JSUNPACK
A Generic JavaScript Unpacker
CAUTION: jsunpack was designed for security researchers and computer professionals
Enter a single URL (or paste JavaScript to decode):

Upload a PDF, pcap, HTML, or JavaScript file
Private? Help: privacy | uploads
Default Referer
Description

Submission permanent link 10871f519954281bd6bc2067782ac1bbbc1109c6 (Received 2018-04-16 19:48:01, http://resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref )

URLStatus
resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref saved 146371 bytes 9ab515ccf07bc27a3063a49a2186eca3f9d1534b

2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/plugins/akismet/_inc/form.js?ver=4.0.3 status: (referer=resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref)

www.redditstatic.com/button/button2.html?url=www.redditstatic.com/button/button2.js status: (referer=www.redditstatic.com/button/button2.js)

apis.google.com/js/platform.js status: (referer=resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref)

a.optmstr.com/app/js/api.min.js?ver=1.3.4 status: (referer=resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref)

www.googletagmanager.com/ns.html?id=GTM-W9VWCG status: (referer=resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref)

resources.infosecinstitute.com/computer-forensics-investigation-case-study/undefined status: (referer=resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref)

resources.infosecinstitute.com/wp-admin/admin-ajax.php status: (referer=resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref)

2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/plugins/thrive-leads/thrive-dashboard/js/dist/frontend.min.js?ver=2.0.29 status: (referer=resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref)

2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/plugins/captcha/js/script.js?ver=4.9.5 status: (referer=resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref)

2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.4.1 status: (referer=resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref)

platform.linkedin.com/in.js status: (referer=resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref)

www.redditstatic.com/button/button1.js status: (referer=resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref)

www2.infosecinstitute.com/l/12882/2015-02-12/fl8sp status: (referer=resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref)

cdn.onesignal.com/sdks/OneSignalSDK.js status: (referer=resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref)

2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/js/vendor/undefined status: (referer=2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/js/vendor/modernizr.min.js)

oss.maxcdn.com/html5shiv/3.7.2/undefined status: (referer=oss.maxcdn.com/html5shiv/3.7.2/html5shiv.min.js)

www.redditstatic.com/button/button2.html?url= status: (referer=www.redditstatic.com/button/button2.js)

All Malicious or Suspicious Elements of Submission

suspicious: maxruntime exceeded 10 seconds (incomplete) 0 bytes
2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/app.js benign
[nothing detected] (script) 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/app.js
     status: (referer=resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref)saved 179330 bytes afa76e591f9083d828f22083e9f76a786f638696
     info: ActiveXDataObjectsMDAC detected Microsoft.XMLHTTP
     file: afa76e591f9083d828f22083e9f76a786f638696: 179330 bytes

Decoded Files
afa7/6e591f9083d828f22083e9f76a786f638696 from 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/app.js (179330 bytes, 45015 hidden) download


2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/hideother.js benign
[nothing detected] (script) 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/hideother.js
     status: (referer=resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref)saved 754 bytes 7af8b5b503b404b0213af81ed44bb208fca8c5d9
     file: 7af8b5b503b404b0213af81ed44bb208fca8c5d9: 754 bytes

Decoded Files
7af8/b5b503b404b0213af81ed44bb208fca8c5d9 from 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/hideother.js (754 bytes, 63 hidden) download


2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-includes/js/wp-embed.min.js?ver=4.9.5 benign
[nothing detected] (script) 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-includes/js/wp-embed.min.js?ver=4.9.5
     status: (referer=resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref)saved 1398 bytes 54518be91b7c5d4b139e032d23ffae568cc7e9fd
     file: 54518be91b7c5d4b139e032d23ffae568cc7e9fd: 1398 bytes

Decoded Files
5451/8be91b7c5d4b139e032d23ffae568cc7e9fd from 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-includes/js/wp-embed.min.js?ver=4.9.5 (1398 bytes) download


resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref benign
[nothing detected] resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref
     status: (referer=http:/www.ask.com/web?q=puppies)saved 146371 bytes 9ab515ccf07bc27a3063a49a2186eca3f9d1534b
     info: [javascript variable] URL=resources.infosecinstitute.com/wp-admin/admin-ajax.php
     info: [script] oss.maxcdn.com/html5shiv/3.7.2/html5shiv.min.js
     info: [script] oss.maxcdn.com/respond/1.4.2/respond.min.js
     info: [script] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-includes/js/jquery/jquery.js?ver=1.12.4
     info: [script] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.4.1
     info: [script] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/js/vendor/modernizr.min.js
     info: [script] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/js/vendor/device.min.js
     info: [script] a.optmstr.com/app/js/api.min.js?ver=1.3.4
     info: [script] cdn.onesignal.com/sdks/OneSignalSDK.js
     info: [iframe] www.googletagmanager.com/ns.html?id=GTM-W9VWCG
     info: [img] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/assets/imagery/logo.png
     info: [script] www.redditstatic.com/button/button1.js
     info: [iframe] www2.infosecinstitute.com/l/12882/2015-02-12/fl8sp
     info: [img] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/uploads/030614_1456_ComputerFor1.png
     info: [img] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/uploads/030614_1456_ComputerFor2.png
     info: [img] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/uploads/030614_1456_ComputerFor3.png
     info: [img] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/uploads/030614_1456_ComputerFor4.png
     info: [img] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/uploads/030614_1456_ComputerFor5.png
     info: [img] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/uploads/030614_1456_ComputerFor6.png
     info: [script] www.redditstatic.com/button/button2.js
     info: [img] 2.gravatar.com/avatar/8f1530ecfa04f3746a31728cae720552?s=96&d=mm&r=g
     info: [img] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/uploads/sec+-lbox-72x40-ffffff.jpg
     info: [img] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/uploads/CEH1-lbox-72x40-ffffff.jpg
     info: [img] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/uploads/cissp-lbox-72x40-ffffff.jpg
     info: [img] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/uploads/NetworkHunters04302014-76x76-c-default.gif
     info: [img] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/uploads/Anti-Debugging-02122013-76x76-c-default.jpg
     info: [img] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/uploads/metasploit-01-76x76-c-default.jpg
     info: [img] 1.gravatar.com/avatar/d4b562ec4af7903504225f6327533c8a?s=32&d=mm&r=g
     info: [script] platform.linkedin.com/in.js
     info: [script] apis.google.com/js/platform.js
     info: [script] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/hideother.js
     info: [script] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/plugins/akismet/_inc/form.js?ver=4.0.3
     info: [script] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/app.js
     info: [script] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/plugins/thrive-leads/thrive-dashboard/js/dist/frontend.min.js?ver=2.0.29
     info: [script] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-includes/js/wp-embed.min.js?ver=4.9.5
     info: [script] 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/plugins/captcha/js/script.js?ver=4.9.5
     info: [decodingLevel=0] found JavaScript
     error: undefined function b.attachEvent
     error: undefined variable b
     info: [element] URL=resources.infosecinstitute.com/computer-forensics-investigation-case-study/undefined
     info: [var ajaxUrl] URL=resources.infosecinstitute.com/wp-admin/admin-ajax.php
     info: [var newurl] URL=resources.infosecinstitute.com/wp-admin/admin-ajax.php
     info: [decodingLevel=1] found JavaScript
     file: 9ab515ccf07bc27a3063a49a2186eca3f9d1534b: 146371 bytes
     file: 445188d05a8254db3b2d225dd53a646ca9cfa3e3: 258 bytes

Decoded Files
9ab5/15ccf07bc27a3063a49a2186eca3f9d1534b from resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref (146371 bytes, 7987 hidden) download

4451/88d05a8254db3b2d225dd53a646ca9cfa3e3 from resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref (258 bytes) download


oss.maxcdn.com/respond/1.4.2/respond.min.js benign
[nothing detected] (script) oss.maxcdn.com/respond/1.4.2/respond.min.js
     status: (referer=resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref)saved 4377 bytes b5aba40d65b0d6f85859db47f757ea971a0efd30
     info: ActiveXDataObjectsMDAC detected Microsoft.XMLHTTP
     file: b5aba40d65b0d6f85859db47f757ea971a0efd30: 4377 bytes

Decoded Files
b5ab/a40d65b0d6f85859db47f757ea971a0efd30 from oss.maxcdn.com/respond/1.4.2/respond.min.js (4377 bytes) download


2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/js/vendor/modernizr.min.js benign
[nothing detected] (script) 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/js/vendor/modernizr.min.js
     status: (referer=resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref)saved 11426 bytes 6f31ad08d08ebe3be09c7c077f308ee73d802227
     info: [decodingLevel=0] found JavaScript
     error: undefined variable j
     suspicious: maxruntime exceeded 10 seconds (incomplete) 0 bytes
     info: Decoding option navigator.systemLanguage=zh-cn and browser=IE7/XP and browser=IE8/Vista and browser=Opera and browser=Firefox,      0 bytes
     info: Decoding option navigator.systemLanguage=en,      152 bytes
     info: [element] URL=2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/js/vendor/undefined
     file: 6f31ad08d08ebe3be09c7c077f308ee73d802227: 11426 bytes
     file: 516e54a1db2cd2f44deea694d8513fbe0a047224: 11801 bytes
     file: 09b5ba608d22e6873ac7b6feb4ceb26a06bb52ef: 11796 bytes
     file: a533a02dab007b98351c6ff84a0e1f517fb1adae: 12005 bytes
     file: 77cf0bc137be24244e49d402035d145a0ee67db7: 12197 bytes
     file: bf5c2c451fbce6d975d526f53c0777c3a107e890: 11911 bytes
     file: fddcf6827dc66abf087fd53742432a851826f953: 12035 bytes
     file: d881e52bb649412d4114c90d74605e4c6a9e7db1: 152 bytes

Decoded Files
6f31/ad08d08ebe3be09c7c077f308ee73d802227 from 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/js/vendor/modernizr.min.js (11426 bytes) download

516e/54a1db2cd2f44deea694d8513fbe0a047224 from 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/js/vendor/modernizr.min.js (11801 bytes) download

09b5/ba608d22e6873ac7b6feb4ceb26a06bb52ef from 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/js/vendor/modernizr.min.js (11796 bytes) download

a533/a02dab007b98351c6ff84a0e1f517fb1adae from 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/js/vendor/modernizr.min.js (12005 bytes) download

77cf/0bc137be24244e49d402035d145a0ee67db7 from 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/js/vendor/modernizr.min.js (12197 bytes) download

bf5c/2c451fbce6d975d526f53c0777c3a107e890 from 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/js/vendor/modernizr.min.js (11911 bytes) download

fddc/f6827dc66abf087fd53742432a851826f953 from 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/js/vendor/modernizr.min.js (12035 bytes) download

d881/e52bb649412d4114c90d74605e4c6a9e7db1 from 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/js/vendor/modernizr.min.js (152 bytes) download


www.redditstatic.com/button/button2.js benign
[nothing detected] (script) www.redditstatic.com/button/button2.js
     status: (referer=resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref)saved 1073 bytes df0429606fa1507a8faceade41794e59fbdf3954
     info: [iframe] www.redditstatic.com/button/button2.html?url=
     info: [decodingLevel=0] found JavaScript
     info: DecodedIframe detected
     info: [iframe] www.redditstatic.com/button/button2.html?url=www.redditstatic.com%2Fbutton%2Fbutton2.js
     info: [decodingLevel=1] found JavaScript
     file: df0429606fa1507a8faceade41794e59fbdf3954: 1073 bytes
     file: 8da8b5283b2d019c17e8c2b758e0028ec16578b6: 191 bytes

Decoded Files
df04/29606fa1507a8faceade41794e59fbdf3954 from www.redditstatic.com/button/button2.js (1073 bytes, 61 hidden) download

8da8/b5283b2d019c17e8c2b758e0028ec16578b6 from www.redditstatic.com/button/button2.js (191 bytes) download


2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-includes/js/jquery/jquery.js?ver=1.12.4 benign
[nothing detected] (script) 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-includes/js/jquery/jquery.js?ver=1.12.4
     status: (referer=resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref)saved 97184 bytes 076524186dbbdd4c41afbbd6b260d9e46a095811
     info: ActiveXDataObjectsMDAC detected Microsoft.XMLHTTP
     info: [decodingLevel=0] found JavaScript
     error: undefined variable n
     file: 076524186dbbdd4c41afbbd6b260d9e46a095811: 97184 bytes

Decoded Files
0765/24186dbbdd4c41afbbd6b260d9e46a095811 from 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-includes/js/jquery/jquery.js?ver=1.12.4 (97184 bytes) download


oss.maxcdn.com/html5shiv/3.7.2/html5shiv.min.js benign
[nothing detected] (script) oss.maxcdn.com/html5shiv/3.7.2/html5shiv.min.js
     status: (referer=resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref)saved 2636 bytes bb51a5f6c394989bb06e4171179354c6d05ec8f8
     info: [decodingLevel=0] found JavaScript
     info: [element] URL=oss.maxcdn.com/html5shiv/3.7.2/undefined
     info: [1] no JavaScript
     file: bb51a5f6c394989bb06e4171179354c6d05ec8f8: 2636 bytes
     file: 05d40b3adeda38e1d01a1b93940aacca266a21e3: 70 bytes

Decoded Files
bb51/a5f6c394989bb06e4171179354c6d05ec8f8 from oss.maxcdn.com/html5shiv/3.7.2/html5shiv.min.js (2636 bytes) download

05d4/0b3adeda38e1d01a1b93940aacca266a21e3 from oss.maxcdn.com/html5shiv/3.7.2/html5shiv.min.js (70 bytes) download


2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/js/vendor/device.min.js benign
[nothing detected] (script) 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/js/vendor/device.min.js
     status: (referer=resources.infosecinstitute.com/computer-forensics-investigation-case-study/#gref)saved 3296 bytes 98d5079895cadb6b42e4379df565d8ad7dd44e36
     info: [decodingLevel=0] found JavaScript
     error: undefined variable d.className
     error: line:1: SyntaxError: missing ; before statement:
          error: line:1: var d.className = 1;
          error: line:1: ....^
     file: 98d5079895cadb6b42e4379df565d8ad7dd44e36: 3296 bytes

Decoded Files
98d5/079895cadb6b42e4379df565d8ad7dd44e36 from 2we26u4fam7n16rz3a44uhbe1bq2.wpengine.netdna-cdn.com/wp-content/themes/infosec/js/vendor/device.min.js (3296 bytes) download