SkypeSetup.exe

Skype

Skype Technologies S.A.

The executable SkypeSetup.exe has been detected as malware by 8 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from skype.fr.softonic.com.
Publisher:
Skype Technologies S.A.

Product:
Skype

Description:
Skype

Version:
7.21.0.100

MD5:
1328fc6988ea41b732f8b9e22e3cebf2

SHA-1:
28a9178003665880076fbb7d177653004206d4db

SHA-256:
6501e82aaa90dfb4da0d0185facb0041de85087ed4734b1edb2717a5d8594674

Scanner detections:
8 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
12/27/2024 11:19:09 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

avast!
Win32:Sality
160216-0

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
16.03.27

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Virut.AI!Generic
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

VIPRE Antivirus
Threat.4758034
47432

File size:
1.5 MB (1,571,968 bytes)

Product version:
7.21

Copyright:
(c) Skype Technologies S.A.

Original file name:
SkypeSetup.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\skypesetup.exe

File PE Metadata
Compilation timestamp:
3/1/2016 9:32:31 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:5qVMq2j7V+Yr/DYQWWJS4JMuhwi6uwVVBZDSQN3iOHU5OlfG6oiGo:5qVTW7VXUdQZKkc3VBZ+QkvgfGLo

Entry address:
0x2E3DF0

Entry point:
2B, DE, 84, EF, 86, D6, 78, 06, 80, D1, 4F, 0F, B6, D2, 81, F3, D1, C9, 00, 00, 8D, 35, 47, 6B, B5, B4, F6, C2, 2B, 56, 68, F7, DB, 26, 00, F6, C6, 9F, B3, 6C, E8, 49, 00, 00, 00, 0F, AF, EE, F6, C5, 65, B9, D6, 67, FF, FF, 0D, F4, C9, 48, 5E, 81, F1, 15, 9F, 00, 00, 0F, B6, C2, 81, C1, A7, 0B, 00, 00, 43, 0F, BF, D9, 39, E8, 81, E9, F5, FB, FF, FF, 69, F8, F8, 70, F6, 61, 81, E9, 0C, 04, 00, 00, FF, C8, 8D, 15, 15, C5, A8, D7, 1A, DC, 81, F9, 78, 00, 00, 00, 73, D6, 5F, 0F, 6E, DF, 84, EE, C7, C3, E7, F8...
 
[+]

Code size:
1.1 MB (1,187,840 bytes)

The file SkypeSetup.exe has been seen being distributed by the following URL.

Remove SkypeSetup.exe - Powered by Reason Core Security