generic_javascript_obfuscation in d10lpsik1i8c69.cloudfront.net

On 2020-03-25T16:31:38.966989+00:00 we found pattern generic_javascript_obfuscation, type: Suspicious, (JavaScript obfuscation is frequently used to hide malicious code (or with hope to protect intellectual property)) in the page https://d10lpsik1i8c69.cloudfront.net... referenced from http://kbmax.com/ .

Code sample:

b'atob' … b'atob' … b'atob' … b'atob' … b'atob' … b'"getAllResponseHeaders"' … b'"LoChatMinimizedButton"' … b'"InvalidCharacterError"' … b'"removeUnchangedAttrChanges"' … b'"convertChangesIntoArray"' … b'"ABCDEFGHIJKLMNOPQRSTUVWXYZ"'

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).

Fully automated RESTful API is now available. Subscribe for your free trial today!