generic_javascript_obfuscation in cdn.jifo.co

On 2020-03-26T06:23:43.888657+00:00 we found pattern generic_javascript_obfuscation, type: Suspicious, (JavaScript obfuscation is frequently used to hide malicious code (or with hope to protect intellectual property)) in the page https://cdn.jifo.co/js/dist/assets-em... referenced from https://koronawirusy.pl.tl/ .

Code sample:

b'\\x00' … b'\\x7F' … b'atob' … b'atob' … b'atob' … b'"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"' … b'"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"' … b'"abcdefghijklmnopqrst"' … b'"abcdefghijklmnopqrst"' … b'%25'

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).

Fully automated RESTful API is now available. Subscribe for your free trial today!