Solved

What's <script language=3D"JScript.Encode"> ?

Posted on 2004-09-25
5
1,142 Views
Last Modified: 2008-01-09
Hi,

I have encountered a particular spammer's email today (among thousands...), which ends with an encoded script:

<script language=3D"JScript.Encode">#@~^owAAAA=3D=3D~@#@&[Km!:+      YcADbYn`E@=
!(o"bHA~?"Z'r4OYa)JzdtC.=7FNRtKdYbxL (ky&sbxVR4OsVE,=7F&fK_'W*!,C3qVCPxWc!=
,oIzH2~6]fAI{!~?/]}SJqg!'rxGE,/Yzs=7F'ENbdaVCH)      Wx=7Fir@*@!JqoIzH3@*E#i@#@=
&EC8AAA=3D=3D^#~@</script>

I have seen MS Jscript encoding <script language="JScript.Encode"> many times, but never <script language=3D"JScript.Encode">.  I couldn't decode the script using scrdec15.exe or zwdecode.exe; thus won't risk running the codes.  Could anyone enlighten me with what kind of encoding scheme this is and how could I decode it please?

Thanks.
0
Comment
Question by:iuhh
  • 3
  • 2
5 Comments
 
LVL 51

Accepted Solution

by:
ahoffmann earned 50 total points
ID: 12154006
sounds like the sender or your MUA used M$ strange character encoding 'cause of the =3D, =7F
replace these by their original charater, also remove the line endings =
0
 
LVL 2

Author Comment

by:iuhh
ID: 12154486
Many thanks ahoffmann, that makes perfect sense.  But as I replaced all '=3D' to '=', and removed '=7F' along with the character immediately follows (as I understand, 7F is delete), I am still unable to decode this script fully - Incorrect checksum error from scrdec15.  With zwdecode, I am just able to make out 'document.write', 'http://' and 'html' from the gibberish, so I'm guessing, it'll download an evil script from somewhere else and will save it to harddisk, possibly then execute the script.  

I really want to get the bottom of this.  Anything else I can do to straight this encoded text up? Thanks.
0
 
LVL 51

Expert Comment

by:ahoffmann
ID: 12156072
}   =7F  
?
0
 
LVL 2

Author Comment

by:iuhh
ID: 12164256
Thanks ahoffmann.  I've tried replacing =7F with ' ', '', '?', '}' but still can't decode the script.  What exactly does 'DEL' map to?

Cheers.
0
 
LVL 51

Expert Comment

by:ahoffmann
ID: 12168089
sorry, I'm no M$ guru, you need to check your docs (they should be perfect, telling you all you need, I was told once ...)
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

Password hashing is better than message digests or encryption, and you should be using it instead of message digests or encryption.  Find out why and how in this article, which supplements the original article on PHP Client Registration, Login, Logo…
It’s a strangely common occurrence that when you send someone their login details for a system, they can’t get in. This article will help you understand why it happens, and what you can do about it.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now