Hi dudes,
You could find a new paper describing the design of Wepawet. One of my research mate, Daniel, asked the first author about the deobfuscation part. He said "We do some analysis to recover the clear text of the code. For example, we save the parameters passed to eval and document.write, which is often sufficient to deobfuscate the code. However, we don't currently handle more sophisticated obfuscation techniques (e.g., replace-based ones).". It may be the reason why it may not detect the crimeware.
Detection and Analysis of Drive-by-Download Attacks and Malicious JavaScript Code
Abstract:
