Running Puppy Linux with Chromium, so of course I clicked on it, got the source, and downloaded the referenced Javascript file from nickletto.com.
Just for fun, I gave the .JS file to
Virustotal.com to look at.
Copied most of the results here:
Ad-Aware - JS:Adware.Lnkr.E
AegisLab - Adware.Script.Generic.2!c
Arcabit - JS:Adware.Lnkr.E
Avast - Script:SNH-gen [Adw]
AVG - Script:SNH-gen [Adw]
BitDefender - JS:Adware.Lnkr.E
Comodo - Application.JS.AdWare.Revizer.E@8bp9s7
Cyren - JS/Revizer.A
DrWeb - JS.Siggen5.40409
Emsisoft - JS:Adware.Lnkr.E (B)
eScan - JS:Adware.Lnkr.E
FireEye - JS:Adware.Lnkr.E
GData - Script.Adware.Injector.OC
Kaspersky - Not-a-virus:HEUR:AdWare.Script.Generic
MAX - Malware (ai Score=64)
NANO-Antivirus - Trojan.Script.Adware.iestfp
Rising - Adware.Lnkr/JS!1.D2D0 (CLASSIC)
ZoneAlarm by Check Point - Not-a-virus:HEUR:AdWare.Script.Generic
-------------------------------------
When executing the file being studied, it performed the following actions on the registry of the sandbox environment.
Registry Actions
Registry Keys Set
HKLM\Software\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading
1
HKLM\Software\Microsoft\WBEM\CIMOM\List of event-active namespaces
00 00 54 00 45 00 76 00 65 00 6E 00 74 00 4C 00 6F 00 67 00 45 00 76 00 65 00 6E 00 74 00 43 00 6F 00 6E 00 73 00 75 00 6D 00 65 00 72 00
\\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Time Zones\Greenland Standard Time\TZI
HKLM\SYSTEM\ControlSet001\Control\TimeZoneInformation\ActiveTimeBias
4294967176
\\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Time Zones\Iran Standard Time\TZI
HKLM\SYSTEM\ControlSet001\Control\BackupRestore\FilesNotToBackup\BITS_LOG
%windir%\System32\Bits.log
HKLM\SYSTEM\ControlSet001\Control\BackupRestore\FilesNotToBackup\BITS_BAK
%windir%\System32\Bits.bak
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\StateIndex
1
HKLM\SOFTWARE\Microsoft\WBEM\PROVIDERS\Performance\Performance Refresh
0
HKLM\SOFTWARE\Microsoft\WBEM\PROVIDERS\Performance\Performance Refreshed
1
HKLM\SOFTWARE\Microsoft\WBEM\PROVIDERS\Performance\Performance Data
28 1B 00 00 01 00 00 00 00 00 00 00 10 00 00 00 18 1B 00 00 09 00 00 00 9A 00 00 00 01 00 00 00 01 00 00 00 40 00 00 00 1A 00 00 00 5C 00 5C 00 2E 00 5C 00 72 00 6F 00 6F 00 74 00 5C 00 77 00 6D 00 69 00 00 00 00 00 00 00 00 00 00 00 00 00 C0 01 00 00 04 00 00 00 08 00 00 00 01 00 00 00 00 00 00 00 01 00 00 00 64 00 00 00 68 00 00 00 3A 00 00 00 4D 00 53 00 69 00 53 00 43 00 53 00 49 00 5F 00 43 00 6F 00 6E 00 6E 00 65 00 63 00 74 00 69 00 6F 00 6E 00 53 00 74 00 61 00 74 00 69 00 73 00 74 00 69 00 63 00 73 00 00 00 00 00 00 00 00 00 00 00 00 00 30 00 00 00 1A 00 00 00 49 00 6E 00 73 00 74 00 61 00 6E 00 63 00 65 00 4E 00 61 00 6D 00 65 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 48 00 00 00 00 00 00 00 02 00 00 00 15 00 00 00 00 00 00 00 64 00 00 00 00 05 41 10 48 00 00 00 1C 00 00 00 42 00 79 00 74 00 65 00 73 00 52 00 65 00 63 00 65 00 69 00 76 00 65 00 64 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 04 00 00 00 15 00 00 00 00 00 00 00 64 00 00 00 00 05 41 10 40 00 00 00 14 00 00 00 42 0
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\Last Counter
12642
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\Last Help
12643
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\Updating
\\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Time Zones\Paraguay Standard Time\TZI
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\drivers\ndis.sys[MofResourceName]
LowDateTime:-1971493113,HighDateTime:30676308***Binary mof failed, see WMIPROV.LOG
HKLM\Software\Microsoft\WBEM\WDM\%windir%\System32\Drivers\portcls.SYS[PortclsMof]
LowDateTime:-1221632304,HighDateTime:30487028***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\drivers\en-US\ACPI.sys.mui[ACPIMOFResource]
LowDateTime:-403062016,HighDateTime:30016570***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\DRIVERS\HDAudBus.sys[HDAudioMofName]
LowDateTime:-1867536076,HighDateTime:30116016***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\%windir%\System32\Drivers\en-US\portcls.SYS.mui[PortclsMof]
LowDateTime:-503062016,HighDateTime:30016570***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\advapi32.dll[MofResourceName]
LowDateTime:-1337772912,HighDateTime:30778796***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\en-US\advapi32.dll.mui[MofResourceName]
LowDateTime:-1270310445,HighDateTime:30778796***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\drivers\en-US\mssmbios.sys.mui[MofResource]
LowDateTime:-143062016,HighDateTime:30016570***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\DRIVERS\en-US\HDAudBus.sys.mui[HDAudioMofName]
LowDateTime:-2018029312,HighDateTime:30016571***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\drivers\en-US\ndis.sys.mui[MofResourceName]
LowDateTime:-1258029312,HighDateTime:30016571***Binary mof failed, see WMIPROV.LOG
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\DRIVERS\en-US\intelppm.sys.mui[PROCESSORWMI]
LowDateTime:2076937984,HighDateTime:30016571***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\IDE\DiskAMDX_HARDDISK___________________________2.5+____\5&2770a7af&0&0.0.0_0-{05901221-D566-11d1-B2F0-00A0C9062910}
LowDateTime:803713417,HighDateTime:0***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\DRIVERS\intelppm.sys[PROCESSORWMI]
LowDateTime:-2085707242,HighDateTime:30778791***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\drivers\ACPI.sys[ACPIMOFResource]
LowDateTime:-1241494372,HighDateTime:30646958***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\DRIVERS\monitor.sys[MonitorWMI]
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\drivers\mssmbios.sys[MofResource]
LowDateTime:2004871927,HighDateTime:30733930***Binary mof compiled successfully
HKLM\SYSTEM\ControlSet001\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc}\22\(Default)
HKLM\SYSTEM\ControlSet001\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc}\24\ffffffffffffffffffffffffffffff00
00 00 00 00 00 00 00 00 00 00 00 00 FF FF FF FF FF FF FF FF FF FF FF FF
HKLM\SYSTEM\ControlSet001\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc}\24\ffffffffffffffffffffffffffffff01
00 00 00 00 77 00 00 00 19 00 00 00 FF FF FF FF FF FF FF FF FF FF FF FF
HKLM\SYSTEM\ControlSet001\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc}\24\ffffffffffffffffffffffffffffff02
01 00 00 00 5A 00 00 00 D6 17 00 00 FF FF FF FF FF FF FF FF FF FF FF FF
HKLM\SYSTEM\ControlSet001\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc}\24\ffffffffffffffffffffffffffffff03
00 00 00 00 00 00 00 00 00 00 00 00 FF FF FF FF FF FF FF FF FF FF FF FF
HKLM\SYSTEM\ControlSet001\Services\BITS\Performance\PerfMMFileName
Global\MMF_BITS_s
\\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Time Zones\Middle East Standard Time\TZI
Registry Keys Deleted
HKLM\SYSTEM\ControlSet001\Services\WmiApRpl\Performance\First Counter
HKLM\SYSTEM\ControlSet001\Services\WmiApRpl\Performance\Last Counter
HKLM\SYSTEM\ControlSet001\Services\WmiApRpl\Performance\First Help
HKLM\SYSTEM\ControlSet001\Services\WmiApRpl\Performance\Last Help
HKLM\SYSTEM\ControlSet001\Services\WmiApRpl\Performance\Object List
Process And Service Actions
Processes Terminated
wmiadap.exe /F /T /R
Processes Tree
2992 - wmiadap.exe /F /T /R
2676 - wscript.exe %SAMPLEPATH%
3040 - %windir%\system32\wbem\wmiprvse.exe