sky.exe

Sky Saber

GMThai Games

The executable sky.exe has been detected as malware by 7 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from www.gmthai.com.
Publisher:
GMThai Games

Product:
Sky Saber

Description:
Sky Saber Setup

Version:
2.0.0.0

MD5:
46fdd1ee706c42ff6c53c006c589580b

SHA-1:
e5423159e92231485bdbeaf6fb2b9b1120c46454

SHA-256:
149c2d84a4863592315921334387499ed064ad5335fb65244d18f21c8081dd7e

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
11/28/2024 4:22:01 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160518-2

AVG
Win32/Sality
2015.0.4591

Dr.Web
Win32.Sector.30
9.0.1.05190

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.E.gen
4.6.5.141

Microsoft Security Essentials
Threat.Undefined
1.223.1964.0

VIPRE Antivirus
Threat.4721115
49574

File size:
685.2 KB (701,688 bytes)

Copyright:
GMThai Games

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\sky.exe

File PE Metadata
Compilation timestamp:
12/6/2009 5:50:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:XTqy5YJFlE6e7TYmUH/JJLpe0tKmbGJsMbH5DIvho2RvExK1VRXFBQmV:XTqy5gN6TipdK+SsA0Zo2sybBQmV

Entry address:
0x323C

Entry point:
EB, 02, 38, E4, 39, C2, 48, 8A, C2, 85, F1, 0F, AF, F0, 8D, 35, 92, 0F, C2, B1, 0F, AF, F1, FF, CB, 81, C8, 14, 75, 3A, 61, 41, 01, C9, C7, C6, F0, 21, 25, 81, E8, 85, 00, 00, 00, 81, FA, 12, 2D, 00, 00, 70, 02, 20, D9, 4A, 20, DC, EB, 08, F7, C1, BC, 1F, 7B, 20, 12, CF, 8D, 35, 41, 6A, 6C, 4C, 81, CD, 8F, 92, C0, 61, 69, E9, D6, 54, 75, A4, 69, E8, D9, 61, 83, 27, 3A, C9, F6, C3, 84, 33, C0, EB, 05, 39, C5, 1B, F0, F3, B8, 03, 88, F8, FF, 85, D8, 73, 06, FE, CF, 84, C2, 8B, DD, 2D, ED, 01, 00, 00, 39, EB...
 
[+]

Entropy:
7.9801

Packer / compiler:
FSG v1.10 (Microsoft Visual C++ 6.0 / 7.0)

Code size:
23 KB (23,552 bytes)

The file sky.exe has been seen being distributed by the following URL.

Remove sky.exe - Powered by Reason Core Security