Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 52 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow Need Obfuscated Javascript samples
EH-Net
May 23, 2013, 04:53:42 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Need Obfuscated Javascript samples  (Read 4135 times)
0 Members and 1 Guest are viewing this topic.
Equix3n-
Sr. Member
****
Offline Offline

Posts: 386



View Profile
« on: September 25, 2012, 12:40:16 PM »

Hello,

It's been a long time since I last posted on EHNet. Some of you might remember me and some might not. To cut the long story short, I got selected in one of the best universities of my country for MS and currently pursuing research in IT Security.

For one of my research projects I need obfuscated javascript samples: both malicious and harmless. I was thinking if I could get samples from any of the EHNet members or if any of you could direct me to some resource where I could get the samples.

If you want to share samples, kindly message me on EHNet and I will provide you my email address.

Note: Please do not ask for my email if you have only 1-2 posts here on EHNet. I will only provide the email to members I trust or members I can trust.

Regards,
Equix3n
Logged
hayabusa
Hero Member
*****
Offline Offline

Posts: 1632



View Profile
« Reply #1 on: September 25, 2012, 12:58:49 PM »

An older example I'd posted:

http://www.ethicalhacker.net/component/option,com_smf/Itemid,54/topic,7988.msg42741/#msg42741

Hope it helps.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
hayabusa
Hero Member
*****
Offline Offline

Posts: 1632



View Profile
« Reply #2 on: September 25, 2012, 01:18:58 PM »

Also, albeit simple, you could grab pretty much anyone's javascript (non-evil) and run it through an obfuscation tool like:

http://www.javascriptobfuscator.com/

and present that as one of your samples...
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
Equix3n-
Sr. Member
****
Offline Offline

Posts: 386



View Profile
« Reply #3 on: September 25, 2012, 01:30:10 PM »

@hayabusa
Thanks. I highly appreciate it,
The thing is that I need not one or two but a few thousand samples found in the wild. Generating them individually would consume a lot of time. That's why I was asking if someone already has a database maybe they could share it.
Logged
hayabusa
Hero Member
*****
Offline Offline

Posts: 1632



View Profile
« Reply #4 on: September 25, 2012, 01:50:30 PM »

Well, your post didn't ask for a few thousand...   Tongue

I'm not sure if there's a definitive source of a few thousand examples, that anyone can point you to, offhand...   But if they can, I'd be interested to see that, too, if for not other reason than to study 'other' methods that I haven't seen.

Edit - looking for that many, might I assume your project is to try to create some sort of tool to spot them?
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
Andrew Waite
Hero Member
*****
Offline Offline

Posts: 928



View Profile WWW
« Reply #5 on: September 25, 2012, 05:53:21 PM »

If I'm wanting to quickly analyse some JS in the wild I usually turn to Wepawet. I've no affiliation with the service but it couldn't hurt to get in touch with the team there to see if they're willing/able to provide access to some of their samples?

Alternatively, some of Wepawet's reports can be accessed based on md5 hash of the content (I found this report via a quick google search for example). I've not read their Ts&Cs so use at your own risk, but a quick Google Dork of:
Quote
site:wepawet.iseclab.org intitle:report inurl:'type=js'
is currently returning >15k results

Unfortunately Wepawet's report format only lists the de-obfuscated operations rather than the original source so may not be exactly relevant to your needs, but you could always use the listed report targets to grab any scripts that are still live yourself.

Hope this helps, good luck with your project.
« Last Edit: September 25, 2012, 05:55:52 PM by Andrew Waite » Logged

Equix3n-
Sr. Member
****
Offline Offline

Posts: 386



View Profile
« Reply #6 on: September 26, 2012, 02:42:43 AM »

@Andrew
Thanks. I will ask Wepawet if they are willing to share their samples.

Alternatively, I am now trying to use heritrix web crawer to get the samples.
Logged
alan
Newbie
*
Offline Offline

Posts: 48


View Profile
« Reply #7 on: September 26, 2012, 12:14:44 PM »

Not sure if you can see recent submission on iseclab's wepawet site. Here's another one work a look, use the search feature to grab more recently checked URLs

http://urlquery.net/search.php?q=.&type=string&start=2012-09-24&end=2012-09-26&max=50

You might need to sift through some of the lower repped results to get some obsfucated javascript. And they may still be up.

Congrats, enjoy your studies!
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.067 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.