JSUNPACK
A Generic JavaScript Unpacker
CAUTION: jsunpack was designed for security
researchers and computer professionals
Submission permanent link 35c80196904c8ca2e45f17171c90f5e0f1e616fe (Received 2012-11-17 14:07:57, http://mntr.babcdn.com/mntr/apps/babylon/1.3.1/mnu.htm
)
| URL | Status |
| mntr.babcdn.com/mntr/apps/babylon/1.3.1/mnu.htm | saved 3011 bytes b0e9310a0775a11946423d6ead72b1db3a8559a7 |
|
| acx.babsrv.com/?f=1&cou= | status: (referer=zonealarm.claro-search.com/) |
|
| ac.babsrv.com/?f=1&cou= | status: (referer=zonealarm.claro-search.com/) |
|
| search.yahooapis.com/WebSearchService/V1/relatedSuggestion?appid=YahooDemo&output=json&callback=yahRel&query= | status: (referer=zonealarm.claro-search.com/) |
|
| aci.babsrv.com/?f=1&&cou= | status: (referer=zonealarm.claro-search.com/) |
|
| www.googletagservices.com/tag/js/gpt.js | status: (referer=zonealarm.claro-search.com/) |
|
| acr.babsrv.com/?f=1&cou= | status: (referer=zonealarm.claro-search.com/) |
|
| acz.babsrv.com/?f=1&cou= | status: (referer=zonealarm.claro-search.com/) |
|
| act.babsrv.com/?f=1&cou= | status: (referer=zonealarm.claro-search.com/) |
|
| completr-v2.appspot.com/?q= | status: (referer=zonealarm.claro-search.com/) |
|
All Malicious or Suspicious Elements of Submission
None
zonealarm.claro-search.com/ benign[nothing detected] (jsvar) zonealarm.claro-search.com/
status: (referer=cnfg.montiera.com/appsCntrl/babylon/bbylnDef131.js)saved 11094 bytes ad87899b6a46b688f9094f759e9cab52adaadb31
info: [javascript variable] URL=act.babsrv.com/?f=1&cou=
info: [javascript variable] URL=ac.babsrv.com/?f=1&cou=
info: [javascript variable] URL=acx.babsrv.com/?f=1&cou=
info: [javascript variable] URL=acr.babsrv.com/?f=1&cou=
info: [javascript variable] URL=aci.babsrv.com/?f=1&&cou=
info: [javascript variable] URL=acy.babsrv.com/?f=1&cou=
info: [javascript variable] URL=acz.babsrv.com/?f=1&cou=
info: [javascript variable] URL=completr-v2.appspot.com/?q=
info: [javascript variable] URL=search.yahooapis.com/WebSearchService/V1/relatedSuggestion?appid=YahooDemo&output=json&callback=yahRel&query=
info: [img] usw.cdn-services.com/b/images/small9.jpg
info: [decodingLevel=0] found JavaScript
error: undefined variable node
info: [element] URL=www.googletagservices.com/tag/js/gpt.js
info: [1] no JavaScript
file: ad87899b6a46b688f9094f759e9cab52adaadb31: 11094 bytes
file: 8dc44cfcfd5c417ac7d6299f38c84ccc02a30c0a: 112 bytes
Decoded Filesad87/899b6a46b688f9094f759e9cab52adaadb31 from zonealarm.claro-search.com/ (11094 bytes, 195 hidden)
download8dc4/4cfcfd5c417ac7d6299f38c84ccc02a30c0a from zonealarm.claro-search.com/ (112 bytes)
download
cnfg.montiera.com/appsCntrl/babylon/bbylnDef131.js benign[nothing detected] (script) cnfg.montiera.com/appsCntrl/babylon/bbylnDef131.js
status: (referer=mntr.babcdn.com/mntr/apps/babylon/1.3.1/mnu.htm)saved 17607 bytes 665677aa0b61fd26ec0b8ea76c3256ba88d4b74d
info: [javascript variable] URL=zonealarm.claro-search.com
info: [decodingLevel=0] found JavaScript
file: 665677aa0b61fd26ec0b8ea76c3256ba88d4b74d: 17607 bytes
Decoded Files6656/77aa0b61fd26ec0b8ea76c3256ba88d4b74d from cnfg.montiera.com/appsCntrl/babylon/bbylnDef131.js (17607 bytes, 4622 hidden)
download
mntr.babcdn.com/mntr/mntr/ benign[nothing detected] (script) mntr.babcdn.com/mntr/mntr/
status: (referer=mntr.babcdn.com/mntr/mntr/mtldr.js)saved 571 bytes 47a8d1e900538e3e0ea1e9177d241cd1f98f222c
info: [0] no JavaScript
file: 47a8d1e900538e3e0ea1e9177d241cd1f98f222c: 571 bytes
Decoded Files47a8/d1e900538e3e0ea1e9177d241cd1f98f222c from mntr.babcdn.com/mntr/mntr/ (571 bytes, 13 hidden)
download
www.google.com/jsapi benign[nothing detected] (script) www.google.com/jsapi
status: (referer=mntr.babcdn.com/mntr/apps/babylon/1.3.1/mnu.htm)saved 24425 bytes 9df52f346b1520c70ae833f6b872f430746882e4
info: [script] :
info: [script] www.google.com/
info: [decodingLevel=0] found JavaScript
file: 9df52f346b1520c70ae833f6b872f430746882e4: 24425 bytes
Decoded Files9df5/2f346b1520c70ae833f6b872f430746882e4 from www.google.com/jsapi (24425 bytes)
download
acy.babsrv.com/?f=1&cou= benign[nothing detected] (jsvar) acy.babsrv.com/?f=1&cou=
status: (referer=zonealarm.claro-search.com/)saved 42 bytes 5f5f3a645bf641bb3438844f5cb7d2e898e877f1
info: [0] no JavaScript
file: 5f5f3a645bf641bb3438844f5cb7d2e898e877f1: 42 bytes
Decoded Files5f5f/3a645bf641bb3438844f5cb7d2e898e877f1 from acy.babsrv.com/?f=1&cou= (42 bytes)
download
mntr.babcdn.com/mntr/apps/babylon/1.3.1/mnu.htm benign[nothing detected] mntr.babcdn.com/mntr/apps/babylon/1.3.1/mnu.htm
status: (referer=http:/mntr.babcdn.com/mntr/apps/babylon/1.3.1/mnu.htm)saved 3011 bytes b0e9310a0775a11946423d6ead72b1db3a8559a7
info: [script] www.google.com/jsapi
info: [script] cnfg.montiera.com/appsCntrl/babylon/bbylnDef131.js
info: [script] mntr.babcdn.com/mntr/apps/babylon/1.3.1/bbylnVrsnDef.js
info: [script] mntr.babcdn.com/mntr/mntr/mtldr.js
info: [script] mntr.babcdn.com/mntr/mntr/3rdparty/json2.min.js
info: [decodingLevel=0] found JavaScript
error: undefined variable $
error: undefined function $
info: [decodingLevel=1] found JavaScript
file: b0e9310a0775a11946423d6ead72b1db3a8559a7: 3011 bytes
file: 142bc40282f95492f64acfbf20df171a635bf6e5: 374 bytes
Decoded Filesb0e9/310a0775a11946423d6ead72b1db3a8559a7 from mntr.babcdn.com/mntr/apps/babylon/1.3.1/mnu.htm (3011 bytes, 582 hidden)
download142b/c40282f95492f64acfbf20df171a635bf6e5 from mntr.babcdn.com/mntr/apps/babylon/1.3.1/mnu.htm (374 bytes, 86 hidden)
download
mntr.babcdn.com/mntr/apps/babylon/1.3.1/bbylnVrsnDef.js benign[nothing detected] (script) mntr.babcdn.com/mntr/apps/babylon/1.3.1/bbylnVrsnDef.js
status: (referer=mntr.babcdn.com/mntr/apps/babylon/1.3.1/mnu.htm)saved 159 bytes f38beba64bf9ab007fac23e4d7ad053e792c4492
info: [decodingLevel=0] found JavaScript
file: f38beba64bf9ab007fac23e4d7ad053e792c4492: 159 bytes
Decoded Filesf38b/eba64bf9ab007fac23e4d7ad053e792c4492 from mntr.babcdn.com/mntr/apps/babylon/1.3.1/bbylnVrsnDef.js (159 bytes, 41 hidden)
download
mntr.babcdn.com/mntr/mntr/mtldr.js benign[nothing detected] (script) mntr.babcdn.com/mntr/mntr/mtldr.js
status: (referer=mntr.babcdn.com/mntr/apps/babylon/1.3.1/mnu.htm)saved 4819 bytes c495d4f58fdf7a19bfe9f96190256fb11e03ef49
info: [javascript variable] URL=
info: [script] mntr.babcdn.com/mntr/mntr/
info: [decodingLevel=0] found JavaScript
file: c495d4f58fdf7a19bfe9f96190256fb11e03ef49: 4819 bytes
Decoded Filesc495/d4f58fdf7a19bfe9f96190256fb11e03ef49 from mntr.babcdn.com/mntr/mntr/mtldr.js (4819 bytes, 1447 hidden)
download
mntr.babcdn.com/mntr/mntr/3rdparty/json2.min.js benign[nothing detected] (script) mntr.babcdn.com/mntr/mntr/3rdparty/json2.min.js
status: (referer=mntr.babcdn.com/mntr/apps/babylon/1.3.1/mnu.htm)saved 2075 bytes 88f4a8743b8f935e6f9652aadada70072a7e5d7b
info: [decodingLevel=0] found JavaScript
file: 88f4a8743b8f935e6f9652aadada70072a7e5d7b: 2075 bytes
Decoded Files88f4/a8743b8f935e6f9652aadada70072a7e5d7b from mntr.babcdn.com/mntr/mntr/3rdparty/json2.min.js (2075 bytes, 5 hidden)
download