generic_javascript_obfuscation in rinoverrop.pro

On 2019-10-04T21:03:49.416599+00:00 we found suspicious pattern generic_javascript_obfuscation, type: Suspicious, (JavaScript obfuscation is frequently used to hide malicious code (or with hope to protect intellectual property)) in the page https://rinoverrop.pro/HCY?tag_id=69771…

The suspicious code sample:

b'atob' … b'"azFxV0swE0h5eUkdU2FyXAZAZWlHE1N7aVMDRGJ7WwVCYHpdBUNkeFMDRGdpRxNBNHNSB0hvLUZVEzF8RgUUNXtGCUY0fEYERTV8XAFIZHgPVxV1Z0lzM2USPVYBAho9dSU9LF9oHRU4I0keMjwsBx0hDyoJGxUKCH40bw1dRxUbLF9/EDR/OXJAGwgbYhM/BSxUHBZ8AHAIOw4uCCRlMxF0JwUqPGggOi4DeRZ1Z0lDFDMiGVQSI2lHEwMyLwJDFDQ/SR1TJS4PWAMyKB8TXWdnSVkFIzsYFEIWbll3VGUNGUQcPiYEQxgwPkVYHzEkTgM3cngtRRgzblh1R258XABDcnldXx44KBsUQhN6SR1TOiQdWBR6KgddHiBmWBNddWlHE1N7aUkdFzYnGFRdMSoHQhR7EElBQHVnSUFDdWdJQUJ1Z0lBRXVnSUFEdWdJQUd1Z0lBRnVnSUFJdWdJQUh1Z0lBQGdpNh1Ge2lJHRc2JxhUXTk+B11dOT4HXV1'

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).

Fully automated RESTful API is now available. Subscribe for your free trial today!