Hidden_iframe in www.icarro.net

On 2019-07-09T23:23:15.196482+00:00 we found suspicious pattern Hidden_iframe, type: Suspicious, (Detect JavaScript injecting IFRAME injection using various HTML and CSS attributes to hide it.) in the page https://www.icarro.net/2019/05/mountune…

The suspicious code sample:

b'document.write(' … b'document.write(' … b'document.write(' … b'<iframe' … b'display:none' … b'display:none' … b' hidden' … b'display:none' … b'display:none' … b' hidden' … b'display:none' … b' hidden' … b'display:none' … b'display:none' … b' hidden' … b'display: none' … b' hidden' … b' hidden' … b'display:none' … b'display:none' … b'display:none' … b'display:none' … b'display:none' … b' hidden' … b' hidden' … b' hidden' … b'display:none' … b' hidden' … b' hidden' … b' hidden' … b' hidden' … b' hidden' … b' hidden' … b'display:none' … b'display:none' … b'display:none' … b'display:none' … b'display:none' … b'display:none' … b' hidden' … b" width='0" … b" height='0"

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).

Fully automated RESTful API is now available. Subscribe for your free trial today!