JSUNPACK
A Generic JavaScript Unpacker
CAUTION: jsunpack was designed for security
researchers and computer professionals
Submission permanent link 2821587210332f6695d84a9fe20d5a5fad77ff5e (Received 2012-08-25 04:28:01, http://quizingen.net/d/p/c4e2n30801 )
| URL | Status |
| quizingen.net/d/p/c4e2n30801 | saved 470 bytes f727d94339e70b05257950cd176348ecd41d663f |
|
All Malicious or Suspicious Elements of Submission
None
mysearchproperties.com/images/js/cs-mn.js?251208 benign[nothing detected] (script) mysearchproperties.com/images/js/cs-mn.js?251208
status: (referer=clicks.coolsearchnow.com/fly?q=Investment+In+Properties&enk=hslGmeaBZpGPiabjJuOmuUbBpuMmmYapB8HGsSbBj4GPoQ==)saved 217 bytes d04e02eaffd6bd7b8307a83083333fd85db0feb1
info: [0] no JavaScript
file: d04e02eaffd6bd7b8307a83083333fd85db0feb1: 217 bytes
Decoded Filesd04e/02eaffd6bd7b8307a83083333fd85db0feb1 from mysearchproperties.com/images/js/cs-mn.js?251208 (217 bytes)
download
ww90.centralpropertysales.net/?framerequest=1 benign[nothing detected] (metarefresh) ww90.centralpropertysales.net/?framerequest=1
status: (referer=ww90.centralpropertysales.net/)saved 4398 bytes fb5483fb0f0b4b95f8dc4676ec60c04e32c36c6d
info: [meta refresh] URL=clicks.coolsearchnow.com/fly?q=Investment+In+Properties&enk=hslGmeaBZpGPiabjJuOmuUbBpuMmmYapB8HGsSbBj4GPoQ==
info: [script] ww90.centralpropertysales.net/
info: [decodingLevel=0] found JavaScript
error: line:3: SyntaxError: missing = in XML attribute:
error: line:3: <!DOCTYPE html PUBLIC "-/W3C/DTD XHTML 1.0 Transitional/EN" "http:/www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
error: line:3: ...............^
file: fb5483fb0f0b4b95f8dc4676ec60c04e32c36c6d: 4398 bytes
Decoded Filesfb54/83fb0f0b4b95f8dc4676ec60c04e32c36c6d from ww90.centralpropertysales.net/?framerequest=1 (4398 bytes, 32 hidden)
download
ww90.centralpropertysales.net/ benign[nothing detected] (var newurl) ww90.centralpropertysales.net/
status: (referer=quizingen.net/d/p/c4e2n30801)saved 1233 bytes 3ee84a5ba02249aacb7ae70013b6fc58f52953ea
info: [meta refresh] URL=ww90.centralpropertysales.net/?framerequest=1
info: [frame] ww90.centralpropertysales.net/
info: [decodingLevel=0] found JavaScript
error: undefined variable window.location.search
error: line:1: SyntaxError: missing ; before statement:
error: line:1: var window.location.search = 1;
error: line:1: ....^
error: line:3: SyntaxError: missing = in XML attribute:
error: line:3: <!DOCTYPE html PUBLIC "-/W3C/DTD XHTML 1.0 Transitional/EN" "http:/www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
error: line:3: ...............^
file: 3ee84a5ba02249aacb7ae70013b6fc58f52953ea: 1233 bytes
Decoded Files3ee8/4a5ba02249aacb7ae70013b6fc58f52953ea from ww90.centralpropertysales.net/ (1233 bytes, 42 hidden)
download
clicks.coolsearchnow.com/js/sk.js?251208 benign[nothing detected] (script) clicks.coolsearchnow.com/js/sk.js?251208
status: (referer=clicks.coolsearchnow.com/fly?q=Investment+In+Properties&enk=hslGmeaBZpGPiabjJuOmuUbBpuMmmYapB8HGsSbBj4GPoQ==)saved 206 bytes 81f0cd7202f2a7344aa0f57aa04dfa6e5205d2e8
info: [0] no JavaScript
file: 81f0cd7202f2a7344aa0f57aa04dfa6e5205d2e8: 206 bytes
Decoded Files81f0/cd7202f2a7344aa0f57aa04dfa6e5205d2e8 from clicks.coolsearchnow.com/js/sk.js?251208 (206 bytes)
download
quizingen.net/d/p/c4e2n30801 benign[nothing detected] quizingen.net/d/p/c4e2n30801
status: (referer=http:/www.twitter.com/trends/)saved 470 bytes f727d94339e70b05257950cd176348ecd41d663f
info: [meta refresh] URL=ww90.centralpropertysales.net
info: [decodingLevel=0] found JavaScript
info: [var location] URL=ww90.centralpropertysales.net
info: [var newurl] URL=ww90.centralpropertysales.net
info: [decodingLevel=1] found JavaScript
file: f727d94339e70b05257950cd176348ecd41d663f: 470 bytes
file: abe3b72852c62ad373f6be0c6829f53f3db6f469: 362 bytes
Decoded Filesf727/d94339e70b05257950cd176348ecd41d663f from quizingen.net/d/p/c4e2n30801 (470 bytes)
downloadabe3/b72852c62ad373f6be0c6829f53f3db6f469 from quizingen.net/d/p/c4e2n30801 (362 bytes)
download
clicks.coolsearchnow.com/js/sk-mn.js?251208 benign[nothing detected] (script) clicks.coolsearchnow.com/js/sk-mn.js?251208
status: (referer=clicks.coolsearchnow.com/fly?q=Investment+In+Properties&enk=hslGmeaBZpGPiabjJuOmuUbBpuMmmYapB8HGsSbBj4GPoQ==)saved 209 bytes 76c407dce5d9cbb286544cfe4f96f775a0f43cbd
info: [0] no JavaScript
file: 76c407dce5d9cbb286544cfe4f96f775a0f43cbd: 209 bytes
Decoded Files76c4/07dce5d9cbb286544cfe4f96f775a0f43cbd from clicks.coolsearchnow.com/js/sk-mn.js?251208 (209 bytes)
download
mysearchproperties.com/images/js/mmd5-mn.js?251208 benign[nothing detected] (script) mysearchproperties.com/images/js/mmd5-mn.js?251208
status: (referer=clicks.coolsearchnow.com/fly?q=Investment+In+Properties&enk=hslGmeaBZpGPiabjJuOmuUbBpuMmmYapB8HGsSbBj4GPoQ==)saved 219 bytes 58ab67e5df52dae6487152c136c00e25c75f3aed
info: [0] no JavaScript
file: 58ab67e5df52dae6487152c136c00e25c75f3aed: 219 bytes
Decoded Files58ab/67e5df52dae6487152c136c00e25c75f3aed from mysearchproperties.com/images/js/mmd5-mn.js?251208 (219 bytes)
download
mysearchproperties.com/images/ benign[nothing detected] (var newurl) mysearchproperties.com/images/
status: (referer=clicks.coolsearchnow.com/fly?q=Investment+In+Properties&enk=hslGmeaBZpGPiabjJuOmuUbBpuMmmYapB8HGsSbBj4GPoQ==)saved 209 bytes 43fa3d0fa511dad68fefa2a95da86817048600b6
info: [0] no JavaScript
file: 43fa3d0fa511dad68fefa2a95da86817048600b6: 209 bytes
Decoded Files43fa/3d0fa511dad68fefa2a95da86817048600b6 from mysearchproperties.com/images/ (209 bytes)
download
clicks.coolsearchnow.com/fly?q=Investment+In+Properties&enk=hslGmeaBZpGPiabjJuOmuUbBpuMmmYapB8HGsSbBj4GPoQ== benign[nothing detected] (metarefresh) clicks.coolsearchnow.com/fly?q=Investment+In+Properties&enk=hslGmeaBZpGPiabjJuOmuUbBpuMmmYapB8HGsSbBj4GPoQ==
status: (referer=ww90.centralpropertysales.net/?framerequest=1)saved 6412 bytes 103618cf885bea50602a678c4a7b2747056c184b
info: [javascript variable] URL=mysearchproperties.com/images/
info: [script] clicks.coolsearchnow.com/js/main.js?251208
info: [script] mysearchproperties.com/images/js/cs-mn.js?251208
info: [script] mysearchproperties.com/images/js/mmd5-mn.js?251208
info: [script] clicks.coolsearchnow.com/js/sk.js?251208
info: [script] clicks.coolsearchnow.com/js/sk-mn.js?251208
info: [decodingLevel=0] found JavaScript
info: [var IS] URL=mysearchproperties.com/images/
info: [var newurl] URL=mysearchproperties.com/images/
info: [decodingLevel=1] found JavaScript
file: 103618cf885bea50602a678c4a7b2747056c184b: 6412 bytes
file: 8574ede46807a89fce7cc3c07b12546f11c30d47: 130 bytes
Decoded Files1036/18cf885bea50602a678c4a7b2747056c184b from clicks.coolsearchnow.com/fly?q=Investment+In+Properties&enk=hslGmeaBZpGPiabjJuOmuUbBpuMmmYapB8HGsSbBj4GPoQ== (6412 bytes, 31 hidden)
download8574/ede46807a89fce7cc3c07b12546f11c30d47 from clicks.coolsearchnow.com/fly?q=Investment+In+Properties&enk=hslGmeaBZpGPiabjJuOmuUbBpuMmmYapB8HGsSbBj4GPoQ== (130 bytes)
download
clicks.coolsearchnow.com/js/main.js?251208 benign[nothing detected] (script) clicks.coolsearchnow.com/js/main.js?251208
status: (referer=clicks.coolsearchnow.com/fly?q=Investment+In+Properties&enk=hslGmeaBZpGPiabjJuOmuUbBpuMmmYapB8HGsSbBj4GPoQ==)saved 208 bytes 357592e52a75d92edd6cf66a1bfb60141d18d3f4
info: [0] no JavaScript
file: 357592e52a75d92edd6cf66a1bfb60141d18d3f4: 208 bytes
Decoded Files3575/92e52a75d92edd6cf66a1bfb60141d18d3f4 from clicks.coolsearchnow.com/js/main.js?251208 (208 bytes)
download