{"repo":"CapacitorSet/box-js","free":true,"listed":false,"github":"https://github.com/CapacitorSet/box-js","clone":"git clone https://github.com/CapacitorSet/box-js.git","description":"A tool for studying JavaScript malware.","language":"JavaScript","stars":672,"topics":["malware","malwareanalysis","nodejs","es6","javascript","es6-proxies"],"license":"MIT","category":"dev-tools","readme_excerpt":"box.js ====== A utility to analyze malicious JavaScript. Installation Simply install box-js from npm: box-js is also available: - as a Cuckoo module (see the integrations directory and Nwinternights/Cuckoo Boxjs); - as a Dockerfile (see integrations/README.md ); - as a package in distros for security professionals (REMnux, BlackArch); - as part of open source applications (Intel Owl); - as part of commercial third-party services (any.run). Usage Let's say you have a sample called sample.js : to analyze it, simply run Chances are you will also want to download any payloads; use the flag --download to enable downloading. Otherwise, the engine will simulate a 404 error, so that the script will be tricked into thinking the distribution site is down and contacting any fallback sites. Box.js will emulate a Windows JScript environment, print a summary of the emulation to the console, and create a folder called sample.js.results (if it already exists, it will create sample.js.1.results and so on). This folder will contain: analysis.log , a log of the analysis as it was printed on screen; a series of files identified by UUIDs; snippets.json , a list of pieces of code executed by the sample (JavaScript, shell commands, etc.); urls.json , a list of URLs contacted; active urls.json , a list of URLs that seem to drop active malware; resources.json , the ADODB streams (i.e. the files that the script wrote to disk) with file types and hashes; IOC.json , a list of behaviours identified as IO","default_branch":null,"files":null,"tree":[],"storefront":"/r/CapacitorSet","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/CapacitorSet/box-js/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}