new-york-city-panorama.rar_13741813_01_letf.exe

Skymonk Solutions Limited

The application new-york-city-panorama.rar_13741813_01_letf.exe by Skymonk Solutions Limited has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from letitbit.net and multiple other hosts.
Publisher:
Skymonk Solutions Limited  (signed and verified)

MD5:
fdc9b6f9790713526e45000de03c8376

SHA-1:
250e58bd32d6303aab75e1234fa916bf6f7f6715

SHA-256:
999b4a2d4921f3a3a975f25977af6b038375a44dcb842c384bffcb1791868f93

Scanner detections:
7 / 68

Status:
Adware

Analysis date:
11/27/2024 6:46:43 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Trojan.Win32.Skymonk
4.0.3.14110

Bkav FE
W32.Clodf32.Trojan
1.3.0.4613

Dr.Web
Tool.Skymonk.14
9.0.1.010

ESET NOD32
Win32/Skymonk
8.9190

McAfee
Artemis!FDC9B6F97907
5600.7255

Norman
Skymonk.B
11.20140110

Reason Heuristics
PUP.SkymonkSolutionsLimited.k
14.5.19.1

File size:
117.7 KB (120,520 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\new-york-city-panorama.rar_13741813_01_letf.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/9/2012 2:00:00 AM

Valid to:
4/10/2015 1:59:59 AM

Subject:
CN=Skymonk Solutions Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Skymonk Solutions Limited, L=Tortola, S=Tortola, C=VG

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
632A5F301191DF03C4933D982BAD525F

File PE Metadata
Compilation timestamp:
2/24/2012 8:22:01 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:0tKr1f0hzRjeWsHyb2SjlLbS1ydrIJKIsuwlnX:KEG71Tb2sLp6KfFnX

Entry address:
0x36DA

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 1C, C7, 44, 24, 10, C0, 8A, 40, 00, 89, 5C, 24, 18, C6, 44, 24, 14, 20, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, AC, 80, 40, 00, 53, FF, 15, A4, 82, 40, 00, 6A, 08, A3, 18, 36, 45, 00, E8, FD, 28, 00, 00, 53, 68, 60, 01, 00, 00, A3, 28, 35, 45, 00, 8D, 44, 24, 3C, 50, 53, 68, BF, 8A, 40, 00, FF, 15, 70, 81, 40, 00, 68, B4, 8A, 40, 00, 68, 20, F5, 44, 00, E8, 27, 26, 00, 00, FF, 15, A8, 80, 40, 00, 50, BF, 50, C0, 47, 00, 57, E8, 15, 26...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The file new-york-city-panorama.rar_13741813_01_letf.exe has been seen being distributed by the following 14 URLs.

http://letitbit.net/downloader_13613573_04_letF.exe

http://dl.skymonk.net/.../?id=rapid004

http://letitbit.net/downloader_18194935_17_letF.exe