skymonkasetup.exe

Skymonk Solutions Limited

The application skymonkasetup.exe by Skymonk Solutions Limited has been detected as adware by 5 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from update.skymonk.net.
Publisher:
Skymonk Solutions Limited  (signed and verified)

MD5:
8de68038b6f1ef43d26577c6007537ee

SHA-1:
a09769adc06e093a3451a6f0effd7e729db0b8af

SHA-256:
e5e73d355b929ae0c55dbedee29e6573402ca916dc4fb62e2880a429241342bc

Scanner detections:
5 / 68

Status:
Adware

Analysis date:
11/27/2024 6:35:12 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Downware.2172
9.0.1.054

Kaspersky
not-a-virus:AdWare.Win32.Skyli
14.0.0.4270

Quick Heal
(Suspicious) - DNAScan
2.14.12.00

Reason Heuristics
PUP.Installer.SkymonkSolutionsLimited.N
14.5.19.1

Trend Micro House Call
TROJ_GE.C4C60729
7.2.54

File size:
1.5 MB (1,573,264 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\skymonkasetup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/9/2012 4:00:00 AM

Valid to:
4/10/2015 3:59:59 AM

Subject:
CN=Skymonk Solutions Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Skymonk Solutions Limited, L=Tortola, S=Tortola, C=VG

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
632A5F301191DF03C4933D982BAD525F

File PE Metadata
Compilation timestamp:
11/27/2013 10:18:53 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:p+ibSEGcgRgGYp1Y8dQOBEmJ86Ln6mq6pQT2a0nDG320bgqYhScz29GRr:HHwRgGa1VdQzmmYnKT2a0irbTi329GR

Entry address:
0x38DA

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, C0, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 0D, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 84, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, EF, 26, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, DD, 26, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
28.5 KB (29,184 bytes)

The file skymonkasetup.exe has been seen being distributed by the following URL.

Remove skymonkasetup.exe - Powered by Reason Core Security