JSUNPACK
A Generic JavaScript Unpacker
CAUTION: jsunpack was designed for security researchers and computer professionals
Enter a single URL (or paste JavaScript to decode):

Upload a PDF, pcap, HTML, or JavaScript file
Private? Help: privacy | uploads
Default Referer
Description

Submission permanent link e9e99876551e5a4258c1eba7f4b17f60feb63f31 (Received 2018-07-09 17:21:24, script )

URLStatus

All Malicious or Suspicious Elements of Submission

malicious: client download shellcode URL (non-executable) saved (5991f9ac33f38173ebc9d3ee27fc3703059741ae)
suspicious: shellcode of length 131/123
malicious: shellcode URL=chat.whatssap.me/3gGOkb1F5za0PzAv/
chat.whatssap.me/3gGOkb1F5za0PzAv/ malicious
[malicious:6] (ipaddr:69.175.68.55) (shellcode) chat.whatssap.me/3gGOkb1F5za0PzAv/
     status: (referer=http:/www.ask.com/web?q=puppies)saved 1139 bytes 5991f9ac33f38173ebc9d3ee27fc3703059741ae
     malicious: client download shellcode URL (non-executable) saved (5991f9ac33f38173ebc9d3ee27fc3703059741ae)
     info: file: saved chat.whatssap.me/3gGOkb1F5za0PzAv/ to (5991f9ac33f38173ebc9d3ee27fc3703059741ae)
     file: 5991f9ac33f38173ebc9d3ee27fc3703059741ae: 1139 bytes

Decoded Files
5991/f9ac33f38173ebc9d3ee27fc3703059741ae from chat.whatssap.me/3gGOkb1F5za0PzAv/ (1139 bytes, 16 hidden) download


chat.whatssap.me/verificando benign
[nothing detected] (var newurl) chat.whatssap.me/verificando
     status: (referer=http:/www.ask.com/web?q=puppies)saved 1139 bytes 5991f9ac33f38173ebc9d3ee27fc3703059741ae
     info: [0] no JavaScript
     file: 5991f9ac33f38173ebc9d3ee27fc3703059741ae: 1139 bytes

Decoded Files
5991/f9ac33f38173ebc9d3ee27fc3703059741ae from chat.whatssap.me/verificando (1139 bytes, 16 hidden) download


script malicious
[malicious:8] script
     info: [decodingLevel=0] found JavaScript
     error: undefined variable $
     error: undefined function $
     info: Decoding option navigator.systemLanguage=en and navigator.systemLanguage=zh-cn and browser=IE8/Vista,      423 bytes
     info: Decoding option browser=IE7/XP and browser=Opera and browser=Firefox,      454 bytes
     suspicious: shellcode of length 131/123
     malicious: shellcode URL=chat.whatssap.me/3gGOkb1F5za0PzAv/
     info: [var urlpubliMovil] URL=chat.whatssap.me/verificando
     info: [var urlpubliPC] URL=chat.whatssap.me/verificando
     info: [var newurl] URL=chat.whatssap.me/verificando
     info: [decodingLevel=1] found JavaScript
     info: file: saved script to (7ecf1bbad20d751c2babc89e7b356fd1e478f97e)
     file: 7ecf1bbad20d751c2babc89e7b356fd1e478f97e: 9478 bytes
     file: 2f669da1be3e03cb691344050a6aac04af7ff6f6: 454 bytes
     file: 4b95f94b82f816c23888f1cad0fcca71662123d8: 131 bytes

Decoded Files
7ecf/1bbad20d751c2babc89e7b356fd1e478f97e from script (9478 bytes) download

2f66/9da1be3e03cb691344050a6aac04af7ff6f6 from script (454 bytes) download

4b95/f94b82f816c23888f1cad0fcca71662123d8 from script (131 bytes, 11 hidden) download