsJWWtVawlYa1VrCV9rVWsJXmtVawlda1VrCVxrVWsJU2tVawlSa1VrCVp5WxRVXGVba1UNKBU6HEcnDCUVRycMJRVHaxolFhgsW2UfCiUKLFUNKBU6HEcvGCUKDmUfKBUYLCQ"'

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).

Fully automated RESTful API is now available. Subscribe for your free trial today!