Analysis report for http://captjomarjomar.blogspot.com/
Sample Overview
| URL | http://captjomarjomar.blogspot.com/ |
|---|---|
| MD5 | 83f6fe88cd7a439c5ed1171381c11bc6 |
| Analysis Started | 2010-02-02 01:44:05 |
| Report Generated | 2010-02-02 01:44:55 |
| Jsand version | 1.03.02 |
See the report for domain captjomarjomar.blogspot.com.
Detection results
| Detector | Result |
|---|---|
| Jsand 1.03.02 | suspicious |
This resource appears to be involved in the Koobface malware campaign.
Exploits
No exploits were identified.Deobfuscation results
Evals
- (repeated 2 times)
document.referrer
- (repeated 2 times)
window.redirect
- (repeated 1 time)
location.href
- (repeated 1 time)
location.search
- (repeated 1 time)
window.location.href = window.redirect;
- (repeated 1 time)
window.attachEvent('onunload', exiter);
Writes
- (repeated 1 time)
<OBJECT id="iie" width="0" height="0" style="position:absolute; left:0;top:0;" CLASSID= "CLSID:6BF52A52-394A-11d3-B153-00C04F79FAA6" type="application/x-oleobject"> <PARAM NAME= "SendPlayStateChangeEvents" VALUE="True"> <PARAM NAME="AutoStart" VALUE="True"> <PARAM name="uiMode" value="none"> <PARAM name="PlayCount" value="9999"></OBJECT>
Network Activity
Requests
| URL | Status | Content Type |
|---|---|---|
| http://captjomarjomar.blogspot.com/ | 200 | text/html |
| http://www.fastpitchequipment.com/index.htm/?go | 200 | text/javascript |
| http://24.183.202.80/go.js?0x3E8/view/console=yes/?go | 200 | text/javascript |
| http://84.109.115.225/go.js?0x3E8/view/console=yes/?go | 200 | text/javascript |
| http://87.69.137.120/go.js?0x3E8/view/console=yes/?go | 200 | text/javascript |
| http://76.29.107.169/go.js?0x3E8/view/console=yes/?go | 200 | text/javascript |
| http://69.141.160.61/go.js?0x3E8/view/console=yes/?go | 200 | text/javascript |
| http://87.69.154.105/go.js?0x3E8/view/console=yes/?go | 200 | text/javascript |
| http://71.199.216.160/go.js?0x3E8/view/console=yes/?go | 200 | text/javascript |
| http://174.101.95.243/go.js?0x3E8/view/console=yes/?go | 200 | text/javascript |
| http://206.59.71.243/go.js?0x3E8/view/console=yes/?go | 200 | text/javascript |
| http://96.231.223.38/go.js?0x3E8/view/console=yes/?go | 200 | text/javascript |
| http://89.138.9.59/go.js?0x3E8/view/console=yes/?go | 200 | text/javascript |
| http://76.85.186.214/go.js?0x3E8/view/console=yes/?go | 200 | text/javascript |
| http://84.108.144.103/go.js?0x3E8/view/console=yes/?go | 200 | text/javascript |
| http://74.254.157.183/go.js?0x3E8/view/console=yes/?go | 200 | text/javascript |
| http://77.127.143.202/go.js?0x3E8/view/console=yes/?go | 200 | text/javascript |
| http://89.138.152.206/go.js?0x3E8/view/console=yes/?go | 200 | text/javascript |
| http://24.231.53.47/go.js?0x3E8/view/console=yes/?go | 200 | text/javascript |
| http://115.240.63.60/go.js?0x3E8/view/console=yes/?go | 200 | text/javascript |
| http://76.249.24.112/go.js?0x3E8/view/console=yes/?go | 200 | text/javascript |
| http://76.114.131.147/go.js?0x3E8/view/console=yes/?go | 200 | text/javascript |
| about:blank | 200 | text/html |
| http://76.114.131.147/d=www.fastpitchequipment.com/0x3E8/view/console=yes/?go | 200 | text/html |
| http://76.114.131.147/d=www.fastpitchequipment.com/0x3E8/view/console=yes/player.swf?pid=6123 | 200 | application/x-shockwave-flash |
Redirects
No redirects.ActiveX controls
-
6BF52A52-394A-11D3-B153-00C04F79FAA6 Name Arg0 Count Methods launchURL http://bmwmodeltoys.com/?pid=312s02&sid=4db12f
1 http://76.114.131.147/d=www.fastpitchequipment.com/0x3E8/view/console=yes/?go
1 Name Value Count Attributes PlayCount 9999
1 uiMode none
1 AutoStart True
1 SendPlayStateChangeEvents True
1 -
D27CDB6E-AE6D-11CF-96B8-444553540000 Name Value Count Attributes bgcolor #000000
1 movie player.swf?pid=6123
1 allowScriptAccess sameDomain
1 allowFullScreen false
1 menu false
1 quality high
1
Shellcode and Malware
No shellcode was identified.
Additional (potential) malware:
| URL | Type | Hash | Analysis |
|---|---|---|---|
| http://76.114.131.147/d=www.fastpitchequipment.com/0x3E8/view/console=yes/?go | N/A | N/A |
|
| http://bmwmodeltoys.com/?pid=312s02&sid=4db12f | N/A | N/A |
|