JSUNPACK
A Generic JavaScript Unpacker
CAUTION: jsunpack was designed for security researchers and computer professionals
Enter a single URL (or paste JavaScript to decode):

Upload a PDF, pcap, HTML, or JavaScript file
Private? Help: privacy | uploads
Default Referer
Description

Submission permanent link 41886ad3ccd54d36842ff1844e0c322c891d9e25 (Received 2012-08-21 01:40:27, http://91.121.87.136:84/promo.php?compte=356159704679&path=002032&lg=en&cat=arts&sous_cat=cinema&lg_nav=en )

URLStatus
91.121.87.136:84/promo.php?compte=356159704679&path=002032&lg=en&cat=arts&cat=cinema&nav=en saved 11194 bytes e879485aaf833ad1819040b83e49f75ba71357c7

cachewww.21nova.com/ status: (referer=www.21nova.fr/demarrer.php)

www.21nova.fr/ status: (referer=www.21nova.fr/demarrer.php)

cachewww.21nova.com?sjs=testab/ status: (referer=91.121.87.136:84/)

tickers.playtech.com/jackpots/jackpot.swf?info=2&casino=32vegas&up=32vegas&face=arial&size=22&color=3d0000&currency=eur&align=right&color=F9F9F9&bold=1 status: (referer=91.121.87.136:84/)

banner.21nova.com/casinoclient.html? status: (referer=www.21nova.fr/demarrer.php)

cachewww.21nova.com?sjs=shared:ajax:common:swfobject:floater:accordion:exp:rafform&js=1_7_min:jquery.cookie:project:fr-lang:se:seoref/ status: (referer=www.21nova.fr/demarrer.php)

All Malicious or Suspicious Elements of Submission

None
91.121.87.136:84/promo.php?compte=356159704679&path=002032&lg=en&cat=arts&cat=cinema&nav=en benign
[nothing detected] 91.121.87.136:84/promo.php?compte=356159704679&path=002032&lg=en&cat=arts&cat=cinema&nav=en
     status: (referer=http:/www.twitter.com/trends/)saved 11194 bytes e879485aaf833ad1819040b83e49f75ba71357c7
     info: [script] 91.121.87.136:84/scripts/lp.js
     info: [iframe] 91.121.87.136:84/
     info: [img] 91.121.87.136:84/./logo.png
     info: [img] 91.121.87.136:84/./greencheck.png
     info: [img] images.scanalert.com/meter/www.ilivid.com/22.gif
     info: [iframe] www.facebook.com/plugins/like.php?locale=US&href=http%3A%2F%2Fwww.facebook.com%2Fpages%2FIlivid%2F121626371218107&layout=standard&faces=false&width=526&action=like&colorscheme=light&height=55
     info: [img] 91.121.87.136:84/images/406/popupClose.gif
     info: [img] 91.121.87.136:84/images/406/popupBtn.gif
     info: [decodingLevel=0] found JavaScript
     error: undefined variable initPage
     error: undefined function initPage
     file: e879485aaf833ad1819040b83e49f75ba71357c7: 11194 bytes

Decoded Files
e879/485aaf833ad1819040b83e49f75ba71357c7 from 91.121.87.136:84/promo.php?compte=356159704679&path=002032&lg=en&cat=arts&cat=cinema&nav=en (11194 bytes, 1674 hidden) download


91.121.87.136:84/ benign
[nothing detected] (iframe) 91.121.87.136:84/
     status: (referer=91.121.87.136:84/promo.php?compte=356159704679&path=002032&lg=en&cat=arts&cat=cinema&nav=en)saved 19795 bytes 7b882eee605aadcdae87267d34cd0fc785eaad1d
     info: [javascript variable] URL=www.21nova.fr
     info: [javascript variable] URL=cachewww.21nova.com
     info: [javascript variable] URL=banner.21nova.com/casinoclient.html?
     info: [javascript variable] URL=banner.21nova.com/cgi-bin/SetupCasino.exe
     info: [javascript variable] URL=www.21nova.fr/demarrer.php
     info: [script] cachewww.21nova.com?js=module&debug
     info: [script] cachewww.21nova.com?sjs=shared:ajax:common:swfobject:floater:smooth:browserdetect:module&js=1_7_min:jquery.cookie:project:fr-lang:se:seoref
     info: [script] cachewww.21nova.com?sjs=testab
     info: [script] cachewww.21nova.com?js=fr-cooltool
     info: [img] cachewww.21nova.com/skin/default/images/logo.gif
     info: [img] cachewww.21nova.com/skin/default/images/left.gif
     info: [embed] tickers.playtech.com/jackpots/jackpot.swf?info=2&casino=32vegas&up=32vegas&face=arial&size=22&color=3d0000&currency=eur&align=right&color=F9F9F9&bold=1
     info: [img] cachewww.21nova.com/media/images/pix.gif
     info: [embed] cachewww.21nova.com/skin/default/payments/main.swf
     info: [decodingLevel=0] found JavaScript
     error: undefined variable L
     error: undefined variable L[SITELANG]
     error: line:1: SyntaxError: missing ; before statement:
          error: line:1: var L[SITELANG] = 1;
          error: line:1: ....^
     info: [var SITEURL] URL=www.21nova.fr
     info: [var CACHEURI] URL=cachewww.21nova.com
     info: [var INSTANTFLASH] URL=banner.21nova.com/casinoclient.html?
     info: [var DLURL] URL=banner.21nova.com/cgi-bin/SetupCasino.exe
     info: [var onDLURL] URL=www.21nova.fr/demarrer.php
     info: [var newurl] URL=www.21nova.fr/demarrer.php
     info: [decodingLevel=1] found JavaScript
     file: 7b882eee605aadcdae87267d34cd0fc785eaad1d: 19795 bytes
     file: fb083466d5103f1a6cee200f02ae13173d30781c: 392 bytes

Decoded Files
7b88/2eee605aadcdae87267d34cd0fc785eaad1d from 91.121.87.136:84/ (19795 bytes, 349 hidden) download

fb08/3466d5103f1a6cee200f02ae13173d30781c from 91.121.87.136:84/ (392 bytes) download


cachewww.21nova.com?js=fr-cooltool/ benign
[nothing detected] (script) cachewww.21nova.com?js=fr-cooltool/
     status: (referer=91.121.87.136:84/)saved 53 bytes d8715b2a722b1b3901072a5a4c092a8bebd71f5f
     info: [0] no JavaScript
     file: d8715b2a722b1b3901072a5a4c092a8bebd71f5f: 53 bytes

Decoded Files
d871/5b2a722b1b3901072a5a4c092a8bebd71f5f from cachewww.21nova.com?js=fr-cooltool/ (53 bytes) download


banner.21nova.com/cgi-bin/SetupCasino.exe benign
[nothing detected] [MZ] (var DLURL) banner.21nova.com/cgi-bin/SetupCasino.exe
     status: (referer=www.21nova.fr/demarrer.php)saved 646488 bytes 03ad670e187f954f0c01eb3db95cf1b40e5c3e91
     info: [0] executable file
     file: 03ad670e187f954f0c01eb3db95cf1b40e5c3e91: 646488 bytes

Decoded Files
03ad/670e187f954f0c01eb3db95cf1b40e5c3e91 from banner.21nova.com/cgi-bin/SetupCasino.exe (646488 bytes, 404952 hidden) download


cachewww.21nova.com?js=module&debug/ benign
[nothing detected] (script) cachewww.21nova.com?js=module&debug/
     status: (referer=91.121.87.136:84/)saved 53 bytes d8715b2a722b1b3901072a5a4c092a8bebd71f5f
     info: [0] no JavaScript
     file: d8715b2a722b1b3901072a5a4c092a8bebd71f5f: 53 bytes

Decoded Files
d871/5b2a722b1b3901072a5a4c092a8bebd71f5f from cachewww.21nova.com?js=module&debug/ (53 bytes) download


cachewww.21nova.com/skin/default/payments/main.swf benign
[nothing detected] [SWF] (embed) cachewww.21nova.com/skin/default/payments/main.swf
     status: (referer=www.21nova.fr/demarrer.php)saved 2565 bytes c82c27f61c13cd03a1907fab5b805c4ef13b9f4e
     info: [0] no JavaScript
     file: c82c27f61c13cd03a1907fab5b805c4ef13b9f4e: 2565 bytes

Decoded Files
c82c/27f61c13cd03a1907fab5b805c4ef13b9f4e from cachewww.21nova.com/skin/default/payments/main.swf (2565 bytes, 1545 hidden) download


cachewww.21nova.com?sjs=shared:ajax:common:swfobject:floater:smooth:browserdetect:module&js=1_7_min:jquery.cookie:project:fr-lang:se:seoref/ benign
[nothing detected] (script) cachewww.21nova.com?sjs=shared:ajax:common:swfobject:floater:smooth:browserdetect:module&js=1_7_min:jquery.cookie:project:fr-lang:se:seoref/
     status: (referer=91.121.87.136:84/)saved 53 bytes d8715b2a722b1b3901072a5a4c092a8bebd71f5f
     info: [0] no JavaScript
     file: d8715b2a722b1b3901072a5a4c092a8bebd71f5f: 53 bytes

Decoded Files
d871/5b2a722b1b3901072a5a4c092a8bebd71f5f from cachewww.21nova.com?sjs=shared:ajax:common:swfobject:floater:smooth:browserdetect:module&js=1_7_min:jquery.cookie:project:fr-lang:se:seoref/ (53 bytes) download


www.21nova.fr/demarrer.php benign
[nothing detected] (var newurl) www.21nova.fr/demarrer.php
     status: (referer=91.121.87.136:84/)saved 19817 bytes 039265d03e579cc37c2a650190e23d465de5e945
     info: [javascript variable] URL=www.21nova.fr
     info: [javascript variable] URL=cachewww.21nova.com
     info: [javascript variable] URL=banner.21nova.com/casinoclient.html?
     info: [javascript variable] URL=banner.21nova.com/cgi-bin/SetupCasino.exe
     info: [javascript variable] URL=www.21nova.fr/demarrer.php
     info: [script] cachewww.21nova.com?sjs=shared:ajax:common:swfobject:floater:accordion:exp:rafform&js=1_7_min:jquery.cookie:project:fr-lang:se:seoref
     info: [img] cachewww.21nova.com/skin/default/images/logo.gif
     info: [img] cachewww.21nova.com/skin/default/images/left.gif
     info: [img] cachewww.21nova.com/media/images/getting-started/tab1-_step1-run.gif
     info: [img] cachewww.21nova.com/media/images/getting-started/tab1-step2-download.gif
     info: [img] cachewww.21nova.com/media/images/getting-started/fr/tab1_step3-fr.jpg
     info: [img] cachewww.21nova.com/media/images/getting-started/fr/tab2-step1-Installation.gif
     info: [img] cachewww.21nova.com/media/images/getting-started/fr/tab2-step2-I-agree.gif
     info: [img] cachewww.21nova.com/media/images/getting-started/fr/tab2-step3-play-for-real.gif
     info: [img] cachewww.21nova.com/media/images/getting-started/fr/tab3-step1-enter-details.gif
     info: [img] cachewww.21nova.com/media/images/getting-started/fr/tab3-step2-enter-password.gif
     info: [img] cachewww.21nova.com/media/images/getting-started/fr/tab3-step3-welcome.gif
     info: [img] cachewww.21nova.com/media/images/getting-started/fr/tab4-step1-deposit.gif
     info: [img] cachewww.21nova.com/media/images/getting-started/fr/tab4-step2-deposit-process.gif
     info: [img] cachewww.21nova.com/media/images/getting-started/fr/tab4-step3-21nova-Lobby.gif
     info: [img] cachewww.21nova.com/media/images/pix.gif
     info: [embed] cachewww.21nova.com/skin/default/payments/main.swf
     info: [decodingLevel=0] found JavaScript
     error: undefined variable cookieReader
     error: undefined function cookieReader
     info: [var SITEURL] URL=www.21nova.fr
     info: [var CACHEURI] URL=cachewww.21nova.com
     info: [var INSTANTFLASH] URL=banner.21nova.com/casinoclient.html?
     info: [var DLURL] URL=banner.21nova.com/cgi-bin/SetupCasino.exe
     info: [var onDLURL] URL=www.21nova.fr/demarrer.php
     info: [var newurl] URL=www.21nova.fr/demarrer.php
     info: [decodingLevel=1] found JavaScript
     file: 039265d03e579cc37c2a650190e23d465de5e945: 19817 bytes
     file: fb083466d5103f1a6cee200f02ae13173d30781c: 392 bytes

Decoded Files
0392/65d03e579cc37c2a650190e23d465de5e945 from www.21nova.fr/demarrer.php (19817 bytes, 457 hidden) download

fb08/3466d5103f1a6cee200f02ae13173d30781c from www.21nova.fr/demarrer.php (392 bytes) download


www.facebook.com/plugins/like.php?locale=US&href=http:/www.facebook.com/pages/Ilivid/121626371218107&layout=standard&faces=false&width=526&action=like&colorscheme=light&height=55 benign
[nothing detected] (iframe) www.facebook.com/plugins/like.php?locale=US&href=http:/www.facebook.com/pages/Ilivid/121626371218107&layout=standard&faces=false&width=526&action=like&colorscheme=light&height=55
     status: (referer=91.121.87.136:84/promo.php?compte=356159704679&path=002032&lg=en&cat=arts&cat=cinema&nav=en)saved 27042 bytes 89a4f5bb3065ae37309439ae4f2c22ba8e9f27d4
     info: [decodingLevel=0] found JavaScript
     error: undefined variable a
     info: [1] no JavaScript
     file: 89a4f5bb3065ae37309439ae4f2c22ba8e9f27d4: 27042 bytes
     file: ac90d41fa54ad3f2f32c54d9ca732c1f2a8f4f50: 114 bytes

Decoded Files
89a4/f5bb3065ae37309439ae4f2c22ba8e9f27d4 from www.facebook.com/plugins/like.php?locale=US&href=http:/www.facebook.com/pages/Ilivid/121626371218107&layout=standard&faces=false&width=526&action=like&colorscheme=light&height=55 (27042 bytes) download

ac90/d41fa54ad3f2f32c54d9ca732c1f2a8f4f50 from www.facebook.com/plugins/like.php?locale=US&href=http:/www.facebook.com/pages/Ilivid/121626371218107&layout=standard&faces=false&width=526&action=like&colorscheme=light&height=55 (114 bytes) download


91.121.87.136:84/scripts/lp.js benign
[nothing detected] (script) 91.121.87.136:84/scripts/lp.js
     status: (referer=91.121.87.136:84/promo.php?compte=356159704679&path=002032&lg=en&cat=arts&cat=cinema&nav=en)saved 211 bytes bc3bed249c65e250c04a699b0294ffe3bab926f2
     info: [0] no JavaScript
     file: bc3bed249c65e250c04a699b0294ffe3bab926f2: 211 bytes

Decoded Files
bc3b/ed249c65e250c04a699b0294ffe3bab926f2 from 91.121.87.136:84/scripts/lp.js (211 bytes) download