generic_javascript_obfuscation in espaciopopup.com

On 2020-03-25T16:40:53.596284+00:00 we found pattern generic_javascript_obfuscation, type: Suspicious, (JavaScript obfuscation is frequently used to hide malicious code (or with hope to protect intellectual property)) in the page https://espaciopopup.com/wp-content/c... referenced from http://espaciopopup.com/ .

Code sample:

b'atob' … b'"borderBottomRightRadius"' … b'"borderBottomLeftRadius"' … b'"RequestAnimationFrame"' … b'"CancelRequestAnimationFrame"' … b'"triggerElementPosition"' … b'"RequestAnimationFrame"' … b'"CancelRequestAnimationFrame"' … b'"elementor/frontend/init"' … b'"elementor/frontend/init"' … b'"elementor/frontend/init"' … b'"elementor/frontend/init"' … b'"isSidebarFitsViewport"' … b'"requireArgumentInstance"' … b'"requireArgumentConstructor"' … b'"forceMethodImplementation"' … b'"forceMethodImplementation"' … b'"elementor/frontend/init"' … b'"onElementorFrontendInit"' … b'"onElementorFrontendComponentsInit"' … b'"setCloseButtonPosition"' … b'"removeBackgroundLayer"' … b'"updateBackgroundLayerSize"' … b'"defineBackgroundLayerDimensions"' … b'"initInteractionsTypes"' … b'"prepareSpecialActions"' … b'"getMovePointFromPassedPercents"' … b'"getEffectValueFromMovePoint"' … b'"getDirectionMovePoint"' … b'"removeAnimationClasses"' … b'"toggleOverlayHoverAnimation"' … b'"toggleOverlayContentAnimation"' … b'"toggleOverlayContentSequencedAnimation"' … b'"toggleImageHoverAnimation"' … b'"toggleAllAnimationsClasses"' … b'"toggleAnimationClasses"' … b'"galleriesNavigationListener"' … b'"setLightboxGalleryIndex"' … b'"handleNoHeadingsFound"' … b'"slideChangeTransitionStart"' … b'"slidesGridLengthChange"' … b'"beforeTransitionStart"' … b'"beforeTransitionStart"' … b'"slideResetTransitionStart"' … b'"slideChangeTransitionStart"' … b'"slideResetTransitionEnd"' … b'"slideNextTransitionEnd"' … b'"slidePrevTransitionEnd"' … b'"beforeSlideChangeStart"' … b'"beforeTransitionStart"' … b'"beforeTransitionStart"' … b'"getCurrentDeviceSetting"' … b'"initOnReadyComponents"' … b'"elementor/frontend/init"' … b'"attachDocumentsClasses"' … b'"onGeneralSettingsChange"' … b'"webkitRequestFullscreen"' … b'"webkitFullscreenElement"' … b'"webkitFullscreenEnabled"' … b'"webkitfullscreenerror"' … b'"webkitRequestFullScreen"' … b'"webkitCancelFullScreen"' … b'"webkitCurrentFullScreenElement"' … b'"webkitCancelFullScreen"' … b'"webkitfullscreenerror"' … b'"jetCountdownTimerExpire"' … b'"elementor/frontend/init"' … b"'elementor/frontend/init'" … b'"elementor/frontend/init"'

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).

Fully automated RESTful API is now available. Subscribe for your free trial today!