generic_javascript_obfuscation in urityofferencem.com

On 2019-11-27T02:55:23.861948+00:00 we found suspicious pattern generic_javascript_obfuscation, type: Suspicious, (JavaScript obfuscation is frequently used to hide malicious code (or with hope to protect intellectual property)) in the page https://urityofferencem.com/FDRMA?tag_i…

The suspicious code sample:

b'atob' … b'"eko0R1ohaA1paFhmFnBuTX8Ff3hWaFooLCV7AH9jSHgNfwUtI1ojNQ05a3ZqVHprBDIIJVkieFZoBXFjTn8MfmhNfgF+a097BnJjSWgYZWtMKFchY0orGXU/HH8Zcz5MehklY0J6GXU5T34Hfm9NKAclO1hmFgUVVzhREwIMAn52HxMSd341JRp1cTw0fwI0Di16VigzD35TABkDJn4COC04UiotAghDADYoe0w9axMbBT4THCh9cxAgKUE0Dw8aBSYxThlaMQsDfQQxKVhmFiQ2FTlRZXZYOFEjMwgvVzN4VmhGIj4TOFEkLlhmBGt4Ej5ANylfeXViaDxvBgEtDT0aNygfLl0kLhMlWiMpVClbKn9IDF4yNwpvBgE0HzJAaSoSOhF0HAhvBwNoS3wEdmlPbwZxKQ8oBWJpPm8BBQ0/CGcODj8DcGJvPmgYZT4VPVorNRsuazQ5CC9RKQUbOEYoLVhmFmV2WGgYZXhWLFUrKR9mUiY2CS8YHHgWIww'

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).

Fully automated RESTful API is now available. Subscribe for your free trial today!