generic_javascript_obfuscation in cotozachoroba.pl

On 2019-07-11T05:33:37.546283+00:00 we found suspicious pattern generic_javascript_obfuscation, type: Suspicious, (JavaScript obfuscation is frequently used to hide malicious code (or with hope to protect intellectual property)) in the page https://cotozachoroba.pl/badania-i-wizy…

The suspicious code sample:

b'atob' … b'"application/wlwmanifest+xml"' … b'"application/json+oembed"' … b"'ajaxsearchlitesettings1'" … b'"ew0KICAgICJob21ldXJsIjogImh0dHBzOi8vY290b3phY2hvcm9iYS5wbC8iLA0KICAgICJyZXN1bHRzdHlwZSI6ICJ2ZXJ0aWNhbCIsDQogICAgInJlc3VsdHNwb3NpdGlvbiI6ICJob3ZlciIsDQogICAgIml0ZW1zY291bnQiOiA0LA0KICAgICJpbWFnZXdpZHRoIjogNzAsDQogICAgImltYWdlaGVpZ2h0IjogNzAsDQogICAgInJlc3VsdGl0ZW1oZWlnaHQiOiAiNzBweCIsDQogICAgInNob3dhdXRob3IiOiAwLA0KICAgICJzaG93ZGF0ZSI6IDAsDQogICAgInNob3dkZXNjcmlwdGlvbiI6IDEsDQogICAgImNoYXJjb3VudCI6ICAwLA0KICAgICJkZWZhdWx0SW1hZ2UiOiAiaHR0cHM6Ly9jb3RvemFjaG9yb2JhLnBsL3dwLWNvbnRlbnQvcGx1Z2lucy9hamF4LXNlYXJjaC1' … b"'ajaxsearchlitesettings2'" … b'"ew0KICAgICJob21ldXJsIjogImh0dHBzOi8vY290b3phY2hvcm9iYS5wbC8iLA0KICAgICJyZXN1bHRzdHlwZSI6ICJ2ZXJ0aWNhbCIsDQogICAgInJlc3VsdHNwb3NpdGlvbiI6ICJob3ZlciIsDQogICAgIml0ZW1zY291bnQiOiA0LA0KICAgICJpbWFnZXdpZHRoIjogNzAsDQogICAgImltYWdlaGVpZ2h0IjogNzAsDQogICAgInJlc3VsdGl0ZW1oZWlnaHQiOiAiNzBweCIsDQogICAgInNob3dhdXRob3IiOiAwLA0KICAgICJzaG93ZGF0ZSI6IDAsDQogICAgInNob3dkZXNjcmlwdGlvbiI6IDEsDQogICAgImNoYXJjb3VudCI6ICAwLA0KICAgICJkZWZhdWx0SW1hZ2UiOiAiaHR0cHM6Ly9jb3RvemFjaG9yb2JhLnBsL3dwLWNvbnRlbnQvcGx1Z2lucy9hamF4LXNlYXJjaC1'

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).

Fully automated RESTful API is now available. Subscribe for your free trial today!