JSUNPACK
A Generic JavaScript Unpacker
CAUTION: jsunpack was designed for security
researchers and computer professionals
Submission permanent link ebde4541a64a3a138c95c8ad8d10cd7598d189f7 (Received 2010-02-14 18:36:16, 1.xhcuns.com/a/xiaoshuolei/wuxiagudian/20100105/2902.html )
| URL | Status |
| 1.xhcuns.com/a/xiaoshuolei/wuxiagudian/20100105/2902.html | saved 22166 bytes to fetch_f42c3c6d073628220ef5bf5e747783e8a207e3ab |
|
| 1.xhcuns.com/plus/count.php?view=yes&aid= | saved 0 bytes to fetch_da39a3ee5e6b4b0d3255bfef95601890afd80709 |
|
| 1.xhcuns.com/gg/zxj.htm | saved 1034 bytes to fetch_4964ca167b9011b15b086837543dacfa4bcdbf1f |
|
| 1.xhcuns.com/gg/900.js | failure: HTTP Error 404: Not Found |
|
| 1.xhcuns.com/gg/900.htm | saved 194 bytes to fetch_5c4e6f50cdc05d1d90e251697880fe0a4aa8f31c |
|
| 1.xhcuns.com/gg/ybhf.htm | failure: HTTP Error 404: Not Found |
|
| s10.histats.com/js9.js | saved 7363 bytes to fetch_345c46680f68f435e77e5b9cdd39935c97c4ee5e |
|
| pstatic.xunlei.com/js/webThunderDetect.js | saved 20027 bytes to fetch_252ccf7a1db20dabf716d00b36fa8a87bca20d75 |
|
| 1.xhcuns.com/plus/ad_js.php?aid=3 | saved 1696 bytes to fetch_65ad74eeb3b7f8256814d83a017fb601787ce278 |
|
| 1.xhcuns.com/plus/ad_js.php?aid=2 | saved 130 bytes to fetch_2a88e0592153455d52486b3c7e22ef253e80a02e |
|
| 1.xhcuns.com/js/dy.js | failure: HTTP Error 404: Not Found |
|
| 1.xhcuns.com/plus/ad_js.php?aid=7 | saved 32 bytes to fetch_2eee4ccf9f984da8e17703857d6b1bda8ef30350 |
|
| 1.xhcuns.com/plus/ad_js.php?aid=6 | saved 32 bytes to fetch_2eee4ccf9f984da8e17703857d6b1bda8ef30350 |
|
| 1.newlinkexchange.nl/link/duilian.js | saved 1507 bytes to fetch_d56aada5583fd4444bc086eef942142f74b5ab1a |
|
| 1.xhcuns.com/gglink/guanggao.js | failure: HTTP Error 404: Not Found |
|
| 1.xhcuns.com/gg/pf.js | failure: HTTP Error 404: Not Found |
|
| 1.xhcuns.com/gg/728d.htm | failure: HTTP Error 404: Not Found |
|
| 1.xhcuns.com/js/base64.js | failure: HTTP Error 404: Not Found |
|
| 1.xhcuns.com/gg/zxj2.htm | saved 620 bytes to fetch_3be3f170c2fa843936b8744b13404e455f61ec1c |
|
| 1.xhcuns.com/js/search.js | saved 1092 bytes to fetch_3f592c46134e4c605a7eec3063536a3ec5b69730 |
|
| 1.xhcuns.com/gg/760h.js | failure: HTTP Error 404: Not Found |
|
| 1.xhcuns.com/js/thunderForum.js | failure: HTTP Error 404: Not Found |
|
| 1.xhcuns.com/gg/yb120.htm | failure: HTTP Error 404: Not Found |
|
| 1.xhcuns.com/gg/728db.htm | failure: HTTP Error 404: Not Found |
|
| analytics-union.xunlei.com/PV?peerid=0&uri=http://thunderqtypv.union.xunlei.com&src=undefined | saved 0 bytes to fetch_da39a3ee5e6b4b0d3255bfef95601890afd80709 |
|
| banners.getiton.com/go/page/iframe_large_thumbs_180x179?pid=g1202053-ppc | saved 9896 bytes to fetch_3e036afd756b47e1534279fadb8745244cd7b9b9 |
|
| 74.63.102.91/link/click.php?fromid=1 | saved 3930 bytes to fetch_1ace251e7adfa9197fd763b953eefcc553903706 |
|
| s10./ | failure: <urlopen error (-2, 'Name or service not known')> |
|
| s10.histats.com/ | saved 2 bytes to fetch_a5d5b61aa8a61b7d9d765e1daf971a9a578f1cfa |
|
| banners.getiton.com/piclist?pid=g1202053-ppc&display=gio_flash_07&grid=1x2&textsearch=一夜情性交&use_flash=1&no_fakevid=1&photo=1&banner_title=%u5728[LOC]%u7684GetItOn%u6703%u54E1%u5C0D%u7D66%u4E88%u53E3%u4EA4%u611F%u8208%u8DA3&text_color=#000000&link_col | saved 5601 bytes to fetch_256cb1f5f49a27f912fc4174ca003b5a75637275 |
|
| content.pop6.com/banners/getiton/english/18584_160x600.swf | saved 52297 bytes to fetch_e309a144e1bf2a31cc06d1dabeff88bbfd36324f |
|
| ads.159ads.cn/ads.js | saved 207 bytes to fetch_eff98f6468aabc97c40191ca401e293b2e45d89b |
|
All Malicious or Suspicious Elements of Submission
None
1.xhcuns.com/plus/count.php?view=yes&aid= benign[nothing detected] (script) 1.xhcuns.com/plus/count.php?view=yes&aid=
File information (1 files) Download zip | Explanationfetch_da39a3ee5e6b4b0d3255bfef95601890afd80709 from 1.xhcuns.com/plus/count.php?view=yes&aid= (0 bytes)
1.xhcuns.com/gg/zxj.htm benign[nothing detected] (iframe) 1.xhcuns.com/gg/zxj.htm
info: [embed http] content.pop6.com/banners/getiton/english/18584_160x600.swf
File information (1 files) Download zip | Explanationfetch_4964ca167b9011b15b086837543dacfa4bcdbf1f from 1.xhcuns.com/gg/zxj.htm (1034 bytes, 8 hidden)
1.xhcuns.com/gg/zxj2.htm benign[nothing detected] (iframe) 1.xhcuns.com/gg/zxj2.htm
info: [iframe http] banners.getiton.com/piclist?pid=g1202053-ppc&display=gio_flash_07&grid=1x2&textsearch=一夜情性交&use_flash=1&no_fakevid=1&photo=1&banner_title=%u5728%5BLOC%5D%u7684GetItOn%u6703%u54E1%u5C0D%u7D66%u4E88%u53E3%u4EA4%u611F%u8208%u8DA3&text_color=%23000000&link_color=%23114376&background_color=%23F3F3F3&border_color=%23DDDDDD&overlay_color=%234973AF&overlay_text_color=%23FFFFFF&photo_frame_color=%235A99F9&photo_frame_text_color=%23FFFFFF&thumb=portrait&iframe=1&site=getiton&models=1
File information (1 files) Download zip | Explanationfetch_3be3f170c2fa843936b8744b13404e455f61ec1c from 1.xhcuns.com/gg/zxj2.htm (620 bytes, 11 hidden)
74.63.102.91/link/click.php?fromid=1 benign[nothing detected] (var suspendcode14) 74.63.102.91/link/click.php?fromid=1
info: [script http] s134.cnzz.com/stat.php?id=1246003&web_id=1246003
info: [decodingLevel=0] found JavaScript
info: [decodingLevel=0] decoded 6525 bytes (decoding_5980b2e0f86f577f74abebcab4604840e3b05f36)
File information (2 files) Download zip | Explanationfetch_1ace251e7adfa9197fd763b953eefcc553903706 from 74.63.102.91/link/click.php?fromid=1 (3930 bytes, 633 hidden)
decoding_5980b2e0f86f577f74abebcab4604840e3b05f36 from 74.63.102.91/link/click.php?fromid=1 (6525 bytes)
content.pop6.com/banners/getiton/english/18584_160x600.swf benign[nothing detected] [SWF] (embed) content.pop6.com/banners/getiton/english/18584_160x600.swf
info: [decodingLevel=0] found JavaScript
File information (1 files) Download zip | Explanationfetch_e309a144e1bf2a31cc06d1dabeff88bbfd36324f from content.pop6.com/banners/getiton/english/18584_160x600.swf (52297 bytes, 31501 hidden)
1.xhcuns.com/plus/ad_js.php?aid=3 benign[nothing detected] (script) 1.xhcuns.com/plus/ad_js.php?aid=3
info: [decodingLevel=0] found JavaScript
File information (1 files) Download zip | Explanationfetch_65ad74eeb3b7f8256814d83a017fb601787ce278 from 1.xhcuns.com/plus/ad_js.php?aid=3 (1696 bytes, 165 hidden)
1.xhcuns.com/plus/ad_js.php?aid=2 benign[nothing detected] (script) 1.xhcuns.com/plus/ad_js.php?aid=2
info: [script http] ads.159ads.cn/ads.js
info: [decodingLevel=0] found JavaScript
File information (1 files) Download zip | Explanationfetch_2a88e0592153455d52486b3c7e22ef253e80a02e from 1.xhcuns.com/plus/ad_js.php?aid=2 (130 bytes, 3 hidden)
analytics-union.xunlei.com/PV?peerid=0&uri=http://thunderqtypv.union.xunlei.com&src=undefined benign[nothing detected] (var vhref) analytics-union.xunlei.com/PV?peerid=0&uri=http://thunderqtypv.union.xunlei.com&src=undefined
File information (1 files) Download zip | Explanationfetch_da39a3ee5e6b4b0d3255bfef95601890afd80709 from analytics-union.xunlei.com/PV?peerid=0&uri=http://thunderqtypv.union.xunlei.com&src=undefined (0 bytes)
1.xhcuns.com/js/search.js benign[nothing detected] (script) 1.xhcuns.com/js/search.js
info: [decodingLevel=0] found JavaScript
info: [decodingLevel=0] decoded 714 bytes (decoding_6cb45ead651f5ae231a6002754f68bf94496c902)
info: [decodingLevel=1] found JavaScript
File information (2 files) Download zip | Explanationfetch_3f592c46134e4c605a7eec3063536a3ec5b69730 from 1.xhcuns.com/js/search.js (1092 bytes, 88 hidden)
decoding_6cb45ead651f5ae231a6002754f68bf94496c902 from 1.xhcuns.com/js/search.js (714 bytes, 70 hidden)
1.xhcuns.com/gg/900.htm benign[nothing detected] (iframe) 1.xhcuns.com/gg/900.htm
info: [iframe http] banners.getiton.com/go/page/iframe_large_thumbs_180x179?pid=g1202053-ppc
File information (1 files) Download zip | Explanationfetch_5c4e6f50cdc05d1d90e251697880fe0a4aa8f31c from 1.xhcuns.com/gg/900.htm (194 bytes, 1 hidden)
s10.histats.com/js9.js benign[nothing detected] (script) s10.histats.com/js9.js
info: [javascript variable] URL=s10.
info: [embed .] s10.histats.com/
info: [script http] s
info: [decodingLevel=0] found JavaScript
File information (1 files) Download zip | Explanationfetch_345c46680f68f435e77e5b9cdd39935c97c4ee5e from s10.histats.com/js9.js (7363 bytes, 11 hidden)
1.newlinkexchange.nl/link/duilian.js benign[nothing detected] (script) 1.newlinkexchange.nl/link/duilian.js
info: [img http] qjgtjq.blu.livefilestore.com/y1pjZxeyFdBHbgloD-P6NTmb0R6iPeWlWz3AqBOAopoXEESF7ULIF47pyhuWgvEC6AJ0pVGLpROxTbSXa9KDK75ms9RFOULuR_s/left.gif
info: [img http] qjgtjq.blu.livefilestore.com/y1pjZxeyFdBHbjIEE96WLWT7Z_Ux7d7eotm8AxUggS_2s16u0TORBt3BuUIKr16yDSmr_Gfjh1LX5SIyD-OTv6LFy6HvmwLw5NB/right.gif
info: [decodingLevel=0] found JavaScript
info: [decodingLevel=0] decoded 1406 bytes (decoding_f04b1c7e62bff63e1b330b274369870216144946)
info: [var suspendcode12] URL=74.63.102.91/link/click.php?fromid=1
info: [var suspendcode12] URL=qjgtjq.blu.livefilestore.com/y1pjZxeyFdBHbgloD-P6NTmb0R6iPeWlWz3AqBOAopoXEESF7ULIF47pyhuWgvEC6AJ0pVGLpROxTbSXa9KDK75ms9RFOULuR_s/left.gif
info: [var suspendcode14] URL=74.63.102.91/link/click.php?fromid=1
info: [var suspendcode14] URL=qjgtjq.blu.livefilestore.com/y1pjZxeyFdBHbjIEE96WLWT7Z_Ux7d7eotm8AxUggS_2s16u0TORBt3BuUIKr16yDSmr_Gfjh1LX5SIyD-OTv6LFy6HvmwLw5NB/right.gif
info: [decodingLevel=1] found JavaScript
File information (2 files) Download zip | Explanationfetch_d56aada5583fd4444bc086eef942142f74b5ab1a from 1.newlinkexchange.nl/link/duilian.js (1507 bytes, 49 hidden)
decoding_f04b1c7e62bff63e1b330b274369870216144946 from 1.newlinkexchange.nl/link/duilian.js (1406 bytes)
banners.getiton.com/go/page/iframe_large_thumbs_180x179?pid=g1202053-ppc benign[nothing detected] (iframe) banners.getiton.com/go/page/iframe_large_thumbs_180x179?pid=g1202053-ppc
info: [javascript variable] URL=graphics.pop6.com/images/banners/common/female_180x179/
info: [javascript variable] URL=getiton.com/p/register.cgi?pid=g1202053-ppc
info: [javascript variable] URL=1.xhcuns.com/gg/900.htm
info: [img .] banners.getiton.com/go/page/
info: [script .] banners.getiton.com/go/page/
info: [img http] glean.pop6.com/images/common/glean.gif?rand=4957&site=getiton&session=U%5Ch%60%3EdjS3eGg+1266182445+67.217.160.100+&pwsid=&pagename=ttp%3A%2F%2F1.xhcuns.com%2Fgg%2F900.htm&pagestate=&country=United+States&city=&lang=english&level=&gpid=g1202053&pid=g1202053-ppc
info: [decodingLevel=0] found JavaScript
info: [decodingLevel=0] decoded 2768 bytes (decoding_ef4657581f2e60d3c47bfbd255a43c5d37005b0a)
info: [var udImgPre] URL=graphics.pop6.com/images/banners/common/female_180x179/
info: [var udLink] URL=getiton.com/p/register.cgi?pid=g1202053-ppc
info: [var gaJsHost] URL=www.
info: [img http] graphics.pop6.com/images/banners/common/female_180x179/16.jpg
info: [img http] graphics.pop6.com/images/banners/common/female_180x179/00.jpg
info: [img http] graphics.pop6.com/images/banners/common/female_180x179/03.jpg
info: [img http] graphics.pop6.com/images/banners/common/female_180x179/09.jpg
info: [img http] graphics.pop6.com/images/banners/common/female_180x179/11.jpg
info: [script http] www.google-analytics.com/ga.js
info: [decodingLevel=1] found JavaScript
File information (2 files) Download zip | Explanationfetch_3e036afd756b47e1534279fadb8745244cd7b9b9 from banners.getiton.com/go/page/iframe_large_thumbs_180x179?pid=g1202053-ppc (9896 bytes, 257 hidden)
decoding_ef4657581f2e60d3c47bfbd255a43c5d37005b0a from banners.getiton.com/go/page/iframe_large_thumbs_180x179?pid=g1202053-ppc (2768 bytes)
1.xhcuns.com/a/xiaoshuolei/wuxiagudian/20100105/2902.html benign[nothing detected] 1.xhcuns.com/a/xiaoshuolei/wuxiagudian/20100105/2902.html
info: [script /] 1.xhcuns.com/gg/760h.js
info: [script /] 1.xhcuns.com/plus/ad_js.php?aid=3
info: [script /] 1.xhcuns.com/plus/ad_js.php?aid=7
info: [script /] 1.xhcuns.com/plus/ad_js.php?aid=2
info: [script /] 1.xhcuns.com/plus/ad_js.php?aid=6
info: [img /] 1.xhcuns.com/images/bbs_btn.gif
info: [iframe /] 1.xhcuns.com/gg/zxj.htm
info: [iframe /] 1.xhcuns.com/gg/zxj2.htm
info: [script /] 1.xhcuns.com/js/search.js
info: [iframe /] 1.xhcuns.com/gg/728db.htm
info: [script /] 1.xhcuns.com/js/dy.js
info: [iframe /] 1.xhcuns.com/gg/yb120.htm
info: [iframe /] 1.xhcuns.com/gg/ybhf.htm
info: [iframe /] 1.xhcuns.com/gg/728d.htm
info: [script /] 1.xhcuns.com/plus/count.php?view=yes&aid=
info: [script http] pstatic.xunlei.com/js/webThunderDetect.js
info: [script /] 1.xhcuns.com/js/base64.js
info: [script /] 1.xhcuns.com/js/thunderForum.js
info: [iframe /] 1.xhcuns.com/gg/900.htm
info: [script /] 1.xhcuns.com/gg/900.js
info: [script http] s10.histats.com/js9.js
info: [img http] s4.histats.com/stats/0.gif?946652&1
info: [script /] 1.xhcuns.com/gg/pf.js
info: [script http] 1.xhcuns.com/gglink/guanggao.js
info: [script http] 1.newlinkexchange.nl/link/duilian.js
info: [decodingLevel=0] found JavaScript
File information (1 files) Download zip | Explanationfetch_f42c3c6d073628220ef5bf5e747783e8a207e3ab from 1.xhcuns.com/a/xiaoshuolei/wuxiagudian/20100105/2902.html (22166 bytes, 6025 hidden)
1.xhcuns.com/plus/ad_js.php?aid=7 benign[nothing detected] (script) 1.xhcuns.com/plus/ad_js.php?aid=7
info: [decodingLevel=0] found JavaScript
File information (1 files) Download zip | Explanationfetch_2eee4ccf9f984da8e17703857d6b1bda8ef30350 from 1.xhcuns.com/plus/ad_js.php?aid=7 (32 bytes, 3 hidden)
ads.159ads.cn/ads.js benign[nothing detected] (script) ads.159ads.cn/ads.js
info: [script http] ads.159ads.cn/stats.js
info: [script http] ads.159ads.cn/468x60.js
info: [decodingLevel=0] found JavaScript
info: [decodingLevel=0] decoded 177 bytes (decoding_a07a814b5913cfa18ada81dd968f475bb23532b5)
info: [decodingLevel=1] found JavaScript
File information (2 files) Download zip | Explanationfetch_eff98f6468aabc97c40191ca401e293b2e45d89b from ads.159ads.cn/ads.js (207 bytes, 1 hidden)
decoding_a07a814b5913cfa18ada81dd968f475bb23532b5 from ads.159ads.cn/ads.js (177 bytes)
banners.getiton.com/piclist?pid=g1202053-ppc&display=gio_flash_07&grid=1x2&textsearch=一夜情性交&use_flash=1&no_fakevid=1&photo=1&banner_title=%u5728[LOC]%u7684GetItOn%u6703%u54E1%u5C0D%u7D66%u4E88%u53E3%u4EA4%u611F%u8208%u8DA3&text_color=#000000&link_col benign[nothing detected] (iframe) banners.getiton.com/piclist?pid=g1202053-ppc&display=gio_flash_07&grid=1x2&textsearch=一夜情性交&use_flash=1&no_fakevid=1&photo=1&banner_title=%u5728[LOC]%u7684GetItOn%u6703%u54E1%u5C0D%u7D66%u4E88%u53E3%u4EA4%u611F%u8208%u8DA3&text_color=#000000&link_color=#114376&background_color=#F3F3F3&border_color=#DDDDDD&overlay_color=#4973AF&overlay_text_color=#FFFFFF&photo_frame_color=#5A99F9&photo_frame_text_color=#FFFFFF&thumb=portrait&iframe=1&site=getiton&models=1
info: [decodingLevel=0] found JavaScript
info: [decodingLevel=0] decoded 5416 bytes (decoding_4c47a504941b185037c440278425b82c52116627)
info: [javascript variable] URL=content.pop6.com/images/getiton/piclist/english/piclist_gio_flash_01v.swf
info: [javascript variable] URL=content.pop6.com/images/ffadult/flash/expressInstall.swf
info: [script /] banners.getiton.com/javascript/getiton-rm_swfobject-1248882689.js
info: [decodingLevel=1] found JavaScript
info: [decodingLevel=1] decoded 203 bytes (decoding_a9852b3b78be1b90c1f89b7e528f8f330003e4f2)
info: [var swf] URL=content.pop6.com/images/getiton/piclist/english/piclist_gio_flash_01v.swf
info: [var installer] URL=content.pop6.com/images/ffadult/flash/expressInstall.swf
info: [decodingLevel=2] found JavaScript
File information (3 files) Download zip | Explanationfetch_256cb1f5f49a27f912fc4174ca003b5a75637275 from banners.getiton.com/piclist?pid=g1202053-ppc&display=gio_flash_07&grid=1x2&textsearch=一夜情性交&use_flash=1&no_fakevid=1&photo=1&banner_title=%u5728[LOC]%u7684GetItOn%u6703%u54E1%u5C0D%u7D66%u4E88%u53E3%u4EA4%u611F%u8208%u8DA3&text_color=#000000&link_col (5601 bytes, 445 hidden)
decoding_4c47a504941b185037c440278425b82c52116627 from banners.getiton.com/piclist?pid=g1202053-ppc&display=gio_flash_07&grid=1x2&textsearch=一夜情性交&use_flash=1&no_fakevid=1&photo=1&banner_title=%u5728[LOC]%u7684GetItOn%u6703%u54E1%u5C0D%u7D66%u4E88%u53E3%u4EA4%u611F%u8208%u8DA3&text_color=#000000&link_col (5416 bytes, 538 hidden)
decoding_a9852b3b78be1b90c1f89b7e528f8f330003e4f2 from banners.getiton.com/piclist?pid=g1202053-ppc&display=gio_flash_07&grid=1x2&textsearch=一夜情性交&use_flash=1&no_fakevid=1&photo=1&banner_title=%u5728[LOC]%u7684GetItOn%u6703%u54E1%u5C0D%u7D66%u4E88%u53E3%u4EA4%u611F%u8208%u8DA3&text_color=#000000&link_col (203 bytes)
s10.histats.com/ benign[nothing detected] (embed) s10.histats.com/
File information (1 files) Download zip | Explanationfetch_a5d5b61aa8a61b7d9d765e1daf971a9a578f1cfa from s10.histats.com/ (2 bytes)
1.xhcuns.com/plus/ad_js.php?aid=6 benign[nothing detected] (script) 1.xhcuns.com/plus/ad_js.php?aid=6
info: [decodingLevel=0] found JavaScript
File information (1 files) Download zip | Explanationfetch_2eee4ccf9f984da8e17703857d6b1bda8ef30350 from 1.xhcuns.com/plus/ad_js.php?aid=6 (32 bytes, 3 hidden)
pstatic.xunlei.com/js/webThunderDetect.js benign[nothing detected] (script) pstatic.xunlei.com/js/webThunderDetect.js
info: [decodingLevel=0] found JavaScript
info: [decodingLevel=0] decoded 129 bytes (decoding_16dc53e97208e010cc38b885419efdbdfce63592)
info: [var vhref] URL=analytics-union.xunlei.com/PV?peerid=0&uri=http://thunderqtypv.union.xunlei.com&src=undefined
info: [decodingLevel=1] found JavaScript
File information (2 files) Download zip | Explanationfetch_252ccf7a1db20dabf716d00b36fa8a87bca20d75 from pstatic.xunlei.com/js/webThunderDetect.js (20027 bytes, 2601 hidden)
decoding_16dc53e97208e010cc38b885419efdbdfce63592 from pstatic.xunlei.com/js/webThunderDetect.js (129 bytes)