skype_he.exe

Webcellence Ltd.

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application skype_he.exe by Webcellence has been detected as adware by 4 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from safe.to.download.downloadastro.com.
Publisher:
Webcellence Ltd.  (signed and verified)

MD5:
dc09595248bca4d1a03e818ad8dfab7f

SHA-1:
fc25e9fd3b42777ad31e044b7552c9b9bb2d26ac

SHA-256:
c222a37c862acc07318779a56ac87842544827191c52b93522278581827ee183

Scanner detections:
4 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/24/2024 6:07:01 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/InstallCore.BL potentially unwanted application
8.0.319.0

F-Prot
W32/InstallCore.R.gen
4.6.5.141

Reason Heuristics
PUP.installCore.Webcelle (M)
16.6.20.0

VIPRE Antivirus
Threat.4150696
29708

File size:
648.1 KB (663,680 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\skype_he.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/5/2013 12:00:00 AM

Valid to:
5/4/2014 11:59:59 PM

Subject:
CN=Webcellence Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Webcellence Ltd., L=Moshav Ora, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2742F1242826FB7F69B052B7F394DFED

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:lVyMJfsekgR9qtoDtQ9nCF4PVK1f4c/uyg/Hv6V3znQ4IkX7ko+yvnCZCXPwFQb:lVyMJfs7gR9goXFeUiyg/vcE4r7D+gnL

Entry address:
0x98CC

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, FA, 97, FF, FF, E8, 01, AA, FF, FF, E8, 2C, CC, FF, FF, E8, 73, CC, FF, FF, E8, 0A, F3, FF, FF, E8, 71, F4, FF, FF, 33, C0, 55, 68, 76, 9F, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 2C, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 26, FA, FF, FF, 8D, 55, F0, 33, C0, E8, E0, D0, FF, FF, 8B, 55, F0, B8, D8, BD, 40, 00, E8, AB, 98, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D8, BD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.7892

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36 KB (36,864 bytes)

The file skype_he.exe has been seen being distributed by the following URL.

Remove skype_he.exe - Powered by Reason Core Security