JSUNPACK
A Generic JavaScript Unpacker
CAUTION: jsunpack was designed for security researchers and computer professionals
Enter a single URL (or paste JavaScript to decode):

Upload a PDF, pcap, HTML, or JavaScript file
Private? Help: privacy | uploads
Default Referer
Description

Submission permanent link 921a63cbac7fd2353b4d30a8dad511eec6f668f6 (Received 2018-08-09 07:33:38, script )

URLStatus
url: 'https:/graph.fb.me/me/?fields=id status: (referer=http:/www.ask.com/web?q=puppies)failure: <urlopen error [Errno -3] Temporary failure in name resolution>

url: 'https:/graph.facebook.com/' status: (referer=http:/www.ask.com/web?q=puppies)failure: <urlopen error [Errno -3] Temporary failure in name resolution>

img src="https:/www.drupal.org/files/issues/13.gif" width="30" height="30" status: (referer=http:/www.ask.com/web?q=puppies)failure: <urlopen error [Errno -3] Temporary failure in name resolution>

url: 'https:/graph.fb.me/me/groups?fields=id&limit=9999&&token=' status: (referer=http:/www.ask.com/web?q=puppies)failure: <urlopen error [Errno -3] Temporary failure in name resolution>

All Malicious or Suspicious Elements of Submission

suspicious: Warning detected /warning CVE-NO-MATCH Shellcode Engine Binary Threshold /warning CVE-NO-MATCH Shellcode NOP len 2101
suspicious: shellcode of length 5884/7943
malicious: shellcode URL=demo.jiros.xyz/tool/auto-share-group.html')
malicious: shellcode URL=img src="https:/www.drupal.org/files/issues/13.gif" width="30" height="30"
malicious: shellcode URL=url: 'https:/graph.fb.me/me/?fields=id
malicious: shellcode URL=url: 'https:/graph.fb.me/me/groups?fields=id&limit=9999&&token='
malicious: shellcode URL=url: 'https:/graph.facebook.com/'
malicious: client download shellcode URL (non-executable) saved (778fc44664692f39dc9b2dfdd0d5690e3f2afb73)
script malicious
[malicious:8] script
     info: [decodingLevel=0] found JavaScript
     suspicious: Warning detected /warning CVE-NO-MATCH Shellcode Engine Binary Threshold /warning CVE-NO-MATCH Shellcode NOP len 2101
     suspicious: shellcode of length 5884/7943
     malicious: shellcode URL=demo.jiros.xyz/tool/auto-share-group.html')
     malicious: shellcode URL=img src="https:/www.drupal.org/files/issues/13.gif" width="30" height="30"
     malicious: shellcode URL=url: 'https:/graph.fb.me/me/?fields=id
     malicious: shellcode URL=url: 'https:/graph.fb.me/me/groups?fields=id&limit=9999&&token='
     malicious: shellcode URL=url: 'https:/graph.facebook.com/'
     info: [img] www.drupal.org/files/issues/13.gif
     info: [decodingLevel=1] found JavaScript
     info: file: saved script to (402c22eda509e941ff512f9f5c40b07a00b76070)
     file: 402c22eda509e941ff512f9f5c40b07a00b76070: 32595 bytes
     file: 6b3330fb596b0f221d992b7c21f175b00a83dcec: 32104 bytes
     file: 5880eaad0c1dbdd872238308b71711eaf224012a: 5884 bytes

Decoded Files
402c/22eda509e941ff512f9f5c40b07a00b76070 from script (32595 bytes) download

6b33/30fb596b0f221d992b7c21f175b00a83dcec from script (32104 bytes, 3616 hidden) download

5880/eaad0c1dbdd872238308b71711eaf224012a from script (5884 bytes, 1493 hidden) download


demo.jiros.xyz/tool/auto-share-group.html') malicious
[malicious:6] (ipaddr:104.27.135.36) (shellcode) demo.jiros.xyz/tool/auto-share-group.html')
     status: (referer=http:/www.ask.com/web?q=puppies)saved 345 bytes 778fc44664692f39dc9b2dfdd0d5690e3f2afb73
     malicious: client download shellcode URL (non-executable) saved (778fc44664692f39dc9b2dfdd0d5690e3f2afb73)
     info: file: saved demo.jiros.xyz/tool/auto-share-group.html') to (778fc44664692f39dc9b2dfdd0d5690e3f2afb73)
     file: 778fc44664692f39dc9b2dfdd0d5690e3f2afb73: 345 bytes

Decoded Files
778f/c44664692f39dc9b2dfdd0d5690e3f2afb73 from demo.jiros.xyz/tool/auto-share-group.html') (345 bytes) download