adskip.v1.0.429.9902.exe

The application adskip.v1.0.429.9902.exe, “ADSkip 32 Bit Application” has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from dl.adskiper.com.
Description:
ADSkip 32 Bit Application

Version:
1.0.429.9902

MD5:
ebcf7cbe7a135858c087e7e58b327ad9

SHA-1:
48f0c2d07a384e355ea56da9c070dd67e3f080bd

SHA-256:
be39292650b535f37a3dd84127d54d6a3c33afc476e1d0e87c35b09556c29381

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 9:41:05 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.AdSkip (M)
16.8.3.20

File size:
10 MB (10,457,088 bytes)

Product version:
1.0.429.9902

File type:
Executable application (Win32 EXE)

Language:
Chinese (Simplified, PRC)

Common path:
C:\users\{user}\downloads\adskip.v1.0.429.9902.exe

File PE Metadata
Compilation timestamp:
2/27/1996 9:57:06 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
196608:B0H4KeeeL92bSTDuD+/CosnhYx8Mbk1jclxxYzhsB:uHQ7HTDuy/n2hYx3gcfPB

Entry address:
0xA01052

Entry point:
8B, E4, 8A, DB, 83, 3C, 24, FE, 77, FE, F5, 83, E9, 00, 8D, 64, 24, CC, 60, 83, EC, DC, E8, FC, 01, 00, 00, 4B, 66, 4B, 75, FC, 47, 48, FE, CC, F6, D0, 81, E2, 08, 6D, 1A, 42, FF, 73, 3C, 40, 59, 81, E9, FD, FF, FF, 7F, 73, E2, F6, D2, FC, 90, 81, D9, E6, 13, 00, 00, 71, D6, F6, D2, B6, E5, 86, E4, F7, C2, 91, 3D, B6, CB, FF, B4, 19, E4, 13, 00, 80, 83, C4, 04, 90, 66, 81, 44, 24, FC, B0, BA, 75, B6, 4E, 8B, D6, 4A, 68, 90, 04, 62, 22, E8, E2, FE, FF, FF, 89, 74, 24, 44, 80, E5, 18, 91, E8, 4B, 01, 00, 00...
 
[+]

Entropy:
7.9531  (probably packed)

Code size:
788.5 KB (807,424 bytes)

The file adskip.v1.0.429.9902.exe has been seen being distributed by the following URL.

Remove adskip.v1.0.429.9902.exe - Powered by Reason Core Security