skyfilmes_player.exe

Backup

The executable skyfilmes_player.exe has been detected as malware by 16 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from skyfilmess.com.
Publisher:
Backup

Description:
Backup for

Version:
0.0.0.1

MD5:
04a1ae84a0629aa005522cf4ddc5293f

SHA-1:
1293e23177b7ed1fcf3451cdf240138c99641113

SHA-256:
0e124dfbf37a7f18c4f6403c4aa1bdd05e631a044b89e5d7a2cd1677323b3f1e

Scanner detections:
16 / 68

Status:
Malware

Analysis date:
11/15/2024 1:05:28 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.101775
377

Agnitum Outpost
Trojan.PWS.BestaFera
7.1.1

Avira AntiVirus
TR/Spy.Banker.626688.3
8.3.2.4

Arcabit
Trojan.Strictor.D18D8F
1.0.0.642

avast!
Win32:Dropper-gen [Drp]
2014.9-160124

Bitdefender
Gen:Variant.Strictor.101775
1.0.20.120

Comodo Security
TrojWare.Win32.TrojanDownloader.Delf.gen
23912

Emsisoft Anti-Malware
Gen:Variant.Strictor.101775
8.16.01.24.09

Fortinet FortiGate
W32/BestaFera.FZA!tr
1/24/2016

F-Secure
Gen:Variant.Strictor.101775
11.2016-24-01_1

G Data
Gen:Variant.Strictor.101775
16.1.25

K7 AntiVirus
Trojan
13.212.18305

Kaspersky
Trojan-Banker.Win32.BestaFera
14.0.0.768

MicroWorld eScan
Gen:Variant.Strictor.101775
17.0.0.72

Quick Heal
(Suspicious) - DNAScan
1.16.14.00

Sophos
Mal/Generic-S
4.98

File size:
612 KB (626,688 bytes)

Product version:
Backup

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\skyfilmes_player.exe

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:Ksl4ZfFeD8Q78jr39c+o0jVgIeJ0rUAYJCPh4Z:K3Z28jr39cpmgIw0rUAYeGZ

Entry address:
0x1000

Entry point:
68, 01, A0, 48, 00, E8, 01, 00, 00, 00, C3, C3, 6F, C9, 77, 8E, 3E, FF, 06, 58, CE, D2, 85, 3C, 75, 5E, D9, 4D, 64, FF, 72, A0, F9, 5F, 18, 46, 11, F7, 2F, 0C, 22, 54, B9, 82, 5A, AC, EE, 0A, DF, C5, F5, 23, 58, 69, 40, A3, 86, D0, F0, 43, DA, 47, C1, 5F, 66, 41, DF, ED, 86, 10, 7E, 36, 96, 28, 96, 03, 8D, 7C, 20, 02, 91, 6B, 12, C7, 3E, 9B, DD, 1D, A0, E6, 13, EF, 4A, B7, AF, 41, 0A, 34, 6C, 42, 66, 26, 67, 86, 66, F0, EF, DC, 2A, 8D, 2B, E3, 81, 11, AF, 29, AA, 84, 1A, F1, A7, 2B, 44, EB, 38, AE, A7, 3D...
 
[+]

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
341.5 KB (349,696 bytes)

The file skyfilmes_player.exe has been seen being distributed by the following URL.

Remove skyfilmes_player.exe - Powered by Reason Core Security