generic_javascript_obfuscation5 in www.googletagmanager.com

On 2020-06-30T03:31:15.188520+00:00 we found pattern generic_javascript_obfuscation5, type: Suspicious, (JavaScript obfuscation is frequently used to hide malicious code (or with hope to protect intellectual property)) in the page https://www.googletagmanager.com/gtm.js… referenced from http://lafrancelaw.com/ .

Code sample:

b'["require","r\xc2\xb7\xc2\x9a\xc2\xb5\xc3\xa0+\xc2\x82\xc3\xa9\xc2\x9e\xc2\x9e\xc3\x9b\x10\xc2\xb9\xc3\xab\xc2\x9e"]],[52,"c",["require","encodeUriComponent"]],[52,"d",["require","\xc2\x8ax\xc3\x9er\xc3\x94\xc2\x9c\xc2\xae*m"]],[52,"e",["require","makeString"]],[52,"f",["require","setInWindow"]],["b","hj","hj.q"],[52,"g",[17,[15,"a"],"hotjar_site_id"]],["f","_hjSettings",[8,"hjid",[15,"g"],"hjsv",7,"\xc2\xb1\xc3\x8a\xc3\xa2\xc2\xa6\xc3\x94\xc2\xa8\xc2\xba\xc2\xb7\x1e","gtm"]],["d",[0,[0,"https://static.hotjar.com/c/hotjar-",["c",["e",' … b'["require","encodeUriComponent"]],[52,"d",["require","\xc2\x8ax\xc3\x9er\xc3\x94\xc2\x9c\xc2\xae*m"]],[52,"e",["require","makeString"]],[52,"f",["require","setInWindow"]],["b","hj","hj.q"],[52,"g",[17,[15,"a"],"hotjar_site_id"]],["f","_hjSettings",[8,"hjid",[15,"g"],"hjsv",7,"\xc2\xb1\xc3\x8a\xc3\xa2\xc2\xa6\xc3\x94\xc2\xa8\xc2\xba\xc2\xb7\x1e","gtm"]],["d",[0,[0,"https://static.hotjar.com/c/hotjar-",["c",["e",' … b'["require","\xc2\x8ax\xc3\x9er\xc3\x94\xc2\x9c\xc2\xae*m"]],[52,"e",["require","makeString"]],[52,"f",["require","setInWindow"]],["b","hj","hj.q"],[52,"g",[17,[15,"a"],"hotjar_site_id"]],["f","_hjSettings",[8,"hjid",[15,"g"],"hjsv",7,"\xc2\xb1\xc3\x8a\xc3\xa2\xc2\xa6\xc3\x94\xc2\xa8\xc2\xba\xc2\xb7\x1e","gtm"]],["d",[0,[0,"https://static.hotjar.com/c/hotjar-",["c",["e",' … b'["ecl"],r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l:["nonGooglePixels"],ecl:["cl"],ehl:["hl"],hl:["ehl"],html:["customScripts","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],customScripts:["html","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],nonGooglePixels:[],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl:["nonGooglePixels"],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac:["nonGooglePixels"]},bj={cl:["ecl"],r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l:["customScripts",' … b'["nonGooglePixels"],ecl:["cl"],ehl:["hl"],hl:["ehl"],html:["customScripts","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],customScripts:["html","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],nonGooglePixels:[],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl:["nonGooglePixels"],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac:["nonGooglePixels"]},bj={cl:["ecl"],r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l:["customScripts",' … b'["cl"],ehl:["hl"],hl:["ehl"],html:["customScripts","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],customScripts:["html","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],nonGooglePixels:[],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl:["nonGooglePixels"],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac:["nonGooglePixels"]},bj={cl:["ecl"],r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l:["customScripts",' … b'["hl"],hl:["ehl"],html:["customScripts","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],customScripts:["html","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],nonGooglePixels:[],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl:["nonGooglePixels"],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac:["nonGooglePixels"]},bj={cl:["ecl"],r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l:["customScripts",' … b'["ehl"],html:["customScripts","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],customScripts:["html","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],nonGooglePixels:[],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl:["nonGooglePixels"],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac:["nonGooglePixels"]},bj={cl:["ecl"],r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l:["customScripts",' … b'["customScripts","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],customScripts:["html","r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l","nonGooglePixels","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl","\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac"],nonGooglePixels:[],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%y\'+\xc2\x8a\xc2\x9bl:["nonGooglePixels"],\xc2\x9e\xc2\x89\xc3\x86\xc2\xa2\xc2\x88%x\xc2\x87\xc3\xabjg\xc2\xac:["nonGooglePixels"]},bj={cl:["ecl"],r\xc3\xab-\xc2\xa2c\xc3\xa2\xc3\x85\xc3\xa9l:["customScripts",'

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).