Analysis report for http://fnplbpnbvxqjrey.blogspot.com

Sample Overview

URLhttp://fnplbpnbvxqjrey.blogspot.com
MD55451b7ee7ea406a6479da71e42a2d479
Analysis Started2009-09-29 01:54:19
Report Generated2009-09-29 01:55:15
Jsand version1.03.02

See the report for domain fnplbpnbvxqjrey.blogspot.com.

Detection results

DetectorResult
Jsand 1.03.02suspicious

This resource appears to be involved in the Koobface malware campaign.

Warning:

  • The analyzed resource contains one or more syntax errors.

This may affect the detection of malicious code.

Exploits

No exploits were identified.

Deobfuscation results

Evals

Writes

Network Activity

Requests

URLStatusContent Type
http://fnplbpnbvxqjrey.blogspot.com200text/html
http://71.59.170.194/go.js?0x3E8/view/Timeoutapplication/x-empty
http://119.152.40.196/go.js?0x3E8/view/Timeoutapplication/x-empty
http://76.202.5.26/go.js?0x3E8/view/Timeoutapplication/x-empty
http://76.187.143.137/go.js?0x3E8/view/200text/javascript
http://119.152.75.243/go.js?0x3E8/view/401text/html
http://76.187.143.137/d=fnplbpnbvxqjrey.blogspot.com/0x3E8/view/200text/html
about:blank200text/html
http://76.187.143.137/d=fnplbpnbvxqjrey.blogspot.com/0x3E8/view/setup.exe200application/x-msdos-program

Redirects

No redirects.

ActiveX controls

Shellcode and Malware

No shellcode was identified.

Additional (potential) malware:

URLTypeHashAnalysis
http://76.187.143.137/d=fnplbpnbvxqjrey.blogspot.com/0x3E8/view/ N/A N/A
http://76.187.143.137/d=fnplbpnbvxqjrey.blogspot.com/0x3E8/view/setup.exe MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit 3a32fbe2b704b6ae36fbd35637b2f46e
http://pancho-2807.com/popup.php N/A N/A