Solved

What's <script language=3D"JScript.Encode"> ?

Posted on 2004-09-25
5
1,163 Views
Last Modified: 2008-01-09
Hi,

I have encountered a particular spammer's email today (among thousands...), which ends with an encoded script:

<script language=3D"JScript.Encode">#@~^owAAAA=3D=3D~@#@&[Km!:+      YcADbYn`E@=
!(o"bHA~?"Z'r4OYa)JzdtC.=7FNRtKdYbxL (ky&sbxVR4OsVE,=7F&fK_'W*!,C3qVCPxWc!=
,oIzH2~6]fAI{!~?/]}SJqg!'rxGE,/Yzs=7F'ENbdaVCH)      Wx=7Fir@*@!JqoIzH3@*E#i@#@=
&EC8AAA=3D=3D^#~@</script>

I have seen MS Jscript encoding <script language="JScript.Encode"> many times, but never <script language=3D"JScript.Encode">.  I couldn't decode the script using scrdec15.exe or zwdecode.exe; thus won't risk running the codes.  Could anyone enlighten me with what kind of encoding scheme this is and how could I decode it please?

Thanks.
0
Comment
Question by:iuhh
  • 3
  • 2
5 Comments
 
LVL 51

Accepted Solution

by:
ahoffmann earned 50 total points
ID: 12154006
sounds like the sender or your MUA used M$ strange character encoding 'cause of the =3D, =7F
replace these by their original charater, also remove the line endings =
0
 
LVL 2

Author Comment

by:iuhh
ID: 12154486
Many thanks ahoffmann, that makes perfect sense.  But as I replaced all '=3D' to '=', and removed '=7F' along with the character immediately follows (as I understand, 7F is delete), I am still unable to decode this script fully - Incorrect checksum error from scrdec15.  With zwdecode, I am just able to make out 'document.write', 'http://' and 'html' from the gibberish, so I'm guessing, it'll download an evil script from somewhere else and will save it to harddisk, possibly then execute the script.  

I really want to get the bottom of this.  Anything else I can do to straight this encoded text up? Thanks.
0
 
LVL 51

Expert Comment

by:ahoffmann
ID: 12156072
}   =7F  
?
0
 
LVL 2

Author Comment

by:iuhh
ID: 12164256
Thanks ahoffmann.  I've tried replacing =7F with ' ', '', '?', '}' but still can't decode the script.  What exactly does 'DEL' map to?

Cheers.
0
 
LVL 51

Expert Comment

by:ahoffmann
ID: 12168089
sorry, I'm no M$ guru, you need to check your docs (they should be perfect, telling you all you need, I was told once ...)
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Enterprise Password Manager Suites as well as Local Password managers are covered in this article.
On Beyond Tools A conversation I recently had with the DevOps manager of a major online retailer really made me think about DevOps monitoring tools (https://www.onpage.com/devops-incident-management-tool/). The manager and I discussed how sever…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

832 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question