generic_javascript_obfuscation5 in maps.googleapis.com

On 2020-03-11T22:18:33.259340+00:00 we found pattern generic_javascript_obfuscation5, type: Suspicious, (JavaScript obfuscation is frequently used to hide malicious code (or with hope to protect intellectual property)) in the page https://maps.googleapis.com/maps/api/js… referenced from https://www.terabilisim.com/blog/phishi… .

Code sample:

b'["https://khms0.googleapis.com/kh?v=865&hl=tr&gl=TR&","https://khms1.googleapis.com/kh?v=865&hl=tr&gl=TR&"],null,null,null,1,"865",["https://khms0.google.com/kh?v=865&hl=tr&gl=TR&","https://khms1.google.com/kh?v=865&hl=tr&gl=TR&"]],null,null,null,null,[["https://cbks0.googleapis.com/cbk?","https://cbks1.googleapis.com/cbk?"]],[["https://khms0.googleapis.com/kh?v=127&hl=tr&gl=TR&","https://khms1.googleapis.com/kh?v=127&hl=tr&gl=TR&"],null,null,null,null,"127",["https://khms0.google.com/kh?v=127&hl=tr&gl=TR&"' … b'["https://khms0.google.com/kh?v=865&hl=tr&gl=TR&","https://khms1.google.com/kh?v=865&hl=tr&gl=TR&"]],null,null,null,null,[["https://cbks0.googleapis.com/cbk?","https://cbks1.googleapis.com/cbk?"]],[["https://khms0.googleapis.com/kh?v=127&hl=tr&gl=TR&","https://khms1.googleapis.com/kh?v=127&hl=tr&gl=TR&"],null,null,null,null,"127",["https://khms0.google.com/kh?v=127&hl=tr&gl=TR&","https://khms1.google.com/kh?v=127&hl=tr&gl=TR&"]]],["tr","TR",null,0,null,null,"https://maps.gstatic.com/mapfiles/",null,"https:/' … b'["https://cbks0.googleapis.com/cbk?","https://cbks1.googleapis.com/cbk?"]],[["https://khms0.googleapis.com/kh?v=127&hl=tr&gl=TR&","https://khms1.googleapis.com/kh?v=127&hl=tr&gl=TR&"],null,null,null,null,"127",["https://khms0.google.com/kh?v=127&hl=tr&gl=TR&","https://khms1.google.com/kh?v=127&hl=tr&gl=TR&"]]],["tr","TR",null,0,null,null,"https://maps.gstatic.com/mapfiles/",null,"https://maps.googleapis.com","https://maps.googleapis.com",null,"https://maps.google.com",null,"https://maps.gstatic.com/maps-api' … b'["https://khms0.googleapis.com/kh?v=127&hl=tr&gl=TR&","https://khms1.googleapis.com/kh?v=127&hl=tr&gl=TR&"],null,null,null,null,"127",["https://khms0.google.com/kh?v=127&hl=tr&gl=TR&","https://khms1.google.com/kh?v=127&hl=tr&gl=TR&"]]],["tr","TR",null,0,null,null,"https://maps.gstatic.com/mapfiles/",null,"https://maps.googleapis.com","https://maps.googleapis.com",null,"https://maps.google.com",null,"https://maps.gstatic.com/maps-api-v3/api/images/","https://www.google.com/maps",0,"https://www.google.com"],[' … b'["https://khms0.google.com/kh?v=127&hl=tr&gl=TR&","https://khms1.google.com/kh?v=127&hl=tr&gl=TR&"]]],["tr","TR",null,0,null,null,"https://maps.gstatic.com/mapfiles/",null,"https://maps.googleapis.com","https://maps.googleapis.com",null,"https://maps.google.com",null,"https://maps.gstatic.com/maps-api-v3/api/images/","https://www.google.com/maps",0,"https://www.google.com"],["https://maps.googleapis.com/maps-api-v3/api/js/41/1/intl/tr_ALL","3.41.1"],[2939648417],null,"google-maps-embed",null,[35,39,1,2,3,8,' … b'["tr","TR",null,0,null,null,"https://maps.gstatic.com/mapfiles/",null,"https://maps.googleapis.com","https://maps.googleapis.com",null,"https://maps.google.com",null,"https://maps.gstatic.com/maps-api-v3/api/images/","https://www.google.com/maps",0,"https://www.google.com"],["https://maps.googleapis.com/maps-api-v3/api/js/41/1/intl/tr_ALL","3.41.1"],[2939648417],null,"google-maps-embed",null,[35,39,1,2,3,8,11,14,15,17,18,20,21,23,24,26,32,45,47,48,88,30,10,51,63,68,71,72,76,78,81,85,102,103,104,105,106,117,' … b'["https://maps.googleapis.com/maps-api-v3/api/js/41/1/intl/tr_ALL","3.41.1"],[2939648417],null,"google-maps-embed",null,[35,39,1,2,3,8,11,14,15,17,18,20,21,23,24,26,32,45,47,48,88,30,10,51,63,68,71,72,76,78,81,85,102,103,104,105,106,117,118,121,114,123,127,131],null,null,"onApiLoad",["\xc2\x81\xc3\xaa&z\xc3\x9a\xc3\xb2","search"],null,1,"https://khms.googleapis.com/mz?v=865&",null,"https://earthbuilder.googleapis.com","https://earthbuilder.googleapis.com",null,"https://mts.googleapis.com\xc3\xbef\xc2\xa9\xc2\xb3\xc3\xbb\xc3\xad/icon",[["\xc3\xbef\xc2\xa9\xc2\xb3\xc3\xbb\xc3\xad"],["\xc3\xbef\xc2\xa9\xc2\xb3' … b'["\xc2\x81\xc3\xaa&z\xc3\x9a\xc3\xb2","search"],null,1,"https://khms.googleapis.com/mz?v=865&",null,"https://earthbuilder.googleapis.com","https://earthbuilder.googleapis.com",null,"https://mts.googleapis.com\xc3\xbef\xc2\xa9\xc2\xb3\xc3\xbb\xc3\xad/icon",[["\xc3\xbef\xc2\xa9\xc2\xb3\xc3\xbb\xc3\xad"],["\xc3\xbef\xc2\xa9\xc2\xb3\xc3\xbb\xc3\xad"],null,null,null,null,null,null,null,null,null,null,["\xc3\xbef\xc2\xa9\xc2\xb3\xc3\xbb\xc3\xad"],"\xc3\xbef\xc2\xa9\xc2\xb3\xc3\xbb\xc3\xad",514000000,514,514228847],2,500,[null,null,null,null,"https://www.google.com/maps/preview/log204","","https://static.panoramio.com.storage.googleapis.com/photos/",["https://geo0.ggpht.com/cbk","http' … b'["\xc3\xbef\xc2\xa9\xc2\xb3\xc3\xbb\xc3\xad"],["\xc3\xbef\xc2\xa9\xc2\xb3\xc3\xbb\xc3\xad"],null,null,null,null,null,null,null,null,null,null,["\xc3\xbef\xc2\xa9\xc2\xb3\xc3\xbb\xc3\xad"],"\xc3\xbef\xc2\xa9\xc2\xb3\xc3\xbb\xc3\xad",514000000,514,514228847],2,500,[null,null,null,null,"https://www.google.com/maps/preview/log204","","https://static.panoramio.com.storage.googleapis.com/photos/",["https://geo0.ggpht.com/cbk","https://geo1.ggpht.com/cbk","https://geo2.ggpht.com/cbk","https://geo3.ggpht.com/cbk"],"https://maps.googleapis.com/maps/api/js/GeoPhotoService.GetMetadata","https://maps.googleapis.com/maps/api/js/GeoPhotoS' … b'["\xc3\xbef\xc2\xa9\xc2\xb3\xc3\xbb\xc3\xad"],null,null,null,null,null,null,null,null,null,null,["\xc3\xbef\xc2\xa9\xc2\xb3\xc3\xbb\xc3\xad"],"\xc3\xbef\xc2\xa9\xc2\xb3\xc3\xbb\xc3\xad",514000000,514,514228847],2,500,[null,null,null,null,"https://www.google.com/maps/preview/log204","","https://static.panoramio.com.storage.googleapis.com/photos/",["https://geo0.ggpht.com/cbk","https://geo1.ggpht.com/cbk","https://geo2.ggpht.com/cbk","https://geo3.ggpht.com/cbk"],"https://maps.googleapis.com/maps/api/js/GeoPhotoService.GetMetadata","https://maps.googleapis.com/maps/api/js/GeoPhotoService.SingleIma' … b'["\xc3\xbef\xc2\xa9\xc2\xb3\xc3\xbb\xc3\xad"],"\xc3\xbef\xc2\xa9\xc2\xb3\xc3\xbb\xc3\xad",514000000,514,514228847],2,500,[null,null,null,null,"https://www.google.com/maps/preview/log204","","https://static.panoramio.com.storage.googleapis.com/photos/",["https://geo0.ggpht.com/cbk","https://geo1.ggpht.com/cbk","https://geo2.ggpht.com/cbk","https://geo3.ggpht.com/cbk"],"https://maps.googleapis.com/maps/api/js/GeoPhotoService.GetMetadata","https://maps.googleapis.com/maps/api/js/GeoPhotoService.SingleImageSearch",["https://lh3.ggpht.com/","https://lh4.ggpht.com/","http' … b'["https://geo0.ggpht.com/cbk","https://geo1.ggpht.com/cbk","https://geo2.ggpht.com/cbk","https://geo3.ggpht.com/cbk"],"https://maps.googleapis.com/maps/api/js/GeoPhotoService.GetMetadata","https://maps.googleapis.com/maps/api/js/GeoPhotoService.SingleImageSearch",["https://lh3.ggpht.com/","https://lh4.ggpht.com/","https://lh5.ggpht.com/","https://lh6.ggpht.com/"]],null,null,null,null,"/maps/api/js/ApplicationService.GetEntityDetails",'

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).

Fully automated RESTful API is now available. Subscribe for your free trial today!