skypesetup.exe

Skype

Innovative Systems LLC

The application skypesetup.exe by Innovative Systems has been detected as adware by 21 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars. The file has been seen being downloaded from skype.joydownload.com and multiple other hosts.
Publisher:
Innovative Systems LLC  (signed and verified)

Product:
Skype

Version:
1.0.0.0

MD5:
ffb6a44b385e2fbeb68d47171a820d74

SHA-1:
c48b4d86f2c3681250725b9a59d6e4cd8ae989ca

SHA-256:
0742b7374141646936128a4e7c97dc4cc8f30f6296367dabf0a8fe6e30c067d4

Scanner detections:
21 / 68

Status:
Adware

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
11/25/2024 10:21:57 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.OpenCandy
7.1.1

AhnLab V3 Security
PUP/Win32.OpenCandy
2014.10.17

Avira AntiVirus
APPL/Downloader.Gen
7.11.179.8

avast!
Adware-gen [Adw]
2014.9-141017

AVG
OpenCandy
2015.0.3318

Baidu Antivirus
Adware.Win32.OpenCandy
4.0.3.141017

Clam AntiVirus
Win.Trojan.Opencandy
0.98/21411

Comodo Security
Application.Win32.OpenCandy.~WD
18598

Dr.Web
Adware.Downware.6712
9.0.1.0290

ESET NOD32
Win32/JoyDownloader
8.10575

G Data
Win32.Adware.OpenCandy
14.10.24

IKARUS anti.virus
PUA.JoyDownloader
t3scan.1.7.5.0

K7 AntiVirus
Unwanted-Program
13.180.12456

Malwarebytes
PUP.Optional.OpenCandy
v2014.10.17.01

McAfee
Artemis!FFB6A44B385E
5600.6974

NANO AntiVirus
Riskware.Win32.OpenCandy.cxlnia
0.28.0.60253

Reason Heuristics
PUP.Installer.InnovativeSystems.K
14.10.17.13

Rising Antivirus
PE:PUF.OpenCandy!1.9DE5
23.00.65.141015

Sophos
OpenCandy
4.98

Trend Micro House Call
TROJ_GEN.F47V0604
7.2.290

VIPRE Antivirus
Opencandy
32442

File size:
496.4 KB (508,352 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\skypesetup.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
9/19/2014 3:00:00 AM

Valid to:
9/20/2015 2:59:59 AM

Subject:
CN=Innovative Systems LLC, O=Innovative Systems LLC, L=Dnepropetrovsk, S=Dnepropetrovska, C=UA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
09A91C40EAE34E72CD975B0B218AE4BA

File PE Metadata
Compilation timestamp:
5/20/2013 2:52:48 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:IQgLYTqMkGW9PpYRO0VyRzBExWa2J39ODijNxEXc4TBwWy:pSYTqLtYVytBExn2J3gejMcE3y

Entry address:
0x331F

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 30, 92, 40, 00, 89, 6C, 24, 14, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, BC, 70, 40, 00, 55, FF, 15, AC, 72, 40, 00, 6A, 08, A3, D8, 7A, 7A, 00, E8, A8, 2E, 00, 00, A3, 24, 7A, 7A, 00, 55, 8D, 44, 24, 34, 68, B4, 02, 00, 00, 50, 55, 68, D0, EE, 79, 00, FF, 15, 7C, 71, 40, 00, 68, 7C, 93, 40, 00, 68, 20, 6A, 7A, 00, E8, 13, 2B, 00, 00, FF, 15, 34, 71, 40, 00, BB, 00, 20, 7B, 00, 50, 53, E8, 01, 2B, 00, 00...
 
[+]

Entropy:
7.8649

Packer / compiler:
Nullsoft install system v2.x

Code size:
24 KB (24,576 bytes)

The file skypesetup.exe has been seen being distributed by the following 22 URLs.

http://skype.joydownload.com/get_azure_file/wUiS4WnYccXBwj qXP7oQkEsm10kPjuhChOxatrZp7Z rTy893p5ktEPKUbkbLP4OnG5yxdSMGmeRKq1E/Y9xLNyg5/DU1PWvD3zT0z0smnm0qHDpZrSk2lZo5EiiBZIVXatGGos14N1r2K/GD LS/9Wzc3zdGxOKOwgJFsFMKXlECMrasWNLB0onqPmECYkepf5kuczBHvs7Qabyb1 D9G3c8i8bXVVzcr F sujVlR/.../wgp4RV2mhGFi79ojvig==

http://skype.joydownload.com/get_azure_file/wUiS4WnYccXBwj qXP7oQkEsm10kPjuhChOxatrZp7Z rTy893p5ktEPKUbka7n5O3G4yxdSMGmeX621E/Y9wrNyxdSWRAaS9T2hVRLlszi1if/.../q1RHE8cs3ENBkmhbPvUSwhcpekiLFgHGL5uFvLlu0vX9v9JYH7KzQcwZT1SPsv3BcX55qizkrzLaBynT7hWpEJsYD4UXKquZKaiGp5M6RIBo47M20hsuCnHBhzhVW61NdWUHW1FAaqqZvvig==

http://skype.joydownload.com/get_azure_file/wUiS4WnYccXAwj 1RrjxCgghkkVxZmbzR1 xcteQv A8/.../smmxQH5sv3iVLqOPMpwj6tQMVc6s2pACKg88TTz2hlJ6gWDdEvMjwps i1W0M1nB3z3dtOAS7jBA3yoYjvig==

http://skype.joydownload.com/get_azure_file/wUiS4WnYccXBwj zXP7oQkEsml0kPTy1E1v4YtbB8ack5ib0o2JgyskFbk3jYqmqZi/p0l8bOGKIEfvkQ/x3lvo1gIPdGVnZqj3zT0z0smn50qHDpZrSl2lZo5cyg1RARn3kAD91ntF9p2i6BjLQBf4A2syiPTINevppZlhaIaS0XHx1apiRek93zrPvUSwmcpfw1eQnBSqwtFDdybcsXdDoYsn3ZXBY3sK7HuEgmBseroL h0q4N/.../UlK04Ijvig==

http://skype.joydownload.com/get_azure_file/wUiS4WnYccXBwj pXP7oQlssmVx1NTmnEgqmOZ T6bJ/qCeisGMxwd4EPwS8IfupLXj/yldSICPVT/usW780yathx8CPDE b/CXqVR jqnD8gffbvNvcg2gIq5M6kQAKFC/lXyx zcko ir5W2GcQbhVw4TrMz0VPuBuegoEcKX2UnBtO5WHZk5h2eWhUjhwMNDg2q4/CGOo5AWTyKouFpn esGkfXNY1tO2XuMmlQ9Krpr2zlL/.../Mz4SXvjodXUiCdjbbdJV4UvMjwps i1W0M1nB3z3dtOAS7jBA3yoYjvig==

http://skype.joydownload.com/get_azure_file/wUiS4WnYccXGwj 8XPavWwllklYyNSrkQ1GyNZ G8aZ28zC293p5iNENJ1W Me/uNDC2wl5KMGeeEKqtGr8lnPpyz4WXAAaDuHamWBmw 2m0yP/QrtPKxToI4clhyhAACGSsSTRwntFqpWK6D3GSA7ZawtW0f3deKuwgJEEFMqv2VXp7fs7HIBBhhqLuAGB8LJf5kuczBHu4sFjPnf1 D9G3c8i8LCgIzcrkF gv3BcX55q5yUrzLaB0nT6nEcQe5MGxUS 278XF2D4rJLxAT5Y/PXYxu6GtHhBzzk/.../rFAzwpYjvig==

http://skype.joydownload.com/get_azure_file/wUiS4WnYccXDyCf4UfO5CV530RJ0YyqsWxL3as6Q7qp2uHf14WJ0wclbZQe Ku7uNCq2wVBZMWaJHuyjEL50ybpq1oDEUx6avCX BlT1unm/ivfDpZrSk2lZ5dEiiBZIVXy1Cyx 18kr9DmlGXGSA7ZbwtWmbmlTN/5xPRNMOaz9RDkmLNzFfxEjh LuFCw3Ltquhbh3HGL5uFnFjv1oDYC2M8itZWMchpWvFqounBcH7Iv7n1O7ZKl/hXX/.../wgp4RV2mhGFi79ojvig==

http://skype.joydownload.com/get_azure_file/wUiS4WnYccXDyCf4UfO5CV530RJ0YyqsWxL3as6Q7qp2uHf14WJxwclNdBP1Y L2Pnj/ylJSIDbEW7DlTac8mrNhwMeeBQ2W SvwBwX9unGt1LbDpZrSlmlZ5sxu1woFF2SsSTRxntF/p3evSGjaSr1YwtWibH5HPfpna11PLfq/A2h0O8TILAl00/2wR2Q3c8b40ucnDG2zoFGMlvxmFtLkJNClLHtf1dO8Hu82lF4f74LvyRzqZel/lia0At1Wrc24SWuv6sWCkW8qYbxRR4Y/OX4hounkFxlrnE/.../xp4jvig==

http://skype.joydownload.com/get_azure_file/wUiS4WnYccXBwj qXP7oQkEsm10kPjuhChOxat/Zp6VvuXf14WJ0wckML0XnabnuNDC2xl5KZyvMQqvyCr5uybhkxcWaAwuQ CbzT0z1smn7z fa7dPZm3FKs55ziVFIRiD Vmtnn4Aj/y/wSCDCCfwJi5KlcncZPfFnPRNMOaz9RDkmLNzFfxEjh LuECw3J8bg2q4/CWOo9QORyKArR4C2M8ioZWMKgJ3pSKs2lF4f7oLvj1zxfKE2nS2mCd0Jt4T7Hyig9tPMiCdjbbNJV8dmcD92ounkFxlrnE/.../xp4jvig==

http://skype.joydownload.com/get_azure_file/wUiS4WnYccXEwj /TeqjC1c0kw48PjymGx/3Y9/Vs h152b0sCgrn8kFbk3kYqn9PHWuyxdSNmmeTbD7Tac8gLNhwMyPRFfYv3q7WQKy GXqw6DDpZrSkmlZ4sxkkV4bXnesSTR2ntFwp3/oUSCTQrZOysPzPHQNa7MgaUFbIaS0XHx1aszMJBsjjrPvUSwkeI/ghbR2TjXr x NwO1nR5i4etDtNDgcitO2XuMmlQ9RqZr2zlL5ZLh0hSflCc1X/Jj4UXKquZaaiGt5OeIcAscvMjwptui1S0U92kPyxdYHGS/.../3qojvig==

http://skype.joydownload.com/get_azure_file/wUiS4WnYccXDyCf4UfO5CV530RJ0YyqsWxL3as6Q7qp2uHf14WJxwclIdBP1Y/j2OXmuwlZaMmKOCeLkErM90ewohJ/fUh6apiX5CEf1sX 8g/fZpZrSkmlZ4sxkkV4bXnesSTR2ntFwp3/oUSCTQrZOysPzPHQNbrMgeUdTZ/.../wgp4RV2mhGFi79ojvig==

Remove skypesetup.exe - Powered by Reason Core Security