skype.exe

App secure LLC

This is the Softpulse installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application skype.exe by App secure has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Softpulse SoftwareBundler installer. The file has been seen being downloaded from fastjavinstall.com.
Publisher:
App secure LLC  (signed and verified)

MD5:
13db9c5beece3a0c8d4df6161c1c60fc

SHA-1:
750352e9971ad105fac4ccb626db8015577d89f7

SHA-256:
4d25d8b285890b005468ae4786845130161bf562450ec2b8cbe6bec97f746cbb

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/28/2024 8:52:38 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Softpulse.Appsecur.Bundler (M)
16.3.26.8

File size:
485.5 KB (497,112 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Softpulse SoftwareBundler

Common path:
C:\users\{user}\downloads\skype.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/17/2014 4:00:00 AM

Valid to:
12/18/2015 3:59:59 AM

Subject:
CN=App secure LLC, O=App secure LLC, L=Wilmington, S=Delaware, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5D0A1845D85007CD040B350F48C5F721

File PE Metadata
Compilation timestamp:
3/1/2015 1:34:54 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:+tDyfK49N2repycGHbt/mB4b1pHLT9gjY3RNuF5nF:li4bc7ZmB4J9LpIYbW1F

Entry address:
0x1000

Entry point:
B8, B0, DC, 58, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 5D, A6, CB, FE, E1, 56, 16, CD, 5D, 72, C0, 17, CF, 7D, EE, 01, 07, 95, 8A, 01, 86, CF, 52, 4F, D9, A7, 64, 8D, B7, 4C, E0, 12, B4, DF, 60, 56, E2, 04, 0D, FC, 26, AF, 52, 74, 4A, AA, 7A, 4E, FD, 26, 75, 3F, 75, A6, 35, E3, DC, 39, E8, C5, C5, 40, A6, AD, 79, 18, 3D, 77, D1, F3, 70, 9C, 1B, 29, D4, BB, C5, 4B, F2, 47, 67, D3, DD, CD, 2C, 2D, D8, C8, EA, 45, 02, 45, 38...
 
[+]

Entropy:
7.9406

Packer / compiler:
PECompact v2

Code size:
965.5 KB (988,672 bytes)

The file skype.exe has been seen being distributed by the following URL.

Remove skype.exe - Powered by Reason Core Security