Threat Intelligence Report
Attack Pattern Analysis
Top Indicators/Keywords
Malicious Sites Detected
Click on a site to view detailed analysisπ Suspicious Keywords 3
π Extracted URLs 1
π Obfuscated JavaScript
Showing first 2 of 3 entries (truncated for performance)
{'script': '\n (function(_0x45bd8d,_0x7cba03){function _0x5b7bb9(_0xfeff57,_0x4e512a,_0x6c2121,_0x5c91d0,_0x3a6b9e){return _0x467f(_0x3a6b9e-0x2ec,_0xfeff57);}...', 'indicators': [{'pattern': 'var\\s+_0x[a-f0-9]{4,6}\\s*=', 'examples': ['var _0x2007dc=', 'var _0x2f4efc='], 'count': 75}, {'pattern': '_0x[a-f0-9]{4,6}\\[.*?\\]', 'examples': ["_0x2007dc['push']", "_0x2007dc['shift']"], 'count': 692}, {'pattern': '_0x[a-f0-9]{2,6}\\s*=\\s*function', 'examples': ['_0x1830b1=function', '_0x961ba5=function'], 'count': 5}, {'pattern': '\\(function\\s*\\(\\s*_0x[a-f0-9]{2,6}\\s*,\\s*_0x[a-f0-9]{2,6}\\s*\\)', 'examples': ['(function(_0x45bd8d,_0x7cba03)'], 'count': 1}, {'pattern': 'function\\s+_0x[a-f0-9]{4,8}', 'examples': ['function _0x5b7bb9', 'function _0x1fe87c'], 'count': 215}, {'pattern': 'var\\s+_0x[a-f0-9]{2,8}\\s*=', 'examples': ['var _0x2007dc=', 'var _0x2f4efc='], 'count': 75}, {'pattern': 'var\\s+[a-zA-Z0-9_$]+\\s*=\\s*\\[\\s*(?:[\\\'"`].*?[\\\'"`]\\s*,\\s*){10,}', 'examples': ["var _0x47fbf4=['W6uSrSoFqG','Cxj0zCoW','pSo0WPC3la..."], 'count': 1}, {'pattern': 'var\\s+[a-zA-Z0-9_$]+\\s*=\\s*[\\\'"`][^\\\'"`]{50,}[\\\'"`]', 'examples': ["var _0x334da5='abcdefghijklmnopqrstuvwxyzABCDEFGHI..."], 'count': 1}, {'pattern': '[a-zA-Z0-9_$]{1,3}\\[[\\\'"`]push[\\\'"`]\\]', 'examples': ["7dc['push']", "7dc['push']"], 'count': 2}, {'pattern': '[\\\'"`]\\\\x[0-9a-fA-F]{2}\\\\x[0-9a-fA-F]{2}[\\\'"`]', 'examples': ["'\\x0a\\x0a'"], 'count': 1}], 'score': 1068, 'position': 3589}
{'script': '\n function _0x4109d1(_0x285632,_0x3c7efc,_0x496f65,_0x38e615,_0x3b75cc){return _0x17f3(_0x496f65-0x30,_0x285632);}function _0x17f3(_0x203f78,_0x365ef...', 'indicators': [{'pattern': 'var\\s+_0x[a-f0-9]{4,6}\\s*=', 'examples': ['var _0x333fb='], 'count': 1}, {'pattern': '_0x[a-f0-9]{4,6}\\[.*?\\]', 'examples': ['_0x587312[_0x203f78]', "_0x17f3['KaHxjK']"], 'count': 349}, {'pattern': '_0x[a-f0-9]{2,6}\\s*=\\s*function', 'examples': ['_0x333fb=function', '_0x446b73=function'], 'count': 4}, {'pattern': '\\(function\\s*\\(\\s*_0x[a-f0-9]{2,6}\\s*,\\s*_0x[a-f0-9]{2,6}\\s*\\)', 'examples': ['(function(_0x543644,_0x5ac60e)'], 'count': 1}, {'pattern': 'function\\s+_0x[a-f0-9]{4,8}', 'examples': ['function _0x4109d1', 'function _0x17f3'], 'count': 124}, {'pattern': 'var\\s+_0x[a-f0-9]{2,8}\\s*=', 'examples': ['var _0x333fb='], 'count': 1}, {'pattern': 'let\\s+_0x[a-f0-9]{2,8}\\s*=', 'examples': ['let _0x355d67=', 'let _0x145527='], 'count': 15}, {'pattern': 'const\\s+_0x[a-f0-9]{2,8}\\s*=', 'examples': ['const _0x587312=', 'const _0x3476c7='], 'count': 57}, {'pattern': '[a-zA-Z0-9_$]{1,3}\\[[\\\'"`]push[\\\'"`]\\]', 'examples': ["251['push']", "251['push']"], 'count': 2}], 'score': 554, 'position': 134558}
π Suspicious Keywords 3
π Extracted URLs 190
π Suspicious Keywords 3
π Extracted URLs 79
π Suspicious Keywords 5
π Extracted URLs 22
π°οΈ Redirect Follower Findings (1)
{ return; }}
k=e.createElement(t),a=e.getElementsByTagName(t)[0],k.async=1,k.src=r,a.parentNode.insertBefore(k,a)})
(window, document, "script", "https://mc.yandex.ru/metrika/tag.js", "ym");
ym(55085083, "init", {
clickmapβ¦(function(){var p;function aa(a){var b=0;return function(){return b<a.length?{done:!1,value:a[b++]}:{done:!0}}}var ba="function"==typeof Object.defineProperties?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a};
function ca(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw... [truncated]π Suspicious Keywords 3
π Extracted URLs 150
π Suspicious Keywords 19
π Extracted URLs 6
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π Suspicious Keywords 19
π Extracted URLs 6
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π Suspicious Keywords 19
π Extracted URLs 6
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π Suspicious Keywords 19
π Extracted URLs 6
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π Suspicious Keywords 19
π Extracted URLs 6
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π Suspicious Keywords 19
π Extracted URLs 6
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π Suspicious Keywords 1
π Extracted URLs 132
π» PowerShell Commands 2
π Suspicious Keywords 21
π Extracted URLs 5
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π» PowerShell Commands 2
π Suspicious Keywords 21
π Extracted URLs 5
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π» PowerShell Commands 2
π Suspicious Keywords 21
π Extracted URLs 5
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π» PowerShell Commands 2
π Suspicious Keywords 21
π Extracted URLs 5
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π» PowerShell Commands 2
π Suspicious Keywords 21
π Extracted URLs 5
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π» PowerShell Commands 2
π Suspicious Keywords 21
π Extracted URLs 5
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π» PowerShell Commands 2
π Suspicious Keywords 21
π Extracted URLs 5
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
π Suspicious Keywords 18
π Extracted URLs 5
π Clipboard Manipulation Code
Showing first 2 of 6 entries (truncated for performance)
...ea); textarea.select(); try { document.execCommand('copy'); } catch(e) { /* ignore */ } document....
...ntDefault(); if (e.clipboardData) { e.clipboardData.setData('text/plain', command); } else if (window.clip...
Showing top 20 malicious sites. 28 additional sites detected.