generic_javascript_obfuscation5 in www.googletagmanager.com

On 2018-05-21T10:25:25.468895+00:00 we found pattern generic_javascript_obfuscation5, type: Suspicious, (JavaScript obfuscation is frequently used to hide malicious code (or with hope to protect intellectual property)) in the page https://www.googletagmanager.com/gtm.js… referenced from https://www.cookiebot.com/de/dsgvo-cook… .

Code sample:

b'["list",["map","fieldName","anonymizeIp","value","true"],["map","fieldName","displayFeaturesTask","value",["macro",' … b'["map","fieldName","anonymizeIp","value","true"],["map","fieldName","displayFeaturesTask","value",["macro",' … b'["list",["map","fieldName","anonymizeIp","value","true"],["map","fieldName","displayFeaturesTask","value",["macro",1]],["map","fieldName","r\xc2\x8a$\xc2\x89\xc3\xa0\xc3\xa8\xc2\x99\xc2\xa8\xc2\xa7","value",["macro",' … b'["map","fieldName","anonymizeIp","value","true"],["map","fieldName","displayFeaturesTask","value",["macro",1]],["map","fieldName","r\xc2\x8a$\xc2\x89\xc3\xa0\xc3\xa8\xc2\x99\xc2\xa8\xc2\xa7","value",["macro",' … b'["ecl"],r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l:["nonGooglePixels"],ecl:["cl"],ehl:["hl"],hl:["ehl"],html:["customScripts","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],customScripts:["html","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],nonGooglePixels:[],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl:["nonGooglePixels"],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac:["nonGooglePixels"]},wg={cl:["ecl"],r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l:["customScripts",' … b'["nonGooglePixels"],ecl:["cl"],ehl:["hl"],hl:["ehl"],html:["customScripts","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],customScripts:["html","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],nonGooglePixels:[],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl:["nonGooglePixels"],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac:["nonGooglePixels"]},wg={cl:["ecl"],r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l:["customScripts",' … b'["cl"],ehl:["hl"],hl:["ehl"],html:["customScripts","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],customScripts:["html","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],nonGooglePixels:[],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl:["nonGooglePixels"],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac:["nonGooglePixels"]},wg={cl:["ecl"],r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l:["customScripts",' … b'["hl"],hl:["ehl"],html:["customScripts","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],customScripts:["html","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],nonGooglePixels:[],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl:["nonGooglePixels"],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac:["nonGooglePixels"]},wg={cl:["ecl"],r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l:["customScripts",' … b'["ehl"],html:["customScripts","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],customScripts:["html","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],nonGooglePixels:[],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl:["nonGooglePixels"],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac:["nonGooglePixels"]},wg={cl:["ecl"],r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l:["customScripts",' … b'["customScripts","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],customScripts:["html","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],nonGooglePixels:[],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl:["nonGooglePixels"],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac:["nonGooglePixels"]},wg={cl:["ecl"],r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l:["customScripts",'

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).

Fully automated RESTful API is now available. Subscribe for your free trial today!