generic_javascript_obfuscation in static.xx.fbcdn.net

On 2020-01-15T12:01:43.767207+00:00 we found pattern generic_javascript_obfuscation, type: Suspicious, (JavaScript obfuscation is frequently used to hide malicious code (or with hope to protect intellectual property)) in the page https://static.xx.fbcdn.net/rsrc.php/... referenced from https://aromatizate-matanzas.com/ .

Code sample:

b'var e=[],f=[];c=a.replace(h,~\xe9\xdc\xb6*\'(a,c,g){a=d[c];if(a!=null&&typeof a==="object"){e.push(a);f.push(c);return"\\x17"+g}else if(a===null)return"";return String(a)+(b("IntlPunctuation").endsInPunct(String(a))?"":g)}).split("\\x17' … b'\\x02' … b'\\x01' … b'\\x01' … b'\\x01' … b'\\x02' … b'\\xbb' … b'\\x01' … b'\\x17' … b'\\x17' … b'"IntlVariationResolverImpl"' … b'"IntlVariationResolver"' … b'"IntlVariationResolverImpl"' … b'"IntlVariationResolverImpl"' … b'"IntlVariationResolverImpl"' … b'"IntlVariationResolverImpl"' … b'"IntlPhonologicalRules"' … b'"IntlPhonologicalRules"' … b'"IntlVariationResolver"' … b'"IntlVariationResolver"' … b'"IntlVariationResolver"' … b'"replaceTransportMarkers"' … b'"setTimeoutAcrossTransitions"' … b'"handleErrorAfterUnload"' … b'"replaceTransportMarkers"' … b'"useFetchWithIframeFallback"' … b'"useFetchWithIframeFallback"' … b'"useFetchWithIframeFallback"' … b'"setTimeoutAcrossTransitions"' … b'"suppressErrorHandlerWarning"' … b'"useFetchWithIframeFallback"' … b'"useFetchWithIframeFallback"' … b'"useFetchWithIframeFallback"' … b'"useFetchWithIframeFallback"' … b'"useFetchWithIframeFallback"' … b'"TimeSliceAutoclosedInteraction"' … b'"setTimeoutAcrossTransitions"' … b'"XControllerURIBuilder"' … b'"StringToNullableStringMap"' … b'"StringToNullableIntDict"' … b'"StringToNullableFloatDict"' … b'"StringToNullableStringDict"' … b'"EnumToNullableEnumMap"' … b'"EnumToNullableFloatMap"' … b'"EnumToNullableStringMap"' … b'"IntToNullableFloatMap"' … b'"IntToNullableStringMap"' … b'"StringToNullableEnumMap"' … b'"StringToNullableIntMap"' … b'"StringToNullableStringMap"' … b'"EnumToNullableEnumMap"' … b'"EnumToNullableFloatMap"' … b'"EnumToNullableStringMap"' … b'"IntToNullableFloatMap"' … b'"IntToNullableStringMap"' … b'"StringToNullableEnumMap"' … b'"StringToNullableIntMap"' … b'"StringToNullableStringMap"' … b'"XControllerURIBuilder"' … b'"XControllerURIBuilder"' … b'"XSharePluginLoggingController"' … b'"/platform/plugin/share/logging/"' … b'"XSharePluginLoggingController"' … b'"XSharePluginLoggingController"'

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).

Fully automated RESTful API is now available. Subscribe for your free trial today!