skype tools.exe

The application skype tools.exe has been detected as a potentially unwanted program by 12 anti-malware scanners. The file has been seen being downloaded from turbobit.net.
MD5:
5976fbbd2125a6936313a19168b6155f

SHA-1:
63f3af9dd8cab84a110787fcae5eb37dc11718a6

SHA-256:
8e88f321e909cd50bbb371f9b6c5008a5541e3135dcd43dca2150bb4c7ff8680

Scanner detections:
12 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 4:35:53 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.14740677
395

Arcabit
Trojan.Generic.DE0ECC5
1.0.0.425

avast!
Win32:Malware-gen
151217-3

Bitdefender
Trojan.Generic.14740677
1.0.20.25

Emsisoft Anti-Malware
Trojan.Generic.14740677
8.16.01.05.03

ESET NOD32
Win32/HackTool.Skype.K trojan
7.0.302.0

F-Secure
Trojan.Generic.14740677
11.2016-05-01_3

G Data
Trojan.Generic.14740677
16.1.25

McAfee
Program.Artemis!5976FBBD2125
18.0.204.0

MicroWorld eScan
Trojan.Generic.14740677
17.0.0.15

Rising Antivirus
PE:Trojan.Win32.Generic.18C55196!415584662
23.00.65.16103

VIPRE Antivirus
Threat.4150696
46268

File size:
3.7 MB (3,856,384 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\skype tools.exe

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:D+y00Cpnf3jHyTQ28TG/V3qVa9I/V3qValre:DDqpf3Z1TG/V3qVa9I/V3qValq

Entry address:
0x143D40

Entry point:
55, 8B, EC, 83, C4, F0, 53, B8, 28, 38, 54, 00, E8, EF, 33, EC, FF, 8B, 1D, 7C, 8C, 54, 00, 8B, 03, E8, 56, 2C, F2, FF, 8B, 0D, E0, 8D, 54, 00, 8B, 03, 8B, 15, D8, 35, 54, 00, E8, 5B, 2C, F2, FF, 8B, 0D, 2C, 8E, 54, 00, 8B, 03, 8B, 15, E8, F8, 53, 00, E8, 48, 2C, F2, FF, 8B, 0D, 10, 8C, 54, 00, 8B, 03, 8B, 15, C8, 31, 54, 00, E8, 35, 2C, F2, FF, 8B, 0D, 80, 8A, 54, 00, 8B, 03, 8B, 15, C4, 33, 54, 00, E8, 22, 2C, F2, FF, 8B, 03, E8, 9B, 2C, F2, FF, 5B, E8, 71, 0D, EC, FF, 90, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.1351

Developed / compiled with:
Microsoft Visual C++

Code size:
1.3 MB (1,322,496 bytes)

The file skype tools.exe has been seen being distributed by the following URL.

Remove skype tools.exe - Powered by Reason Core Security