JSUNPACK
A Generic JavaScript Unpacker
CAUTION: jsunpack was designed for security researchers and computer professionals
Enter a single URL (or paste JavaScript to decode):

Upload a PDF, pcap, HTML, or JavaScript file
Private? Help: privacy | uploads
Default Referer
Description

Submission permanent link 734d466ee5a71f8c8d5e28328a142ebc5ce6d76a (Received 2013-07-07 09:50:57, www.thebiglead.com )

URLStatus
www.thebiglead.com saved 60547 bytes 3d957123634abc6f47f8bc8aa265e980c9798da9

thebiglead.fantasysportsven.netdna-cdn.com/wp-content/themes/bigleadsports/js/quicktags.js status: (referer=www.thebiglead.com/)

dg.specificclick.net/?y=3&t=i&u= status: (referer=s24.sitemeter.com/js/counter.asp?site=s24sportsblog)

www.usatodayhss.com/script/combined.js.h-1357801833.pack status: (referer=www.usatodayhss.com/S25_widget?version=00000138-964d-d9e7-af3f-d77dc4520000)

www.usatodayhss.com/script/hssnet.js status: (referer=www.usatodayhss.com/S25_widget?version=00000138-964d-d9e7-af3f-d77dc4520000)

www.thebiglead.com/wp-content/plugins/wp-polls/polls-js.js?ver=2.63 status: (referer=www.thebiglead.com/)

www.thebiglead.com/wp-content/plugins/powerpress/ status: (referer=www.thebiglead.com/wp-content/plugins/powerpress/player.js)

thebiglead.fantasysportsven.netdna-cdn.com/wp-content/themes/bigleadsports/js/slideshow.js status: (referer=www.thebiglead.com/)

synd-player.silverchalice.co/v1/player/player.js status: (referer=www.thebiglead.com/)

www.google.com/recaptcha/api/js/ajax.js status: (referer=www.usatodayhss.com/S25_widget?version=00000138-964d-d9e7-af3f-d77dc4520000)

thebiglead.fantasysportsven.netdna-cdn.com/wp-content/themes/bigleadsports/js/jquery-1.3.1.min.js status: (referer=www.thebiglead.com/)

synd-player.silverchalice.co/v1/player/angular.js status: (referer=www.thebiglead.com/)

platform.twitter.com/widgets.js status: (referer=www.thebiglead.com/)

rtax.criteo.com/delivery/rta/rta.js?netId= status: (referer=www.thebiglead.com/)

assets.onswipe.com/synapse/on.js?usr=bigleadsports status: (referer=www.thebiglead.com/)

www.googletagservices.com/tag/js/gpt.js status: (referer=www.thebiglead.com/)

www.usatodayhss.com/gel/lib/core/core.js status: (referer=www.usatodayhss.com/S25_widget?version=00000138-964d-d9e7-af3f-d77dc4520000)

code.jquery.com/undefined status: (referer=code.jquery.com/jquery-1.10.1.min.js)

All Malicious or Suspicious Elements of Submission

suspicious: maxruntime exceeded 10 seconds (incomplete) 0 bytes
thebiglead.fantasysportsven.netdna-cdn.com/wp-includes/js/jquery/jquery.js?ver=1.8.3 benign
[nothing detected] (script) thebiglead.fantasysportsven.netdna-cdn.com/wp-includes/js/jquery/jquery.js?ver=1.8.3
     status: (referer=www.thebiglead.com/)saved 93658 bytes d24817d13b4626b15e2fd51e49f2312f27ef7be5
     info: ActiveXDataObjectsMDAC detected Microsoft.XMLHTTP
     file: d24817d13b4626b15e2fd51e49f2312f27ef7be5: 93658 bytes

Decoded Files
d248/17d13b4626b15e2fd51e49f2312f27ef7be5 from thebiglead.fantasysportsven.netdna-cdn.com/wp-includes/js/jquery/jquery.js?ver=1.8.3 (93658 bytes) download


www.usatodayhss.com/S25_widget?version=00000138-964d-d9e7-af3f-d77dc4520000 benign
[nothing detected] (iframe) www.usatodayhss.com/S25_widget?version=00000138-964d-d9e7-af3f-d77dc4520000
     status: (referer=www.thebiglead.com/)saved 22641 bytes 546a2d31b3d6c6ab55553cef7892291759252b47
     info: [script] www.usatodayhss.com/script/combined.js.h-1357801833.pack
     info: [script] www.usatodayhss.com/gel/lib/core/core.js
     info: [script] www.google.com/recaptcha/api/js/ajax.js
     info: [img] www.usatodayhss.com/imgs/cut.jpg
     info: [img] www.usatodayhss.com/imgs/load.gif
     info: [img] bs.serving-sys.com/BurstingPipe/adServer.bs?cn=tf&c=19&mc=imp&pli=4521973&PluID=0&ord=%%RANDOM%%&rtu=-1
     info: [script] www.usatodayhss.com/script/hssnet.js
     info: [img] gannett.112.2o7.net/b/ss/gpaperhssnet/1/H.24.3--NS/0
     info: [decodingLevel=0] found JavaScript
     error: undefined variable $
     error: undefined function $
     suspicious: maxruntime exceeded 10 seconds (incomplete) 0 bytes
     error: line:3: SyntaxError: missing = in XML attribute:
          error: line:3: <!DOCTYPE html>
          error: line:3: ..............^
     file: 546a2d31b3d6c6ab55553cef7892291759252b47: 22641 bytes
     file: 083746116f704106a5f5755fefda77ff8b7af81c: 32332 bytes
     file: 33f266e371a50ef07ef2df74d402400393882763: 32492 bytes
     file: ff62689af16aff360efc5a5a8bafa98dae2920dc: 32684 bytes
     file: 39b33da7908929bbb0173c2920025e93d5e83d26: 32398 bytes
     file: fe9f39490945c9d55ecbeb9abefa5c1663afeab9: 32522 bytes
     file: 7e0caa4e0260a0bd0d930e68aa7d1a1a2bd6e1ea: 22945 bytes
     file: 46ed97cce38a9eba8251942f70b799d1f488ed34: 22951 bytes
     file: 9e9197604ea86969c304699cf2b02a7275bf5d54: 23160 bytes
     file: b783256ff695c227554d595f3596aa5d7093b06a: 23352 bytes
     file: 134c8931b4321b9db6e30ad45b3d4e3bdd0e431c: 23066 bytes
     file: b7a553f9840d5fe9864acc22c38d38f3be592e18: 23190 bytes

Decoded Files
546a/2d31b3d6c6ab55553cef7892291759252b47 from www.usatodayhss.com/S25_widget?version=00000138-964d-d9e7-af3f-d77dc4520000 (22641 bytes, 8182 hidden) download

0837/46116f704106a5f5755fefda77ff8b7af81c from www.usatodayhss.com/S25_widget?version=00000138-964d-d9e7-af3f-d77dc4520000 (32332 bytes, 6691 hidden) download