File name: | yd.exe |
Full analysis: | https://app.any.run/tasks/81db652f-cac4-4012-a045-e3b6cec5ec41 |
Verdict: | Malicious activity |
Analysis date: | May 15, 2019, 07:13:23 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | CE0771CF5475B13B19D58B78CDF9D0BA |
SHA1: | 5C239303790F4821E04DED3C9C439BF93BB19E38 |
SHA256: | 89D6063C36629BB9999CFE4A131FDCE54B27BA908DE095ECC4E97026829795E5 |
SSDEEP: | 49152:iGFlFJVJsA7JzlSQv8+lSmU8Z/HAwTLm5pbmkyPiMZNuZDLWZr8U:i6rBsWbjTLmLyk+1r |
.exe | | | Win32 Executable (generic) (52.9) |
---|---|---|
.exe | | | Generic Win/DOS Executable (23.5) |
.exe | | | DOS Executable Generic (23.5) |
ProductName: | Free YouTube Downloader |
---|---|
OriginalFileName: | installer.exe |
LegalCopyright: | LegalCopyright "© adaware" string © adaware |
InternalName: | installer.exe |
FileDescription: | YouTube Downloader Setup |
CompanyName: | adaware |
ProductVersion: | 2.8.4.1781 |
FileVersion: | 2.8.4.1781 |
CharacterSet: | Unicode |
LanguageCode: | English (U.S.) |
FileSubtype: | - |
ObjectFileType: | Executable application |
FileOS: | Windows NT 32-bit |
FileFlags: | (none) |
FileFlagsMask: | 0x003f |
ProductVersionNumber: | 2.8.4.1781 |
FileVersionNumber: | 2.8.4.1781 |
Subsystem: | Windows GUI |
SubsystemVersion: | 5.1 |
ImageVersion: | - |
OSVersion: | 5.1 |
EntryPoint: | 0x8e949 |
UninitializedDataSize: | - |
InitializedDataSize: | 406528 |
CodeSize: | 1251328 |
LinkerVersion: | 14 |
PEType: | PE32 |
TimeStamp: | 2019:05:08 18:16:20+02:00 |
MachineType: | Intel 386 or later, and compatibles |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2684 | "C:\Users\admin\AppData\Local\Temp\yd.exe" | C:\Users\admin\AppData\Local\Temp\yd.exe | — | explorer.exe |
User: admin Company: adaware Integrity Level: MEDIUM Description: YouTube Downloader Setup Exit code: 3221226540 Version: 2.8.4.1781 | ||||
4084 | "C:\Users\admin\AppData\Local\Temp\yd.exe" | C:\Users\admin\AppData\Local\Temp\yd.exe | explorer.exe | |
User: admin Company: adaware Integrity Level: HIGH Description: YouTube Downloader Setup Exit code: 1 Version: 2.8.4.1781 |
(PID) Process: | (4084) yd.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager |
Operation: | write | Name: | PendingFileRenameOperations |
Value: \??\C:\Users\admin\AppData\Local\Temp\CR_6EC0F.tmp\setup.exe |
PID | Process | Filename | Type | |
---|---|---|---|---|
4084 | yd.exe | C:\Users\admin\AppData\Local\Temp\2019.05.15_08.13.39.615250_yd_pid=4084.txt | text | |
MD5:5D37F432C1E3692BE7D7556F81972BF4 | SHA256:012197FFF8DF77697840327A7B3D67A6D8DEC285F7375ED5F06A0CB6903C5114 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
4084 | yd.exe | POST | 200 | 104.17.60.19:80 | http://flow.lavasoft.com/v1/event-stat?ProductID=IS&Type=StubError | US | text | 29 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4084 | yd.exe | 104.17.60.19:80 | flow.lavasoft.com | Cloudflare Inc | US | shared |
Domain | IP | Reputation |
---|---|---|
flow.lavasoft.com |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
4084 | yd.exe | Misc activity | ADWARE [PTsecurity] MSIL/WebCompanion.A PUP |