generic_javascript_obfuscation in dalingleftwa.info

On 2019-08-07T03:11:02.829563+00:00 we found suspicious pattern generic_javascript_obfuscation, type: Suspicious, (JavaScript obfuscation is frequently used to hide malicious code (or with hope to protect intellectual property)) in the page https://dalingleftwa.info/LJWNYDZ?tag_i…

The suspicious code sample:

b'\\x61' … b'\\x61' … b'\\x64' … b'\\x65' … b'\\x75' … b'\\x67' … b'\\x72' … b'\\x69' … b'\\x74' … b'\\x6f' … b'\\x6e' … b'\\x28' … b'\\x78' … b'\\x21' … b'atob' … b'"TnJqaGcVUFJGU2xeSF9Xd0JfXkViUEhERXtGXVhWf0tcW1V+R1hRX3pAWl1FYlAMWVd2FlkOXmNDWQ5XY0ZdDARjSl9cUmNCUw4DeURcX1crFghKS2wwKTwePwonMTA/GV8AKTogOgcdFhpcIyAGAAc+CB45NSMXIQQsKwR4OBkSVyBKX1pWOjshMiMhGFkcOAEHMisRFDMwXjh+NlwyJSQTGEU2NxsvDiIgORlKS2wRBgcUK1BGSgQiHRkNRWJQCQQIPRdIRFdiUEhERS0TGhwEJhNIREVsXkhKS2xQRg4GIgEPRAEvHhkNSxVQGllFYlAaWkViUBpbRWJQGlxFYlAaXUViUBpeRWJQGl9FYlAaUEViUBpRRWJQGllXbC9GXktsAlJKSygTBhsCYhwfBAtiHB8EC2JQCQQIPRdIRAEvHhkNSygTBhsCYhQLBBQrXgwJCz0XRkoEIh0ZDUUT"'

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).

Fully automated RESTful API is now available. Subscribe for your free trial today!