generic_javascript_obfuscation in wrontonshatbona.pro

On 2019-09-07T08:53:28.258031+00:00 we found suspicious pattern generic_javascript_obfuscation, type: Suspicious, (JavaScript obfuscation is frequently used to hide malicious code (or with hope to protect intellectual property)) in the page https://wrontonshatbona.pro/?tid=737122…

The suspicious code sample:

b'atob' … b'"aTRGQ0oyFn9te0sYZHR5XgV0cWhFFjYnOQJrd3d6Xgx+e2hFFndwf1kDdnF9XgNwdXNaDXZxaEUWICZ9CARye3NEUiVxL0QAfnMoRFYlIS9EAnN3fF1Vf3UvCFd+YWZLdgEgBFFAAysPE1Z1DiFdTgEkOx8HACInC1EJCxkMDRIOOTxeFBoNI3UnDwQbQiIhGAZZPjEiIncFOzMIBioZGhl8KiIYAFwOOyEhZRkzBgRcPgAcMGw1YWZLVyosOQwWamE4DFAvMS8KQGRvaBtRIio4DFcyYWZZGGQrPh1ENWZ5KBF0BW9bciQmOR1VIiEjDRolLCdMBgAiLBwaNis6TAcAOSUHUS8nb1pwdHN8UAJ3e29bAjAiOEwHAmFmS1slNxVYB2RvaEsYZGFmSxZqJSsFRyNvLAhYNSZmB0EqL2ZEBWphaEVSJy85DBgoNiYFGCg2JgUYZDEvDV00JikdFmolKwVHI28sCFg1JmYPVSowL0VSJy85DBhkMS8NXTQ'

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).

Fully automated RESTful API is now available. Subscribe for your free trial today!