sky_fire.exe

Media Contact LLC

The application sky_fire.exe, “Sky Fire Setup ” has been detected as a potentially unwanted program by 13 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from c.gametop.com.
Publisher:
Media Contact LLC

Description:
Sky Fire Setup

MD5:
79dc2d45a5e49017474b9e02e814c72c

SHA-1:
617692a3151b4e25ba58ad91d69f6b61af726d46

SHA-256:
2ae35a7e0c4769a433fd3976fefddd4ef503dcd5a9819329dd8bacc05558e734

Scanner detections:
13 / 68

Status:
Potentially unwanted

Analysis date:
4/27/2024 1:01:20 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Worm.Autorun.VON
5819428

avast!
Win32:Dropper-NVQ [PUP]
160112-0

AVG
Worm/Pakes.BZH
2015.0.4489

Clam AntiVirus
Win.Worm.Autorun-5208
0.98/21255

Dr.Web
Trojan.Click2.42536
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Graftor.145879
10.0.0.5366

ESET NOD32
Win32/Blueh.A virus
7.0.302.0

F-Prot
W32/Trojan2.NUWQ
4.6.5.141

Kaspersky
Trojan.Win32.Blueh
15.0.0.562

McAfee
Trojan.Trojan-FDMI!79DC2D45A5E4
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.2742.0

Norman
Gen:Variant.Graftor.145879
11.01.2016 17:30:26

VIPRE Antivirus
Threat.4792057
46446

File size:
3.6 MB (3,735,448 bytes)

Copyright:
Copyright (C) Media Contact LLC

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\sky_fire.exe

File PE Metadata
Compilation timestamp:
3/29/2012 11:00:20 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:QYQeaFRWhqK9nBDVX0yK+3NwQyq3r6HntshYksfw:cRdUn9q+dP3+Ns3s4

Entry address:
0x2845

Entry point:
E8, 7E, 04, 00, 00, E9, 37, FD, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 40, 51, 40, 00, 89, 0D, 3C, 51, 40, 00, 89, 15, 38, 51, 40, 00, 89, 1D, 34, 51, 40, 00, 89, 35, 30, 51, 40, 00, 89, 3D, 2C, 51, 40, 00, 66, 8C, 15, 58, 51, 40, 00, 66, 8C, 0D, 4C, 51, 40, 00, 66, 8C, 1D, 28, 51, 40, 00, 66, 8C, 05, 24, 51, 40, 00, 66, 8C, 25, 20, 51, 40, 00, 66, 8C, 2D, 1C, 51, 40, 00, 9C, 8F, 05, 50, 51, 40, 00, 8B, 45, 00, A3, 44, 51, 40, 00, 8B, 45, 04, A3, 48, 51, 40, 00, 8D, 45, 08, A3, 54, 51, 40...
 
[+]

Entropy:
7.9037  (probably packed)

Code size:
7.5 KB (7,680 bytes)

The file sky_fire.exe has been seen being distributed by the following URL.

Remove sky_fire.exe - Powered by Reason Core Security