In January 2013, Iurii Khvyl and Peter Kruse from CSIS posted analysis of Shylock variant capable of spreading through Skype.
You can read their research here Shylock calling Skype. The sample is below
Name
|
MD5
|
GrooveMonitor.exe [dropper]
|
f3dd76477e16e26571f8c64a7fd4a97b
|
juboot.exe
|
fa0b300e671f73b3b0f7f415ccbe9d41
|
jucheck.exe
|
c4cd216112cbc5b8c046934843c579f6
|
SLEEP.EXE
|
ea7ed6b50a9f7b31caeea372a327bd37
|
WmiPrv.exe
|
b7117b5d8281acd56648c9d08fadf630
|
.png)
![]() |
| Img.baronet4tibet. Tibetan furniture featuring a leopard and a lion |