Analysis report for 02b3c6a39de2b21d3399e3de18defee9.swf
WARNING: This SWF files makes use of the built in _url variable. This allows the SWF file to grab the URL that it is ran from. This makes it possible for this SWF file to change its behavior depending on where its ran from.
WARNING: This SWF file checks the timezone that it was ran in. This makes it possible for this SWF file to change its behavior depending on the timezone it was ran in.
NOTE: This SWF file executed 112294 ActionScript actions.
- Summary [?]
- Runtime URL aware.
- Detected URLs are associated with malware.
- Obfuscation Detected.
- Timezone aware.
- Date aware.
- DetailsHash: 02b3c6a39de2b21d3399e3de18defee9
- Network Activity
- Shared Objects
- cHJhbmRpYWxubw%3D%3D.sol
- Referenced Urls [?]
http://waytotheprofit.com/?cmpid=prandialno
Discovery Method: Runtime Extra: Jsand (benign) Domain Associated with Malware! http://newstat.net/c/index.php?id=NFNOQ3lMcU5Ra0xaclVnazhrMkJoPTEyMDY3MTgxMDAmcG
56Y252dGE9Y2VuYXF2bnlhYgYNkiDgNmYNkiDgNmDiscovery Method: Runtime - Obfuscation Techniques
- Invalid tags
- Tag Type 521 at file byte offset 21
- Tag Type 253 at file byte offset 34585
- Tag Type 253 at file byte offset 36777
- Tag Type 253 at file byte offset 38769
- Out Of Bound Jumps
- From 0x000095c6 to 0x0000676f, Src Tag Boundary 0x0000937a - 0x00009763
- From 0x00008a30 to 0x00008835, Src Tag Boundary 0x0000883a - 0x00008f77
- From 0x0000ade0 to 0x00012d86, Src Tag Boundary 0x0000a7be - 0x0000b11d
- From 0x00009720 to 0x00009375, Src Tag Boundary 0x0000937a - 0x00009763
- From 0x000089f9 to 0x00001762, Src Tag Boundary 0x0000883a - 0x00008f77
- From 0x00008e41 to 0x000047c8, Src Tag Boundary 0x0000883a - 0x00008f77
- From 0x0000891c to 0x00002a37, Src Tag Boundary 0x0000883a - 0x00008f77
- From 0x0000afea to 0x00007ea5, Src Tag Boundary 0x0000a7be - 0x0000b11d
- From 0x0000b0da to 0x0000a7b9, Src Tag Boundary 0x0000a7be - 0x0000b11d
- From 0x00008f35 to 0x00007ab9, Src Tag Boundary 0x0000883a - 0x00008f77
- Objects
- Date
- <NOW>
- 2008-03-29
- Call Counts
- Actions
- Methods
- Result: MALICIOUS
Submitted On: 2008-10-30 17:32:05
Processing Start: 2009-03-12 16:29:11
Processing End: 2009-03-12 16:32:29
SWF Version: 6
Virustotal Report (clean)
| Method/Action | Details | ||
| LoadVars.load |
|
| ActionPushData | 36419 |
| ActionGetVariable | 21234 |
| ActionNewAdd | 18749 |
| ActionPop | 5373 |
| ActionSetRegister | 5364 |
| ActionCallMethod | 3909 |
| LogicalNot | 3200 |
| ActionBranchIfTrue | 3199 |
| ActionGetMember | 1503 |
| ActionBranchAlways | 1476 |
| ActionSetVariable | 1462 |
| ActionNewLessThan | 1413 |
| Multiply | 1230 |
| ActionModulo | 1227 |
| ActionShiftRight | 1224 |
| ActionGreater | 1224 |
| ActionBitwiseAnd | 1224 |
| ActionBitwiseXor | 1224 |
| ActionVarEquals | 587 |
| Equal | 522 |
| ActionReturn | 190 |
| ActionVar | 186 |
| ActionSetMember | 33 |
| ActionNewEquals | 28 |
| Add | 27 |
| Subtract | 26 |
| ActionDup | 16 |
| ActionDefineFunction | 5 |
| ActionConstantPool | 5 |
| ActionNewMethod | 5 |
| ActionCallFunction | 4 |
| ActionDefineFunction2 | 2 |
| Divide | 1 |
| ActionDecrement | 1 |
| ActionEnum2 | 1 |
| Stop | 1 |
| [string:parseInt] | 1235 |
| [string:slice] | 1224 |
| [string:fromCharCode] | 1224 |
| [number:1] | 186 |
| [string:substr] | 10 |
| [string:join] | 9 |
| [string:split] | 9 |
| [string:getTime] | 2 |
| [string:random] | 2 |
| [string:floor] | 2 |
| [string:getLocal] | 1 |
| [string:flush] | 1 |
| [string:load] | 1 |
| [string:getTimezoneOffset] | 1 |
| [string:main] | 1 |
| [string:allowDomain] | 1 |