本文へ移動
cccskills
無料GitHub で公開

deobfuscating-malicious-javascript

Deobfuscates malicious JavaScript from droppers, web pages, and HTA/scriptlets: unrolling string-array and char-code encodings, resolving eval/Function chains, and statically recovering payloads and URLs without executing untrusted code. Activates for requests to deobfuscate JavaScript, decode obfuscated JS, or analyze a malicious script dropper.

インストール方法を見る

含まれるファイル(4)

  • SKILL.md3.2 KB
  • LICENSE340 B
  • references/api-reference.md1.2 KB
  • scripts/analyst.py2.8 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Deobfuscating Malicious JavaScript

When to Use

  • You have obfuscated JS (from a phishing page, HTA, .js dropper, or scriptlet) and need its real behavior.
  • You must recover hidden URLs, dropped commands, or a next-stage payload.
  • You want to statically unroll common obfuscation rather than run untrusted code.

Do not use a real browser or node to execute the script for analysis — that runs the malware. Use a sandboxed interpreter (box-js) or static transformation only.

Prerequisites

  • A safe analysis approach: static decoding, or a JS malware sandbox (box-js) in the lab.
  • Familiarity with common obfuscation: string arrays, String.fromCharCode, hex/unicode escapes, eval/Function chains, packers.

Safety & Handling

  • Treat the script as live code; never execute it outside an isolated sandbox.
  • Defang recovered URLs and store dropped payloads password-protected.

Workflow

Step 1: Normalize and de-pack

Pretty-print the source and identify the obfuscation style (array-shuffle, eval-packer, charcode). Decode static encodings first: hex/unicode escapes and base64 literals.

python scripts/analyst.py decode dropper.js

Step 2: Unroll string arrays and char-code builds

Reconstruct strings built from arrays/fromCharCode/concatenation to reveal API names, URLs, and commands.

Step 3: Resolve eval/Function indirection — safely

Replace eval/new Function with logging (or a sandbox) so the constructed code is captured as data, not executed, then recurse on the recovered layer.

Step 4: Extract behavior and IOCs

Identify the dropper actions (WScript.Shell, ActiveX, fetch/XHR), recover URLs and dropped paths, defang, and route payloads onward.

Validation

  • Static encodings (hex/unicode/base64) are fully decoded.
  • String-array/charcode constructions are unrolled to readable strings.
  • eval/Function layers are captured as data and recursed, with no untrusted execution.

Pitfalls

  • Running the script to "see what it does" and infecting the analysis host.
  • Stopping at one layer when the dropper nests several.
  • Missing environment-keyed branches (only acts on certain dates/locales) during static review.

References

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Reverses Android malware: unpacking APKs, decompiling DEX bytecode to readable Java, auditing the manifest for abused permissions and components, and locating dynamically loaded or native payloads. Activates for requests to analyze an APK, decompile DEX, or investigate a suspicious Android app.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes API call traces from a sandbox or API monitor (JSON) to group calls by category, reconstruct high-level behaviors (process injection, file drops, network, crypto), and flag suspicious call sequences. Activates for requests to analyze an API trace, interpret sandbox API logs, or identify behavior from Win32/Native API calls.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Windows Authenticode signatures on PE files: checking for a signature, reading the signer certificate chain, detecting revoked/expired/stolen certs, and recognizing signature-stripping and catalog-signing abuse. Activates for requests to analyze a code signature, verify Authenticode, or assess signer trust on a PE.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes banking trojan webinject configurations to extract targeted institutions, injected JavaScript/HTML, and data-theft hooks, mapping the fraud workflow. Activates for requests to analyze banking trojan webinjects, parse a webinject config, or map targeted banks and credential-theft injections.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Python-based malware packaged as PyInstaller/py2exe executables by detecting the packer, locating the embedded archive, and identifying bundled .pyc modules for extraction and decompilation. Activates for requests to analyze compiled Python malware, unpack a PyInstaller binary, or extract pyc modules from a frozen Python executable.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes cryptojacking/coinminer malware by extracting mining pool endpoints (stratum), wallet addresses, algorithm and miner identifiers (XMRig and forks), and persistence or resource-control settings from static strings and config. Activates for requests to analyze a cryptominer, extract mining pool and wallet IOCs, or identify coinminer configuration.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

meltedinhex のスキルをすべて見る

このスキルの問題を報告する