Analysis report for 2e4c94f60034133195a3c64b544fc1a3.swf

WARNING: This SWF files makes use of the built in _url variable. This allows the SWF file to grab the URL that it is ran from. This makes it possible for this SWF file to change its behavior depending on where its ran from.
NOTE: This SWF file executed 48 ActionScript actions.
  1. Summary [?]
    1. Result: MALICIOUS
      • Runtime URL aware.
      • Automatically Redirects Browser.

  2. Details
  3. Hash: 2e4c94f60034133195a3c64b544fc1a3
    Submitted On: 2010-02-08 05:38:05
    Processing Start: 2010-02-08 05:38:08
    Processing End: 2010-02-08 05:41:14
    SWF Version: 8

    Virustotal Report (malicious)

  4. Network Activity
  5. Method/ActionDetails
    ActionGetUrl2http://wepawet.cs.ucsb.edu/?go, _top

  6. Call Counts
    1. Actions
      1. ActionPushData17
        ActionGetVariable4
        ActionGetMember3
        ActionPop3
        ActionSetRegister2
        ActionCallMethod2
        ActionConstantPool2
        LogicalNot2
        ActionCallFunction2
        ActionNewAdd2
        ActionDefineFunction22
        ActionBranchIfTrue1
        Stop1
        ActionSetMember1
        ActionNew1
        ActionGetUrl21
        ActionVar1
        ActionSetVariable1

    2. Methods
      1. [string:lastIndexOf]1
        [string:substr]1