JSUNPACK
A Generic JavaScript Unpacker
CAUTION: jsunpack was designed for security researchers and computer professionals
Enter a single URL (or paste JavaScript to decode):

Upload a PDF, pcap, HTML, or JavaScript file
Private? Help: privacy | uploads
Default Referer
Description

Submission permanent link 8c359270799f81a7465924c440526b63628d6170 (Received 2013-01-04 21:30:02, http://googleads.g.doubleclick.net:80/pagead/ads?client=ca-pub-5286124103173019&output=html&h=90&slotname=9886867545&w=728&lmt=1354914892&flash=11.4.402.278&url=file%253A%252F%252FC%253A%255Cjwang%255CXiu-Xi%255CWanHuaXiJianLu%255C027.htm&dt=1357332787361)

URLStatus
googleads.g.doubleclick.net:80/pagead/ads?client=ca-pub-5286124103173019&output=html&h=90&slotname=9886867545&w=728&lmt=1354914892&flash=11.4.402.278&url=file%253A%252F%252FC%253A%255Cjwang%255CXiu-Xi%255CWanHuaXiJianLu%255C027.htm&dt=1357332787361&bpp=4& saved 13064 bytes 950300f0df8ca0f02a30d331ea6e9c317b3b439b

www.google.com/pagead/drt/ui status: (referer=googleads.g.doubleclick.net/pagead/drt/s?v=r20120211)

All Malicious or Suspicious Elements of Submission

None
googleads.g.doubleclick.net/pagead/drt/s?v=r20120211 benign
[nothing detected] (iframe) googleads.g.doubleclick.net/pagead/drt/s?v=r20120211
     status: (referer=googleads.g.doubleclick.net:80/pagead/ads?client=ca-pub-5286124103173019&output=html&h=90&slotname=9886867545&w=728&lmt=1354914892&flash=11.4.402.278&url=file%3A%2F%2FC%3A%5Cjwang%5CXiu-Xi%5CWanHuaXiJianLu%5C027.htm&dt=1357332787361&bpp=4&shv=r20121128&jsv=r20121214&correlator=1357332787383&frm=20&adk=877589844&vid=1715993200.1357332787&sid=1357332787&hid=679236501&fc=0&tz=-360&his=1&java=1&h=840&w=1344&ah=784&aw=1344&cd=32&nplug=0&nmime=0&dff=simsun&dfs=13&adx=297&ady=7124&biw=1324&bih=575&oid=3&top=file%3A%2F%2F%2FC%3A%2Fjwang%2FXiu-Xi%2FWanHuaXiJianLu%2F027.htm&docm=8&fu=0&ifi=1&dtd=637&xpc=pDatvIuOBk&p=file%3A/)saved 137 bytes 91edaf7b611619898a2a558014f0939486248049
     info: [meta refresh] URL=www.google.com/pagead/drt/ui
     info: [0] no JavaScript
     file: 91edaf7b611619898a2a558014f0939486248049: 137 bytes

Decoded Files
91ed/af7b611619898a2a558014f0939486248049 from googleads.g.doubleclick.net/pagead/drt/s?v=r20120211 (137 bytes, 5 hidden) download


pagead2.googlesyndication.com/pagead/js/r20121206/r20110914/abg.js benign
[nothing detected] (script) pagead2.googlesyndication.com/pagead/js/r20121206/r20110914/abg.js
     status: (referer=googleads.g.doubleclick.net:80/pagead/ads?client=ca-pub-5286124103173019&output=html&h=90&slotname=9886867545&w=728&lmt=1354914892&flash=11.4.402.278&url=file%3A%2F%2FC%3A%5Cjwang%5CXiu-Xi%5CWanHuaXiJianLu%5C027.htm&dt=1357332787361&bpp=4&shv=r20121128&jsv=r20121214&correlator=1357332787383&frm=20&adk=877589844&vid=1715993200.1357332787&sid=1357332787&hid=679236501&fc=0&tz=-360&his=1&java=1&h=840&w=1344&ah=784&aw=1344&cd=32&nplug=0&nmime=0&dff=simsun&dfs=13&adx=297&ady=7124&biw=1324&bih=575&oid=3&top=file%3A%2F%2F%2FC%3A%2Fjwang%2FXiu-Xi%2FWanHuaXiJianLu%2F027.htm&docm=8&fu=0&ifi=1&dtd=637&xpc=pDatvIuOBk&p=file%3A/)saved 819 bytes f0ae76d56432f76280164051fa6c922cbd24f418
     info: [decodingLevel=0] found JavaScript
     file: f0ae76d56432f76280164051fa6c922cbd24f418: 819 bytes

Decoded Files
f0ae/76d56432f76280164051fa6c922cbd24f418 from pagead2.googlesyndication.com/pagead/js/r20121206/r20110914/abg.js (819 bytes) download


googleads.g.doubleclick.net:80/pagead/ads?client=ca-pub-5286124103173019&output=html&h=90&slotname=9886867545&w=728&lmt=1354914892&flash=11.4.402.278&url=file%3A%2F%2FC%3A%5Cjwang%5CXiu-Xi%5CWanHuaXiJianLu%5C027.htm&dt=1357332787361&bpp=4&shv=r20121128&js benign
[nothing detected] googleads.g.doubleclick.net:80/pagead/ads?client=ca-pub-5286124103173019&output=html&h=90&slotname=9886867545&w=728&lmt=1354914892&flash=11.4.402.278&url=file%3A%2F%2FC%3A%5Cjwang%5CXiu-Xi%5CWanHuaXiJianLu%5C027.htm&dt=1357332787361&bpp=4&shv=r20121128&jsv=r20121214&correlator=1357332787383&frm=20&adk=877589844&vid=1715993200.1357332787&sid=1357332787&hid=679236501&fc=0&tz=-360&his=1&java=1&h=840&w=1344&ah=784&aw=1344&cd=32&nplug=0&nmime=0&dff=simsun&dfs=13&adx=297&ady=7124&biw=1324&bih=575&oid=3&top=file%3A%2F%2F%2FC%3A%2Fjwang%2FXiu-Xi%2FWanHuaXiJianLu%2F027.htm&docm=8&fu=0&ifi=1&dtd=637&xpc=pDatvIuOBk&p=file%3A/
     status: (referer=http:/www.ask.com/web?q=puppies)saved 13064 bytes 950300f0df8ca0f02a30d331ea6e9c317b3b439b
     info: [img] pagead2.googlesyndication.com/simgad/3512532950101065298
     info: [img] pagead2.googlesyndication.com/pagead/images/adchoices/icon.png
     info: [img] pagead2.googlesyndication.com/pagead/images/adchoices/en.png
     info: [script] pagead2.googlesyndication.com/pagead/js/r20121206/r20110914/abg.js
     info: [iframe] googleads.g.doubleclick.net/pagead/drt/s?v=r20120211
     info: [decodingLevel=0] found JavaScript
     error: line:7: SyntaxError: missing } in XML expression:
          error: line:7: function(that){function c(b,d){var a=document.getElementById('abgc');if(b&&a&&b.height>0){a.style.top=0;a.style.visibility='visible'}else setTimeout(function(){c(b,d*2)},d)}c(that,10);})(this);" /></a><style>div,ul,li{margin:0px;padding:0px}#abgc{height:1
          error: line:7: ................................................................................................................................................................................................................................^
     file: 950300f0df8ca0f02a30d331ea6e9c317b3b439b: 13064 bytes

Decoded Files
9503/00f0df8ca0f02a30d331ea6e9c317b3b439b from googleads.g.doubleclick.net:80/pagead/ads?client=ca-pub-5286124103173019&output=html&h=90&slotname=9886867545&w=728&lmt=1354914892&flash=11.4.402.278&url=file%3A%2F%2FC%3A%5Cjwang%5CXiu-Xi%5CWanHuaXiJianLu%5C027.htm&dt=1357332787361&bpp=4&shv=r20121128&js (13064 bytes) download