JSUNPACK
A Generic JavaScript Unpacker
CAUTION: jsunpack was designed for security researchers and computer professionals
Enter a single URL (or paste JavaScript to decode):

Upload a PDF, pcap, HTML, or JavaScript file
Private? Help: privacy | uploads
Default Referer
Description

Submission permanent link 0093eb2005471bc929d1f370ef9691a99182ddd8 (Received 2018-07-09 17:28:36, script )

URLStatus

All Malicious or Suspicious Elements of Submission

malicious: client download shellcode URL (non-executable) saved (5991f9ac33f38173ebc9d3ee27fc3703059741ae)
suspicious: shellcode of length 123/117
malicious: shellcode URL=chat.whatssap.me/3gGOkb1F5za0PzAv/
chat.whatssap.me/3gGOkb1F5za0PzAv/ malicious
[malicious:6] (ipaddr:69.175.68.55) (shellcode) chat.whatssap.me/3gGOkb1F5za0PzAv/
     status: (referer=http:/www.ask.com/web?q=puppies)saved 1139 bytes 5991f9ac33f38173ebc9d3ee27fc3703059741ae
     malicious: client download shellcode URL (non-executable) saved (5991f9ac33f38173ebc9d3ee27fc3703059741ae)
     info: file: saved chat.whatssap.me/3gGOkb1F5za0PzAv/ to (5991f9ac33f38173ebc9d3ee27fc3703059741ae)
     file: 5991f9ac33f38173ebc9d3ee27fc3703059741ae: 1139 bytes

Decoded Files
5991/f9ac33f38173ebc9d3ee27fc3703059741ae from chat.whatssap.me/3gGOkb1F5za0PzAv/ (1139 bytes, 16 hidden) download


chat.whatssap.me/verificando benign
[nothing detected] (var newurl) chat.whatssap.me/verificando
     status: (referer=http:/www.ask.com/web?q=puppies)saved 1139 bytes 5991f9ac33f38173ebc9d3ee27fc3703059741ae
     info: [0] no JavaScript
     file: 5991f9ac33f38173ebc9d3ee27fc3703059741ae: 1139 bytes

Decoded Files
5991/f9ac33f38173ebc9d3ee27fc3703059741ae from chat.whatssap.me/verificando (1139 bytes, 16 hidden) download


script malicious
[malicious:8] script
     info: [decodingLevel=0] found JavaScript
     error: undefined variable $
     error: undefined function $
     info: Decoding option navigator.systemLanguage=zh-cn and browser=IE7/XP and browser=IE8/Vista and browser=Opera,      434 bytes
     info: Decoding option navigator.systemLanguage=en,      433 bytes
     info: Decoding option browser=Firefox,      402 bytes
     suspicious: shellcode of length 123/117
     malicious: shellcode URL=chat.whatssap.me/3gGOkb1F5za0PzAv/
     info: [var urlpubliMovil] URL=chat.whatssap.me/verificando
     info: [var urlpubliPC] URL=chat.whatssap.me/verificando
     info: [var newurl] URL=chat.whatssap.me/verificando
     info: [decodingLevel=1] found JavaScript
     info: file: saved script to (216a6c532a2107b42f5fbe9b97effe3a94ab6a36)
     file: 216a6c532a2107b42f5fbe9b97effe3a94ab6a36: 12063 bytes
     file: 22c2199a3b0513762fec426a401779072e75256b: 434 bytes
     file: e3aaa7367b5c82c60fa8593c72f231b5e58d9149: 123 bytes

Decoded Files
216a/6c532a2107b42f5fbe9b97effe3a94ab6a36 from script (12063 bytes, 2212 hidden) download

22c2/199a3b0513762fec426a401779072e75256b from script (434 bytes) download

e3aa/a7367b5c82c60fa8593c72f231b5e58d9149 from script (123 bytes, 7 hidden) download