skypetool by pops.exe

WindowsApplication1

The executable skypetool by pops.exe has been detected as malware by 25 anti-virus scanners. The file has been seen being downloaded from download1162.mediafire.com.
Product:
WindowsApplication1

Version:
1.0.0.0

MD5:
31d8b055404f56a9f1ccf4ac2ef1e2ca

SHA-1:
215f818539b062f8b6336fe73b91d19fb123f014

SHA-256:
58f74207c486f130cb8aa89edbb83accea4226ea7a1e50fcc3a36d7ff1c782e3

Scanner detections:
25 / 68

Status:
Malware

Analysis date:
4/16/2024 10:28:55 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.127455
646

AegisLab AV Signature
Troj.W32.Gen
2.1.4+

avast!
Win32:Malware-gen
2014.9-150429

AVG
MSIL
2016.0.3124

Baidu Antivirus
Trojan.MSIL.Injector
4.0.3.15429

Bitdefender
Gen:Variant.Kazy.127455
1.0.20.595

Comodo Security
UnclassifiedMalware
21625

Emsisoft Anti-Malware
Gen:Variant.Kazy.127455
8.15.04.29.06

ESET NOD32
MSIL/Injector.BLF (variant)
9.11417

Fortinet FortiGate
MSIL/Injector.AKV
4/29/2015

G Data
Gen:Variant.Kazy.127455
15.4.25

IKARUS anti.virus
Trojan.Msil
t3scan.1.8.9.0

K7 AntiVirus
Riskware
13.202.15469

Kaspersky
Trojan.Win32.Genome
14.0.0.2116

McAfee
Artemis!31D8B055404F
5600.6780

MicroWorld eScan
Gen:Variant.Kazy.127455
16.0.0.357

NANO AntiVirus
Trojan.Win32.Genome.bnzlyt
0.30.8.659

Norman
Troj_Generic.GCPZO
11.20150429

nProtect
Trojan/W32.Agent.516096.MA
15.04.02.01

Qihoo 360 Security
Win32/Trojan.051
1.0.0.1015

Trend Micro House Call
TROJ_SPNR.03CF13
7.2.119

Trend Micro
TROJ_SPNR.03CF13
10.465.29

VIPRE Antivirus
Trojan.Win32.Generic
38998

ViRobot
Trojan.Win32.S.Agent.516096.AX[h]
2014.3.20.0

Zillya! Antivirus
Trojan.Genome.Win32.240513
2.0.0.2124

File size:
504 KB (516,096 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2012

Original file name:
SkypeTool by Lethalnz.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\hack packs\toolz\skype tools\skypetool by pops.exe

File PE Metadata
Compilation timestamp:
12/13/2012 8:11:09 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:Bg9AOmXFsKPrtcMmGTiF4yyWghhhdhEr1fUeqZ295pv:WbYxrOzciF4yyWghhhdhEUeqZ2T

Entry address:
0x3D5BE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 03, 00, 03, 00, 00, 00, 28, 00, 00, 80, 0E, 00, 00, 00, 40, 00, 00, 80, 10, 00, 00, 00, 58, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 02, 00, 00, 00, 70, 00...
 
[+]

Entropy:
6.3285

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
237.5 KB (243,200 bytes)

The file skypetool by pops.exe has been seen being distributed by the following URL.

Remove skypetool by pops.exe - Powered by Reason Core Security