generic_javascript_obfuscation in wrontonshatbona.pro

On 2019-09-07T08:53:28.258031+00:00 we found suspicious pattern generic_javascript_obfuscation, type: Suspicious, (JavaScript obfuscation is frequently used to hide malicious code (or with hope to protect intellectual property)) in the page https://wrontonshatbona.pro/?tid=737122…

The suspicious code sample:

b'atob' … b'"R1hMSTccenVnBmV0bn4EcGl+exVrejwtRCwHfX0HcGB0cRVrenlxD3Jof3AAfmp0eQ51b319AXN6YGtVIjl5cVR3a2F+ViM6YX0EdmphcAN+aGF/VnBoeS1WcTl4fFRldG4LfSYBOzMacCIAE3kuH3RkQQ4xLyRPBBcoDmYuHzQWUnIIHCFDMA0YDlYOKgouQygHPSMGABYtLGIuLDQxeh0cfCMHNWopEEIQGnsrDy0ZEx5wdSAvDm5ldG4qWygrKWsbZSopLV41PS89FWt6PixTLiopKkNldHxlFS8sODlEYmsNbAUBfX4PVSIrOChTJTEoZ1QoNWl7cSY+OWdHLyhpenE9NyIsXiN9fw0Fd251fwZ/fX5/QSYqaXpzZXRuJlQzB316FWt6bmUVZXRuaxshOSA6Ums+LSVEInQiPFsrdGF4G2V6YC9WKyspZVkyNCBlWTI0IGUVNT0oIEUiOzhrGyE5IDpSaz4tJUQidCooWzQ9YC9WKyspZRU1PSg'

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).

Fully automated RESTful API is now available. Subscribe for your free trial today!