Analysis report for 2e4c94f60034133195a3c64b544fc1a3.swf
WARNING: This SWF files makes use of the built in _url variable. This allows the SWF file to grab the URL that it is ran from. This makes it possible for this SWF file to change its behavior depending on where its ran from.
NOTE: This SWF file executed 48 ActionScript actions.
- Summary [?]
- Runtime URL aware.
- Automatically Redirects Browser.
- DetailsHash: 2e4c94f60034133195a3c64b544fc1a3
- Network Activity
- Call Counts
- Actions
- Methods
- Result: MALICIOUS
Submitted On: 2010-02-08 05:38:05
Processing Start: 2010-02-08 05:38:08
Processing End: 2010-02-08 05:41:14
SWF Version: 8
Virustotal Report (malicious)
| Method/Action | Details |
| ActionGetUrl2 | http://wepawet.cs.ucsb.edu/?go, _top |
| ActionPushData | 17 |
| ActionGetVariable | 4 |
| ActionGetMember | 3 |
| ActionPop | 3 |
| ActionSetRegister | 2 |
| ActionCallMethod | 2 |
| ActionConstantPool | 2 |
| LogicalNot | 2 |
| ActionCallFunction | 2 |
| ActionNewAdd | 2 |
| ActionDefineFunction2 | 2 |
| ActionBranchIfTrue | 1 |
| Stop | 1 |
| ActionSetMember | 1 |
| ActionNew | 1 |
| ActionGetUrl2 | 1 |
| ActionVar | 1 |
| ActionSetVariable | 1 |
| [string:lastIndexOf] | 1 |
| [string:substr] | 1 |