generic_javascript_obfuscation2 in docs.google.com

On 2020-10-06T11:16:40.181798+00:00 we found pattern generic_javascript_obfuscation2, type: Suspicious, (JavaScript obfuscation is frequently used to hide malicious code (or with hope to protect intellectual property)) in the page https://docs.google.com/comments/d/AAHR… referenced from https://sites.google.com/site/moversint… .

Code sample:

b'atob' … b'atob' … b'"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789"' … b'"abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789"'

This feature is experimental so please feel free to contact us if you feel any of the reported issues is a false positive or you want to suggest a pattern that should be detected (we are using Yara standard).