Analysis report for 44db623d8f7361980cc476d41100c769.swf

WARNING: This SWF files makes use of the built in _url variable. This allows the SWF file to grab the URL that it is ran from. This makes it possible for this SWF file to change its behavior depending on where its ran from.
NOTE: This SWF file executed 46 ActionScript actions.
  1. Summary [?]
    1. Result: MALICIOUS
      • Runtime URL aware.
      • Automatically Redirects Browser.

  2. Details
  3. Hash: 44db623d8f7361980cc476d41100c769
    Submitted On: 2009-11-05 06:54:46
    Processing Start: 2009-11-05 06:54:48
    Processing End: 2009-11-05 06:57:50
    SWF Version: 8

    Virustotal Report (clean)

  4. Network Activity
  5. Method/ActionDetails
    ActionGetUrl2http://wepawet.cs.ucsb.edu/?go, _self

  6. Call Counts
    1. Actions
      1. ActionPushData16
        ActionGetVariable4
        ActionGetMember3
        ActionPop3
        ActionSetRegister2
        ActionCallMethod2
        ActionConstantPool2
        LogicalNot2
        ActionCallFunction2
        ActionDefineFunction22
        ActionBranchIfTrue1
        Stop1
        ActionSetMember1
        ActionNew1
        ActionNewAdd1
        ActionGetUrl21
        ActionVar1
        ActionSetVariable1

    2. Methods
      1. [string:lastIndexOf]1
        [string:substr]1