generic_javascript_obfuscation5 in www.riyadonline.com

On 2020-06-21T13:52:55.813344+00:00 we found pattern generic_javascript_obfuscation5, type: Suspicious, (JavaScript obfuscation is frequently used to hide malicious code (or with hope to protect intellectual property)) in the page https://www.riyadonline.com/ib/js/rol-j… referenced from https://www.riyadonline.com/ib/login.ht… .

Code sample:

b'["\xc2\xb5\xc2\xa6\xc3\x88\xc2\x9d\xc3\x97\xc2\xb1","\xc2\xad\xc3\xa6\xc2\x9d:yr","maxLength","cellSpacing","cellPadding","rowSpan","colSpan","useMap","frameBorder",'

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).