JSUNPACK
A Generic JavaScript Unpacker
CAUTION: jsunpack was designed for security researchers and computer professionals
Enter a single URL (or paste JavaScript to decode):

Upload a PDF, pcap, HTML, or JavaScript file
Private? Help: privacy | uploads
Description

Submission permanent link ebde4541a64a3a138c95c8ad8d10cd7598d189f7 (Received 2010-02-14 18:36:16, 1.xhcuns.com/a/xiaoshuolei/wuxiagudian/20100105/2902.html )

URLStatus
1.xhcuns.com/a/xiaoshuolei/wuxiagudian/20100105/2902.html saved 22166 bytes to fetch_f42c3c6d073628220ef5bf5e747783e8a207e3ab

1.xhcuns.com/plus/count.php?view=yes&aid= saved 0 bytes to fetch_da39a3ee5e6b4b0d3255bfef95601890afd80709

1.xhcuns.com/gg/zxj.htm saved 1034 bytes to fetch_4964ca167b9011b15b086837543dacfa4bcdbf1f

1.xhcuns.com/gg/900.js failure: HTTP Error 404: Not Found

1.xhcuns.com/gg/900.htm saved 194 bytes to fetch_5c4e6f50cdc05d1d90e251697880fe0a4aa8f31c

1.xhcuns.com/gg/ybhf.htm failure: HTTP Error 404: Not Found

s10.histats.com/js9.js saved 7363 bytes to fetch_345c46680f68f435e77e5b9cdd39935c97c4ee5e

pstatic.xunlei.com/js/webThunderDetect.js saved 20027 bytes to fetch_252ccf7a1db20dabf716d00b36fa8a87bca20d75

1.xhcuns.com/plus/ad_js.php?aid=3 saved 1696 bytes to fetch_65ad74eeb3b7f8256814d83a017fb601787ce278

1.xhcuns.com/plus/ad_js.php?aid=2 saved 130 bytes to fetch_2a88e0592153455d52486b3c7e22ef253e80a02e

1.xhcuns.com/js/dy.js failure: HTTP Error 404: Not Found

1.xhcuns.com/plus/ad_js.php?aid=7 saved 32 bytes to fetch_2eee4ccf9f984da8e17703857d6b1bda8ef30350

1.xhcuns.com/plus/ad_js.php?aid=6 saved 32 bytes to fetch_2eee4ccf9f984da8e17703857d6b1bda8ef30350

1.newlinkexchange.nl/link/duilian.js saved 1507 bytes to fetch_d56aada5583fd4444bc086eef942142f74b5ab1a

1.xhcuns.com/gglink/guanggao.js failure: HTTP Error 404: Not Found

1.xhcuns.com/gg/pf.js failure: HTTP Error 404: Not Found

1.xhcuns.com/gg/728d.htm failure: HTTP Error 404: Not Found

1.xhcuns.com/js/base64.js failure: HTTP Error 404: Not Found

1.xhcuns.com/gg/zxj2.htm saved 620 bytes to fetch_3be3f170c2fa843936b8744b13404e455f61ec1c

1.xhcuns.com/js/search.js saved 1092 bytes to fetch_3f592c46134e4c605a7eec3063536a3ec5b69730

1.xhcuns.com/gg/760h.js failure: HTTP Error 404: Not Found

1.xhcuns.com/js/thunderForum.js failure: HTTP Error 404: Not Found

1.xhcuns.com/gg/yb120.htm failure: HTTP Error 404: Not Found

1.xhcuns.com/gg/728db.htm failure: HTTP Error 404: Not Found

analytics-union.xunlei.com/PV?peerid=0&uri=http://thunderqtypv.union.xunlei.com&src=undefined saved 0 bytes to fetch_da39a3ee5e6b4b0d3255bfef95601890afd80709

banners.getiton.com/go/page/iframe_large_thumbs_180x179?pid=g1202053-ppc saved 9896 bytes to fetch_3e036afd756b47e1534279fadb8745244cd7b9b9

74.63.102.91/link/click.php?fromid=1 saved 3930 bytes to fetch_1ace251e7adfa9197fd763b953eefcc553903706

s10./ failure: <urlopen error (-2, 'Name or service not known')>

s10.histats.com/ saved 2 bytes to fetch_a5d5b61aa8a61b7d9d765e1daf971a9a578f1cfa

banners.getiton.com/piclist?pid=g1202053-ppc&display=gio_flash_07&grid=1x2&textsearch=一夜情性交&use_flash=1&no_fakevid=1&photo=1&banner_title=%u5728[LOC]%u7684GetItOn%u6703%u54E1%u5C0D%u7D66%u4E88%u53E3%u4EA4%u611F%u8208%u8DA3&text_color=#000000&link_col saved 5601 bytes to fetch_256cb1f5f49a27f912fc4174ca003b5a75637275

content.pop6.com/banners/getiton/english/18584_160x600.swf saved 52297 bytes to fetch_e309a144e1bf2a31cc06d1dabeff88bbfd36324f

ads.159ads.cn/ads.js saved 207 bytes to fetch_eff98f6468aabc97c40191ca401e293b2e45d89b

All Malicious or Suspicious Elements of Submission

None
1.xhcuns.com/plus/count.php?view=yes&aid= benign
[nothing detected] (script) 1.xhcuns.com/plus/count.php?view=yes&aid=

File information (1 files) Download zip | Explanation
fetch_da39a3ee5e6b4b0d3255bfef95601890afd80709 from 1.xhcuns.com/plus/count.php?view=yes&aid= (0 bytes)

1.xhcuns.com/gg/zxj.htm benign
[nothing detected] (iframe) 1.xhcuns.com/gg/zxj.htm
     info: [embed http] content.pop6.com/banners/getiton/english/18584_160x600.swf

File information (1 files) Download zip | Explanation
fetch_4964ca167b9011b15b086837543dacfa4bcdbf1f from 1.xhcuns.com/gg/zxj.htm (1034 bytes, 8 hidden)


1.xhcuns.com/gg/zxj2.htm benign
[nothing detected] (iframe) 1.xhcuns.com/gg/zxj2.htm
     info: [iframe http] banners.getiton.com/piclist?pid=g1202053-ppc&display=gio_flash_07&grid=1x2&textsearch=一夜情性交&use_flash=1&no_fakevid=1&photo=1&banner_title=%u5728%5BLOC%5D%u7684GetItOn%u6703%u54E1%u5C0D%u7D66%u4E88%u53E3%u4EA4%u611F%u8208%u8DA3&text_color=%23000000&link_color=%23114376&background_color=%23F3F3F3&border_color=%23DDDDDD&overlay_color=%234973AF&overlay_text_color=%23FFFFFF&photo_frame_color=%235A99F9&photo_frame_text_color=%23FFFFFF&thumb=portrait&iframe=1&site=getiton&models=1

File information (1 files) Download zip | Explanation
fetch_3be3f170c2fa843936b8744b13404e455f61ec1c from 1.xhcuns.com/gg/zxj2.htm (620 bytes, 11 hidden)


74.63.102.91/link/click.php?fromid=1 benign
[nothing detected] (var suspendcode14) 74.63.102.91/link/click.php?fromid=1
     info: [script http] s134.cnzz.com/stat.php?id=1246003&web_id=1246003
     info: [decodingLevel=0] found JavaScript
     info: [decodingLevel=0] decoded 6525 bytes (decoding_5980b2e0f86f577f74abebcab4604840e3b05f36)

File information (2 files) Download zip | Explanation
fetch_1ace251e7adfa9197fd763b953eefcc553903706 from 74.63.102.91/link/click.php?fromid=1 (3930 bytes, 633 hidden)

decoding_5980b2e0f86f577f74abebcab4604840e3b05f36 from 74.63.102.91/link/click.php?fromid=1 (6525 bytes)


content.pop6.com/banners/getiton/english/18584_160x600.swf benign
[nothing detected] [SWF] (embed) content.pop6.com/banners/getiton/english/18584_160x600.swf
     info: [decodingLevel=0] found JavaScript

File information (1 files) Download zip | Explanation
fetch_e309a144e1bf2a31cc06d1dabeff88bbfd36324f from content.pop6.com/banners/getiton/english/18584_160x600.swf (52297 bytes, 31501 hidden)


1.xhcuns.com/plus/ad_js.php?aid=3 benign
[nothing detected] (script) 1.xhcuns.com/plus/ad_js.php?aid=3
     info: [decodingLevel=0] found JavaScript

File information (1 files) Download zip | Explanation
fetch_65ad74eeb3b7f8256814d83a017fb601787ce278 from 1.xhcuns.com/plus/ad_js.php?aid=3 (1696 bytes, 165 hidden)


1.xhcuns.com/plus/ad_js.php?aid=2 benign
[nothing detected] (script) 1.xhcuns.com/plus/ad_js.php?aid=2
     info: [script http] ads.159ads.cn/ads.js
     info: [decodingLevel=0] found JavaScript

File information (1 files) Download zip | Explanation
fetch_2a88e0592153455d52486b3c7e22ef253e80a02e from 1.xhcuns.com/plus/ad_js.php?aid=2 (130 bytes, 3 hidden)


analytics-union.xunlei.com/PV?peerid=0&uri=http://thunderqtypv.union.xunlei.com&src=undefined benign
[nothing detected] (var vhref) analytics-union.xunlei.com/PV?peerid=0&uri=http://thunderqtypv.union.xunlei.com&src=undefined

File information (1 files) Download zip | Explanation
fetch_da39a3ee5e6b4b0d3255bfef95601890afd80709 from analytics-union.xunlei.com/PV?peerid=0&uri=http://thunderqtypv.union.xunlei.com&src=undefined (0 bytes)

1.xhcuns.com/js/search.js benign
[nothing detected] (script) 1.xhcuns.com/js/search.js
     info: [decodingLevel=0] found JavaScript
     info: [decodingLevel=0] decoded 714 bytes (decoding_6cb45ead651f5ae231a6002754f68bf94496c902)
     info: [decodingLevel=1] found JavaScript

File information (2 files) Download zip | Explanation
fetch_3f592c46134e4c605a7eec3063536a3ec5b69730 from 1.xhcuns.com/js/search.js (1092 bytes, 88 hidden)

decoding_6cb45ead651f5ae231a6002754f68bf94496c902 from 1.xhcuns.com/js/search.js (714 bytes, 70 hidden)


1.xhcuns.com/gg/900.htm benign
[nothing detected] (iframe) 1.xhcuns.com/gg/900.htm
     info: [iframe http] banners.getiton.com/go/page/iframe_large_thumbs_180x179?pid=g1202053-ppc

File information (1 files) Download zip | Explanation
fetch_5c4e6f50cdc05d1d90e251697880fe0a4aa8f31c from 1.xhcuns.com/gg/900.htm (194 bytes, 1 hidden)


s10.histats.com/js9.js benign
[nothing detected] (script) s10.histats.com/js9.js
     info: [javascript variable] URL=s10.
     info: [embed .] s10.histats.com/
     info: [script http] s
     info: [decodingLevel=0] found JavaScript

File information (1 files) Download zip | Explanation
fetch_345c46680f68f435e77e5b9cdd39935c97c4ee5e from s10.histats.com/js9.js (7363 bytes, 11 hidden)


1.newlinkexchange.nl/link/duilian.js benign
[nothing detected] (script) 1.newlinkexchange.nl/link/duilian.js
     info: [img http] qjgtjq.blu.livefilestore.com/y1pjZxeyFdBHbgloD-P6NTmb0R6iPeWlWz3AqBOAopoXEESF7ULIF47pyhuWgvEC6AJ0pVGLpROxTbSXa9KDK75ms9RFOULuR_s/left.gif
     info: [img http] qjgtjq.blu.livefilestore.com/y1pjZxeyFdBHbjIEE96WLWT7Z_Ux7d7eotm8AxUggS_2s16u0TORBt3BuUIKr16yDSmr_Gfjh1LX5SIyD-OTv6LFy6HvmwLw5NB/right.gif
     info: [decodingLevel=0] found JavaScript
     info: [decodingLevel=0] decoded 1406 bytes (decoding_f04b1c7e62bff63e1b330b274369870216144946)
     info: [var suspendcode12] URL=74.63.102.91/link/click.php?fromid=1
     info: [var suspendcode12] URL=qjgtjq.blu.livefilestore.com/y1pjZxeyFdBHbgloD-P6NTmb0R6iPeWlWz3AqBOAopoXEESF7ULIF47pyhuWgvEC6AJ0pVGLpROxTbSXa9KDK75ms9RFOULuR_s/left.gif
     info: [var suspendcode14] URL=74.63.102.91/link/click.php?fromid=1
     info: [var suspendcode14] URL=qjgtjq.blu.livefilestore.com/y1pjZxeyFdBHbjIEE96WLWT7Z_Ux7d7eotm8AxUggS_2s16u0TORBt3BuUIKr16yDSmr_Gfjh1LX5SIyD-OTv6LFy6HvmwLw5NB/right.gif
     info: [decodingLevel=1] found JavaScript

File information (2 files) Download zip | Explanation
fetch_d56aada5583fd4444bc086eef942142f74b5ab1a from 1.newlinkexchange.nl/link/duilian.js (1507 bytes, 49 hidden)

decoding_f04b1c7e62bff63e1b330b274369870216144946 from 1.newlinkexchange.nl/link/duilian.js (1406 bytes)


banners.getiton.com/go/page/iframe_large_thumbs_180x179?pid=g1202053-ppc benign
[nothing detected] (iframe) banners.getiton.com/go/page/iframe_large_thumbs_180x179?pid=g1202053-ppc
     info: [javascript variable] URL=graphics.pop6.com/images/banners/common/female_180x179/
     info: [javascript variable] URL=getiton.com/p/register.cgi?pid=g1202053-ppc
     info: [javascript variable] URL=1.xhcuns.com/gg/900.htm
     info: [img .] banners.getiton.com/go/page/
     info: [script .] banners.getiton.com/go/page/
     info: [img http] glean.pop6.com/images/common/glean.gif?rand=4957&site=getiton&session=U%5Ch%60%3EdjS3eGg+1266182445+67.217.160.100+&pwsid=&pagename=ttp%3A%2F%2F1.xhcuns.com%2Fgg%2F900.htm&pagestate=&country=United+States&city=&lang=english&level=&gpid=g1202053&pid=g1202053-ppc
     info: [decodingLevel=0] found JavaScript
     info: [decodingLevel=0] decoded 2768 bytes (decoding_ef4657581f2e60d3c47bfbd255a43c5d37005b0a)
     info: [var udImgPre] URL=graphics.pop6.com/images/banners/common/female_180x179/
     info: [var udLink] URL=getiton.com/p/register.cgi?pid=g1202053-ppc
     info: [var gaJsHost] URL=www.
     info: [img http] graphics.pop6.com/images/banners/common/female_180x179/16.jpg
     info: [img http] graphics.pop6.com/images/banners/common/female_180x179/00.jpg
     info: [img http] graphics.pop6.com/images/banners/common/female_180x179/03.jpg
     info: [img http] graphics.pop6.com/images/banners/common/female_180x179/09.jpg
     info: [img http] graphics.pop6.com/images/banners/common/female_180x179/11.jpg
     info: [script http] www.google-analytics.com/ga.js
     info: [decodingLevel=1] found JavaScript

File information (2 files) Download zip | Explanation
fetch_3e036afd756b47e1534279fadb8745244cd7b9b9 from banners.getiton.com/go/page/iframe_large_thumbs_180x179?pid=g1202053-ppc (9896 bytes, 257 hidden)

decoding_ef4657581f2e60d3c47bfbd255a43c5d37005b0a from banners.getiton.com/go/page/iframe_large_thumbs_180x179?pid=g1202053-ppc (2768 bytes)


1.xhcuns.com/a/xiaoshuolei/wuxiagudian/20100105/2902.html benign
[nothing detected] 1.xhcuns.com/a/xiaoshuolei/wuxiagudian/20100105/2902.html
     info: [script /] 1.xhcuns.com/gg/760h.js
     info: [script /] 1.xhcuns.com/plus/ad_js.php?aid=3
     info: [script /] 1.xhcuns.com/plus/ad_js.php?aid=7
     info: [script /] 1.xhcuns.com/plus/ad_js.php?aid=2
     info: [script /] 1.xhcuns.com/plus/ad_js.php?aid=6
     info: [img /] 1.xhcuns.com/images/bbs_btn.gif
     info: [iframe /] 1.xhcuns.com/gg/zxj.htm
     info: [iframe /] 1.xhcuns.com/gg/zxj2.htm
     info: [script /] 1.xhcuns.com/js/search.js
     info: [iframe /] 1.xhcuns.com/gg/728db.htm
     info: [script /] 1.xhcuns.com/js/dy.js
     info: [iframe /] 1.xhcuns.com/gg/yb120.htm
     info: [iframe /] 1.xhcuns.com/gg/ybhf.htm
     info: [iframe /] 1.xhcuns.com/gg/728d.htm
     info: [script /] 1.xhcuns.com/plus/count.php?view=yes&aid=
     info: [script http] pstatic.xunlei.com/js/webThunderDetect.js
     info: [script /] 1.xhcuns.com/js/base64.js
     info: [script /] 1.xhcuns.com/js/thunderForum.js
     info: [iframe /] 1.xhcuns.com/gg/900.htm
     info: [script /] 1.xhcuns.com/gg/900.js
     info: [script http] s10.histats.com/js9.js
     info: [img http] s4.histats.com/stats/0.gif?946652&1
     info: [script /] 1.xhcuns.com/gg/pf.js
     info: [script http] 1.xhcuns.com/gglink/guanggao.js
     info: [script http] 1.newlinkexchange.nl/link/duilian.js
     info: [decodingLevel=0] found JavaScript

File information (1 files) Download zip | Explanation
fetch_f42c3c6d073628220ef5bf5e747783e8a207e3ab from 1.xhcuns.com/a/xiaoshuolei/wuxiagudian/20100105/2902.html (22166 bytes, 6025 hidden)


1.xhcuns.com/plus/ad_js.php?aid=7 benign
[nothing detected] (script) 1.xhcuns.com/plus/ad_js.php?aid=7
     info: [decodingLevel=0] found JavaScript

File information (1 files) Download zip | Explanation
fetch_2eee4ccf9f984da8e17703857d6b1bda8ef30350 from 1.xhcuns.com/plus/ad_js.php?aid=7 (32 bytes, 3 hidden)


ads.159ads.cn/ads.js benign
[nothing detected] (script) ads.159ads.cn/ads.js
     info: [script http] ads.159ads.cn/stats.js
     info: [script http] ads.159ads.cn/468x60.js
     info: [decodingLevel=0] found JavaScript
     info: [decodingLevel=0] decoded 177 bytes (decoding_a07a814b5913cfa18ada81dd968f475bb23532b5)
     info: [decodingLevel=1] found JavaScript

File information (2 files) Download zip | Explanation
fetch_eff98f6468aabc97c40191ca401e293b2e45d89b from ads.159ads.cn/ads.js (207 bytes, 1 hidden)

decoding_a07a814b5913cfa18ada81dd968f475bb23532b5 from ads.159ads.cn/ads.js (177 bytes)


banners.getiton.com/piclist?pid=g1202053-ppc&display=gio_flash_07&grid=1x2&textsearch=一夜情性交&use_flash=1&no_fakevid=1&photo=1&banner_title=%u5728[LOC]%u7684GetItOn%u6703%u54E1%u5C0D%u7D66%u4E88%u53E3%u4EA4%u611F%u8208%u8DA3&text_color=#000000&link_col benign
[nothing detected] (iframe) banners.getiton.com/piclist?pid=g1202053-ppc&display=gio_flash_07&grid=1x2&textsearch=一夜情性交&use_flash=1&no_fakevid=1&photo=1&banner_title=%u5728[LOC]%u7684GetItOn%u6703%u54E1%u5C0D%u7D66%u4E88%u53E3%u4EA4%u611F%u8208%u8DA3&text_color=#000000&link_color=#114376&background_color=#F3F3F3&border_color=#DDDDDD&overlay_color=#4973AF&overlay_text_color=#FFFFFF&photo_frame_color=#5A99F9&photo_frame_text_color=#FFFFFF&thumb=portrait&iframe=1&site=getiton&models=1
     info: [decodingLevel=0] found JavaScript
     info: [decodingLevel=0] decoded 5416 bytes (decoding_4c47a504941b185037c440278425b82c52116627)
     info: [javascript variable] URL=content.pop6.com/images/getiton/piclist/english/piclist_gio_flash_01v.swf
     info: [javascript variable] URL=content.pop6.com/images/ffadult/flash/expressInstall.swf
     info: [script /] banners.getiton.com/javascript/getiton-rm_swfobject-1248882689.js
     info: [decodingLevel=1] found JavaScript
     info: [decodingLevel=1] decoded 203 bytes (decoding_a9852b3b78be1b90c1f89b7e528f8f330003e4f2)
     info: [var swf] URL=content.pop6.com/images/getiton/piclist/english/piclist_gio_flash_01v.swf
     info: [var installer] URL=content.pop6.com/images/ffadult/flash/expressInstall.swf
     info: [decodingLevel=2] found JavaScript

File information (3 files) Download zip | Explanation
fetch_256cb1f5f49a27f912fc4174ca003b5a75637275 from banners.getiton.com/piclist?pid=g1202053-ppc&display=gio_flash_07&grid=1x2&textsearch=一夜情性交&use_flash=1&no_fakevid=1&photo=1&banner_title=%u5728[LOC]%u7684GetItOn%u6703%u54E1%u5C0D%u7D66%u4E88%u53E3%u4EA4%u611F%u8208%u8DA3&text_color=#000000&link_col (5601 bytes, 445 hidden)

decoding_4c47a504941b185037c440278425b82c52116627 from banners.getiton.com/piclist?pid=g1202053-ppc&display=gio_flash_07&grid=1x2&textsearch=一夜情性交&use_flash=1&no_fakevid=1&photo=1&banner_title=%u5728[LOC]%u7684GetItOn%u6703%u54E1%u5C0D%u7D66%u4E88%u53E3%u4EA4%u611F%u8208%u8DA3&text_color=#000000&link_col (5416 bytes, 538 hidden)

decoding_a9852b3b78be1b90c1f89b7e528f8f330003e4f2 from banners.getiton.com/piclist?pid=g1202053-ppc&display=gio_flash_07&grid=1x2&textsearch=一夜情性交&use_flash=1&no_fakevid=1&photo=1&banner_title=%u5728[LOC]%u7684GetItOn%u6703%u54E1%u5C0D%u7D66%u4E88%u53E3%u4EA4%u611F%u8208%u8DA3&text_color=#000000&link_col (203 bytes)


s10.histats.com/ benign
[nothing detected] (embed) s10.histats.com/

File information (1 files) Download zip | Explanation
fetch_a5d5b61aa8a61b7d9d765e1daf971a9a578f1cfa from s10.histats.com/ (2 bytes)


1.xhcuns.com/plus/ad_js.php?aid=6 benign
[nothing detected] (script) 1.xhcuns.com/plus/ad_js.php?aid=6
     info: [decodingLevel=0] found JavaScript

File information (1 files) Download zip | Explanation
fetch_2eee4ccf9f984da8e17703857d6b1bda8ef30350 from 1.xhcuns.com/plus/ad_js.php?aid=6 (32 bytes, 3 hidden)


pstatic.xunlei.com/js/webThunderDetect.js benign
[nothing detected] (script) pstatic.xunlei.com/js/webThunderDetect.js
     info: [decodingLevel=0] found JavaScript
     info: [decodingLevel=0] decoded 129 bytes (decoding_16dc53e97208e010cc38b885419efdbdfce63592)
     info: [var vhref] URL=analytics-union.xunlei.com/PV?peerid=0&uri=http://thunderqtypv.union.xunlei.com&src=undefined
     info: [decodingLevel=1] found JavaScript

File information (2 files) Download zip | Explanation
fetch_252ccf7a1db20dabf716d00b36fa8a87bca20d75 from pstatic.xunlei.com/js/webThunderDetect.js (20027 bytes, 2601 hidden)

decoding_16dc53e97208e010cc38b885419efdbdfce63592 from pstatic.xunlei.com/js/webThunderDetect.js (129 bytes)