testcookie NGINX anti-bot

testcookie-nginx-module is a basic anti-bot mechanism using a JavaScript-based challenge to defeat simple analysis by sandboxes which don't evaluate JavaScript.

References

IOK Rule (edit)

title: testcookie NGINX anti-bot
description: |
  `testcookie-nginx-module` is a basic anti-bot mechanism using a JavaScript-based challenge to defeat simple analysis by sandboxes which don't evaluate JavaScript.
references:
  - https://github.com/kyprizel/testcookie-nginx-module
  - https://blog.kwiatkowski.fr/?q=en/testcookie

detection:
  aes:
    html|contains|all:
      - "a=toNumbers("
      - "b=toNumbers("
      - "c=toNumbers("
      - "toHex(slowAES.decrypt(c,2,a,b))"
  condition: aes

tags:
  - anti-analysis