skypemoticons.exe

Shlomo Dayan

This program bundles adware during the download and install process using the InstaleRex pay-per-install app monetizer. The application skypemoticons.exe, “Installer for SummerSoft” by Shlomo Dayan has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the WebPick InstalleRex (Tarma) installer. The file has been seen being downloaded from skypemoticonsb.asia. While running, it connects to the Internet address r1.stylezip.info on port 80 using the HTTP protocol.
Publisher:
SummerSoft  (signed by Shlomo Dayan)

Product:
SummerSoft

Description:
Installer for SummerSoft

Version:
2013.9.15.1650

MD5:
8a2380aebd9b6ecc5f62d94bbe308f38

SHA-1:
6449fee447262518e2a9ccf1cd6e45cc041b1e79

SHA-256:
921b31278779dd67936f7f975aeeb4598252ae586d6f995d5fd0a8a5f1ba1470

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses Web-Pick's 'File Product', an Installer which wraps various products and downloads and installs it silently through the process, hosted on TusFiles.

Analysis date:
4/24/2024 12:48:39 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.WebPick.Installer (M)
16.5.17.3

File size:
297.7 KB (304,832 bytes)

Product version:
1.0.0.1

Copyright:
Copyright © 2012 SummerSoft

Original file name:
TSULoader.exe

File type:
Executable application (Win32 EXE)

Installer:
WebPick InstalleRex (Tarma)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\skypemoticons.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/22/2013 4:00:00 AM

Valid to:
1/23/2014 3:59:59 AM

Subject:
CN=Shlomo Dayan, O=Shlomo Dayan, STREET=Smadar 45, L=Tel Aviv, S=center, PostalCode=67126, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
413C7D68ADD60589106BCF7DC596FBBA

File PE Metadata
Compilation timestamp:
3/12/2013 12:51:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:2rkb9uEo2S1YnQmCX492DkwNP3qpYFB44DtcEj2WhIbp1Hl9Ird5NSY/jR:2rkRu6/eIo4244DtJjJS1TaVS0F

Entry address:
0x14DB

Entry point:
55, 8B, EC, 81, EC, 2C, 06, 00, 00, 53, 56, 33, DB, 57, 66, 89, 9D, DC, FB, FF, FF, 89, 5D, F4, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 08, 44, 40, 00, FF, 15, 70, 30, 40, 00, 8B, F8, 8D, 45, EC, 50, FF, 15, 6C, 30, 40, 00, FF, 15, 68, 30, 40, 00, 8B, F0, F7, D6, 33, F7, FF, 15, 64, 30, 40, 00, 33, F0, 8B, 45, F0, 33, 45, EC, 68, 04, 01, 00, 00, 33, F0, 8D, 85, D4, F9, FF, FF, 50, 53, FF, 15, 60, 30, 40, 00, 85, C0, 75, 41, FF, 15, 5C, 30, 40, 00, 83, F8, 78, 75, 1A, 68, A8, 32, 40, 00, E8, 43, FB, FF, FF...
 
[+]

Entropy:
7.9588

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file skypemoticons.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to r1.stylezip.info  (54.186.255.26:80)

Remove skypemoticons.exe - Powered by Reason Core Security