generic_javascript_obfuscation in internetpasoapaso.com

On 2019-08-13T14:02:38.420441+00:00 we found suspicious pattern generic_javascript_obfuscation, type: Suspicious, (JavaScript obfuscation is frequently used to hide malicious code (or with hope to protect intellectual property)) in the page https://internetpasoapaso.com/

The suspicious code sample:

b'atob' … b'"application/wlwmanifest+xml"' … b"'PGRpdiBjbGFzcz0nY29kZS1ibG9jayBjb2RlLWJsb2NrLTcnIHN0eWxlPSdtYXJnaW46IDhweCAwOyBjbGVhcjogYm90aDsnPgo8Y2VudGVyPjxkaXYgY2xhc3M9InZpc2libGUtbW9iaWxlIj48IS0tIElOVEVSTkVUUEFTT0FQQVNPIEJsb3F1ZSBFbmxhY2VzIERlc2NhcmdhIC0tPjxpbnMgY2xhc3M9ImFkc2J5Z29vZ2xlInN0eWxlPSJkaXNwbGF5OmJsb2NrO3dpZHRoOjEwMCUiZGF0YS1hZC1jbGllbnQ9ImNhLXB1Yi0zNDkzNjE2NjI1MjMyNjgyImRhdGEtYWQtc2xvdD0iNTQ0OTA3NTk1NiJkYXRhLWFkLWZvcm1hdD0ibGluayJkYXRhLWZ1bGwtd2lkdGgtcmVzcG9uc2l2ZT0idHJ1ZSI+PC9pbnM+PHNjcmlwdD4oYWRzYnlnb29nbGUgPSB3aW5kb3cuYWRzYnlnb29nbGU" … b'"application/javascript"'

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).

Fully automated RESTful API is now available. Subscribe for your free trial today!