File name:

Yandex.exe

Full analysis: https://app.any.run/tasks/3e0502e7-6886-490e-a848-8f92d4b93e80
Verdict: Malicious activity
Analysis date: July 13, 2024, 18:51:13
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

28EE3C895BE2B8771C06C2820D364B0F

SHA1:

78B61EDEF642DAE3A6C8BD5BEF2C59C5CAEF5879

SHA256:

B7ADE1749F7FCA0D886338D6EAA528530CE36237B46AB47CCD20D736E0B8E748

SSDEEP:

98304:TnbajsQOZzu2AvkuT9DcXr0SPAizoxcUfXto6qprqgYBHJbpcWSLQIJZmX1RuEW2:sxRx9w14mwAS/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Yandex.exe (PID: 2992)
      • ybF544.tmp (PID: 6988)
      • setup.exe (PID: 2860)
      • service_update.exe (PID: 3824)
      • Yandex.exe (PID: 2064)
    • Actions looks like stealing of personal data

      • setup.exe (PID: 5524)
      • service_update.exe (PID: 3824)
      • service_update.exe (PID: 1376)
      • service_update.exe (PID: 3508)
      • service_update.exe (PID: 6544)
      • service_update.exe (PID: 2452)
      • service_update.exe (PID: 6348)
      • explorer.exe (PID: 7136)
      • clidmgr.exe (PID: 2216)
      • explorer.exe (PID: 2648)
      • clidmgr.exe (PID: 5888)
      • conhost.exe (PID: 4780)
      • conhost.exe (PID: 1060)
      • browser.exe (PID: 6044)
      • browser.exe (PID: 3156)
      • browser.exe (PID: 368)
      • setup.exe (PID: 2860)
      • browser.exe (PID: 3932)
      • browser.exe (PID: 5940)
      • browser.exe (PID: 2032)
      • browser.exe (PID: 5316)
      • browser.exe (PID: 3660)
      • browser.exe (PID: 6720)
      • browser.exe (PID: 2260)
      • browser.exe (PID: 5708)
      • setup.exe (PID: 7144)
      • browser.exe (PID: 1544)
      • setup.exe (PID: 3532)
      • browser.exe (PID: 1992)
      • browser.exe (PID: 648)
      • browser.exe (PID: 6324)
    • Creates a writable file in the system directory

      • service_update.exe (PID: 1376)
    • Changes the autorun value in the registry

      • browser.exe (PID: 6324)
    • Steals credentials from Web Browsers

      • browser.exe (PID: 6324)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 7068)
      • setup.exe (PID: 2860)
      • service_update.exe (PID: 3824)
      • explorer.exe (PID: 2648)
      • Yandex.exe (PID: 2064)
      • explorer.exe (PID: 6864)
    • Reads the date of Windows installation

      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 7068)
      • service_update.exe (PID: 3824)
      • explorer.exe (PID: 2648)
      • Yandex.exe (PID: 2064)
      • explorer.exe (PID: 6864)
    • Application launched itself

      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 7068)
      • setup.exe (PID: 2860)
      • service_update.exe (PID: 1376)
      • service_update.exe (PID: 6544)
      • explorer.exe (PID: 2648)
      • browser.exe (PID: 6324)
      • setup.exe (PID: 7144)
    • Starts application with an unusual extension

      • Yandex.exe (PID: 3780)
    • Checks Windows Trust Settings

      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 2860)
      • explorer.exe (PID: 2648)
    • Executable content was dropped or overwritten

      • ybF544.tmp (PID: 6988)
      • setup.exe (PID: 2860)
      • service_update.exe (PID: 3824)
      • Yandex.exe (PID: 2064)
    • Starts itself from another location

      • service_update.exe (PID: 3824)
      • setup.exe (PID: 2860)
      • Yandex.exe (PID: 2064)
    • Adds/modifies Windows certificates

      • setup.exe (PID: 2860)
      • explorer.exe (PID: 2648)
    • Executes as Windows Service

      • service_update.exe (PID: 1376)
    • Searches for installed software

      • setup.exe (PID: 2860)
    • The process creates files with name similar to system file names

      • setup.exe (PID: 2860)
      • Yandex.exe (PID: 2064)
    • Creates a software uninstall entry

      • setup.exe (PID: 2860)
      • Yandex.exe (PID: 2064)
    • Reads Mozilla Firefox installation path

      • browser.exe (PID: 6324)
  • INFO

    • Checks proxy server information

      • Yandex.exe (PID: 2992)
      • slui.exe (PID: 6504)
      • setup.exe (PID: 2860)
      • browser.exe (PID: 6324)
    • Reads the computer name

      • Yandex.exe (PID: 2992)
      • ybF544.tmp (PID: 6988)
      • setup.exe (PID: 7068)
      • setup.exe (PID: 2860)
      • service_update.exe (PID: 3824)
      • service_update.exe (PID: 6348)
      • service_update.exe (PID: 1376)
      • service_update.exe (PID: 6544)
      • service_update.exe (PID: 2452)
      • explorer.exe (PID: 2648)
      • Yandex.exe (PID: 2064)
      • explorer.exe (PID: 6864)
      • clidmgr.exe (PID: 5888)
      • browser.exe (PID: 6324)
      • clidmgr.exe (PID: 2216)
      • browser.exe (PID: 5940)
      • browser.exe (PID: 3156)
      • browser.exe (PID: 3660)
      • browser.exe (PID: 368)
      • setup.exe (PID: 7144)
      • browser.exe (PID: 6720)
    • Creates files or folders in the user directory

      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 5524)
      • setup.exe (PID: 2860)
      • explorer.exe (PID: 2648)
      • Yandex.exe (PID: 2064)
      • explorer.exe (PID: 6864)
      • clidmgr.exe (PID: 5888)
      • browser.exe (PID: 6324)
      • browser.exe (PID: 3660)
      • setup.exe (PID: 7144)
    • Process checks computer location settings

      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 7068)
      • service_update.exe (PID: 3824)
      • explorer.exe (PID: 2648)
      • Yandex.exe (PID: 2064)
      • explorer.exe (PID: 6864)
      • browser.exe (PID: 6324)
      • browser.exe (PID: 2260)
      • browser.exe (PID: 5316)
      • browser.exe (PID: 1992)
    • Checks supported languages

      • Yandex.exe (PID: 2992)
      • Yandex.exe (PID: 3780)
      • ybF544.tmp (PID: 6988)
      • setup.exe (PID: 7068)
      • setup.exe (PID: 5524)
      • setup.exe (PID: 2860)
      • service_update.exe (PID: 3824)
      • service_update.exe (PID: 1376)
      • service_update.exe (PID: 3508)
      • service_update.exe (PID: 6544)
      • service_update.exe (PID: 2452)
      • service_update.exe (PID: 6348)
      • explorer.exe (PID: 2648)
      • explorer.exe (PID: 7136)
      • Yandex.exe (PID: 2064)
      • explorer.exe (PID: 6864)
      • clidmgr.exe (PID: 5888)
      • clidmgr.exe (PID: 2216)
      • browser.exe (PID: 6044)
      • browser.exe (PID: 6324)
      • browser.exe (PID: 3932)
      • browser.exe (PID: 3660)
      • browser.exe (PID: 2032)
      • browser.exe (PID: 368)
      • browser.exe (PID: 3156)
      • browser.exe (PID: 5940)
      • browser.exe (PID: 5316)
      • browser.exe (PID: 6720)
      • browser.exe (PID: 5708)
      • browser.exe (PID: 2260)
      • setup.exe (PID: 3532)
      • browser.exe (PID: 1992)
      • browser.exe (PID: 648)
      • setup.exe (PID: 7144)
      • browser.exe (PID: 1544)
    • Create files in a temporary directory

      • Yandex.exe (PID: 2992)
      • ybF544.tmp (PID: 6988)
      • setup.exe (PID: 7068)
      • setup.exe (PID: 2860)
      • Yandex.exe (PID: 2064)
      • browser.exe (PID: 6324)
      • browser.exe (PID: 6720)
    • Reads the machine GUID from the registry

      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 2860)
      • explorer.exe (PID: 2648)
      • browser.exe (PID: 6324)
    • Reads the software policy settings

      • slui.exe (PID: 7124)
      • slui.exe (PID: 6504)
      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 2860)
      • explorer.exe (PID: 2648)
      • browser.exe (PID: 6324)
    • Creates files in the program directory

      • service_update.exe (PID: 3824)
    • Manual execution by a user

      • browser.exe (PID: 6324)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:07:10 12:38:10+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 1106432
InitializedDataSize: 9735680
UninitializedDataSize: -
EntryPoint: 0xdbe30
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 24.6.3.729
ProductVersionNumber: 24.6.3.729
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: YANDEX LLC
FileDescription: Yandex
FileVersion: 24.6.3.729
InternalName: lite_installer
LegalCopyright: Copyright (c) 2012-2024 YANDEX LLC. All Rights Reserved.
ProductName: Yandex
ProductVersion: 24.6.3.729
ProductChromiumVersion: 124.0.6367.243
ProductYandexVersion: 24.6.3.729
CompanyShortName: YANDEX LLC
ProductShortName: Yandex Installer
LastChange: b9d72f9a3142c72437f331cba038933e97726de0
OfficialBuild: 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
180
Monitored processes
40
Malicious processes
35
Suspicious processes
2

Behavior graph

Click at the process to see the details
start yandex.exe yandex.exe sppextcomobj.exe no specs slui.exe slui.exe ybf544.tmp setup.exe no specs setup.exe setup.exe service_update.exe service_update.exe service_update.exe service_update.exe service_update.exe service_update.exe explorer.exe explorer.exe yandex.exe explorer.exe no specs clidmgr.exe conhost.exe clidmgr.exe conhost.exe browser.exe browser.exe browser.exe browser.exe browser.exe browser.exe browser.exe browser.exe browser.exe browser.exe browser.exe browser.exe setup.exe setup.exe browser.exe browser.exe browser.exe

Process information

PID
CMD
Path
Indicators
Parent process
368"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=ru --service-sandbox-type=none --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --no-appcompat-clear --process-name="Video Capture" --field-trial-handle=3484,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=3496 --brver=24.6.3.729 /prefetch:8C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe
browser.exe
User:
admin
Company:
YANDEX LLC
Integrity Level:
MEDIUM
Description:
Yandex with voice assistant Alice
Version:
24.6.3.729
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\yandex\yandexbrowser\application\24.6.3.729\browser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
648"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=ru --service-sandbox-type=service --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --no-appcompat-clear --process-name="Data Decoder Service" --field-trial-handle=2104,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=5444 --brver=24.6.3.729 /prefetch:8C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe
browser.exe
User:
admin
Company:
YANDEX LLC
Integrity Level:
LOW
Description:
Yandex with voice assistant Alice
Exit code:
0
Version:
24.6.3.729
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\yandex\yandexbrowser\application\24.6.3.729\browser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
1060\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe
clidmgr.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1376"C:\Program Files (x86)\Yandex\YandexBrowser\24.6.3.729\service_update.exe" --run-as-serviceC:\Program Files (x86)\Yandex\YandexBrowser\24.6.3.729\service_update.exe
services.exe
User:
SYSTEM
Company:
YANDEX LLC
Integrity Level:
SYSTEM
Description:
Yandex
Version:
24.6.3.729
Modules
Images
c:\program files (x86)\yandex\yandexbrowser\24.6.3.729\service_update.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1544"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=utility --utility-sub-type=uwp_cookie_provider.mojom.UwpCookieProvider --lang=ru --service-sandbox-type=utility --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --no-appcompat-clear --process-name=uwp_cookie_provider.mojom.UwpCookieProvider --field-trial-handle=5580,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=2072 --brver=24.6.3.729 /prefetch:8C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe
browser.exe
User:
admin
Company:
YANDEX LLC
Integrity Level:
LOW
Description:
Yandex with voice assistant Alice
Version:
24.6.3.729
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\yandex\yandexbrowser\application\24.6.3.729\browser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
1992"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=renderer --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --web-ntp-url-for-renderer=https://webntp.yandex.ru/ --translate-security-origin=https://browser.translate.yandex.net/ --enable-instaserp --no-appcompat-clear --lang=ru --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --field-trial-handle=5148,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=4872 /prefetch:1C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe
browser.exe
User:
admin
Company:
YANDEX LLC
Integrity Level:
LOW
Description:
Yandex with voice assistant Alice
Version:
24.6.3.729
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\yandex\yandexbrowser\application\24.6.3.729\browser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\advapi32.dll
2032"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=ru --service-sandbox-type=service --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --no-appcompat-clear --process-name="Storage Service" --field-trial-handle=2848,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=2968 --brver=24.6.3.729 /prefetch:8C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe
browser.exe
User:
admin
Company:
YANDEX LLC
Integrity Level:
LOW
Description:
Yandex with voice assistant Alice
Version:
24.6.3.729
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\yandex\yandexbrowser\application\24.6.3.729\browser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
2064C:\Users\admin\AppData\Local\Yandex\YaPin\Yandex.exe --silentC:\Users\admin\AppData\Local\Yandex\YaPin\Yandex.exe
setup.exe
User:
admin
Integrity Level:
HIGH
Description:
YandexPin
Exit code:
0
Version:
3.7.9.0
Modules
Images
c:\users\admin\appdata\local\yandex\yapin\yandex.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2216"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\clidmgr.exe" --appid=yabrowser --vendor-xml-path="C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Temp\source2860_165440764\Browser-bin\clids_yandex.xml"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\clidmgr.exe
setup.exe
User:
admin
Company:
Yandex
Integrity Level:
HIGH
Description:
ClidManagerModule
Exit code:
0
Version:
1,0,0,44
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\clidmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2260"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=renderer --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --extension-process --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --web-ntp-url-for-renderer=https://webntp.yandex.ru/ --translate-security-origin=https://browser.translate.yandex.net/ --enable-instaserp --no-appcompat-clear --allow-prefetch --lang=ru --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --field-trial-handle=3784,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=3780 /prefetch:2C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe
browser.exe
User:
admin
Company:
YANDEX LLC
Integrity Level:
LOW
Description:
Yandex with voice assistant Alice
Version:
24.6.3.729
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\yandex\yandexbrowser\application\24.6.3.729\browser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\advapi32.dll
Total events
44 401
Read events
43 508
Write events
791
Delete events
102

Modification events

(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\AppDataLow\Yandex
Operation:writeName:UICreated_admin
Value:
1
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:writeName:DistribInfoParams
Value:
win10pin=1&vup=1&browser=EdgeChromium/64/126.0.0&banerid=6400000000:6692cc2847d2731fe89dc615&bitness=64&def=1&statpromo=true&yandexuid=5671459881720896523&mongoID=6692cc2847d2731fe89dc615&pps=installID%3D5671459881720896523_1720896552422%26mongoID%3D6692cc2847d2731fe89dc615&download_date=1720896552
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:delete valueName:brand
Value:
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:delete valueName:BrandFile
Value:
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:delete valueName:PartnerFile
Value:
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:writeName:lang
Value:
ru
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:writeName:InstallerData
Value:
C:\Users\admin\AppData\Local\Temp\master_preferences
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:writeName:ClidsFile
Value:
C:\Users\admin\AppData\Local\Temp\clids.xml
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:writeName:YandexWebsiteIconFile
Value:
C:\Users\admin\AppData\Local\Temp\website.ico
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:writeName:AbtConfigResourceFile
Value:
C:\Users\admin\AppData\Local\Temp\abt_config_resource
Executable files
12
Suspicious files
264
Text files
132
Unknown types
32

Dropped files

PID
Process
Filename
Type
2992Yandex.exeC:\Users\admin\AppData\Local\Temp\website.ico
MD5:
SHA256:
2992Yandex.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B039FEA45CB4CC4BBACFC013C7C55604_50D7940D5D3FEDD8634D83074C7A46A3der
MD5:AB5877308272DA0D2179321B6AB0E305
SHA256:7E59918F5CFB8A790951BAFEBC43B8C656527620B5460C750256194E81B1EF43
2992Yandex.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0DA515F703BB9B49479E8697ADB0B955_7DAD5545724AA2C98C55095F428499FBder
MD5:6F2A874CCE4BB2C3A26F10B294DB75E8
SHA256:57F0D9FBFEABF6F5DE7624EF1D73D0DA76EBCF950545AF8B6DFBAB55B88E1390
2992Yandex.exeC:\Users\admin\AppData\Local\Temp\clids.xmlxml
MD5:94767E5BD3C7D598C990DCBA9E0ABF8B
SHA256:E1F801C2623ECA1D2EF8C5BEB325B64D3EECD2A36E92E8C2BCFCF9315F9773AF
2992Yandex.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\66F835E41EC6A985EB9271E4A70169D7_CF44E3C99F7F4AC558EEB35244F7E046der
MD5:3D7D74560BD0AD12988D2C75AAD53EEA
SHA256:F21D3B888EFEFED33892DAB4B22FEE974C8F86EAEE864D72F5A19EF60C547EE0
2992Yandex.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0DA515F703BB9B49479E8697ADB0B955_4136D3715888E22D65EBE484B233D81Bder
MD5:78FD56A8B79B5860484CFC19F18B0CCB
SHA256:B7CD1BEC3682718BA966CE7D27572BC998CF83616160DA69BC60B02E41CC5FEB
2992Yandex.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0DA515F703BB9B49479E8697ADB0B955_4136D3715888E22D65EBE484B233D81Bbinary
MD5:83D04575C4A2FC6184B0D1EC6653DC1C
SHA256:F18E6DED96509181951F85FD69A02B4504E9999A1F316FCCBBAD504EBB8456B4
2992Yandex.exeC:\Users\admin\AppData\Local\Temp\master_preferencesbinary
MD5:DCA3CACDD7B0D9DBE1F527D6541F6176
SHA256:46A81699619BA59256404D73A3815D402748C91574619728FF924101E84BE92E
2992Yandex.exeC:\Users\admin\AppData\Local\Temp\lite_installer.logtext
MD5:BA9D765DBC5CBA326FD7826EA5C5233C
SHA256:AB2F70B76F74572DB5E508206E492D1D2A862F55CF096B6D801FA539F87DAA9A
2992Yandex.exeC:\Users\admin\AppData\Roaming\Yandex\uitext
MD5:249A8807FFBBFC46D197CD1E786E5235
SHA256:E1EE6F4AD9075630671E92AA00D6A58C5E83CFF9FDEF687A3600B68A5CFB2FA8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
23
TCP/UDP connections
108
DNS requests
39
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2992
Yandex.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHUeP1PjGFkz6V8I7O6tApc%3D
unknown
whitelisted
2992
Yandex.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCDQHuXxad%2F5c1K2Rl1mo%3D
unknown
whitelisted
2992
Yandex.exe
GET
200
104.18.21.226:80
http://ocsp2.globalsign.com/rootr5/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQiD0S5cIHyfrLTJ1fvAkJWflH%2B2QQUPeYpSJvqB8ohREom3m7e0oPQn1kCDQHuXyKVQkkF%2BQGRqNw%3D
unknown
whitelisted
2992
Yandex.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCDQHuXxad%2F5c1K2Rl1mo%3D
unknown
whitelisted
2992
Yandex.exe
GET
200
104.18.21.226:80
http://ocsp2.globalsign.com/rootr3/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCDQHuXyId%2FGI71DM6hVc%3D
unknown
whitelisted
2992
Yandex.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gseccovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBSTMjK03nNiYoQYvu4Izyfn9OJNdAQUWHuOdSr%2BYYCqkEABrtboB0ZuP0gCDA3dnOhPx5IoBNEilQ%3D%3D
unknown
whitelisted
2992
Yandex.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsrsaovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT%2BanRD3C1tW3nsrKeuXC7DPwQU%2BO9%2F8s14Z6jeb48kjYjxhwMCs%2BsCDDrrc53tnvLvSvE9AA%3D%3D
unknown
whitelisted
2992
Yandex.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsrsaovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT%2BanRD3C1tW3nsrKeuXC7DPwQU%2BO9%2F8s14Z6jeb48kjYjxhwMCs%2BsCDAhWWiYI5dhngnR%2BOQ%3D%3D
unknown
whitelisted
6116
svchost.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6116
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6116
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4032
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
2252
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2248
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2992
Yandex.exe
213.180.193.234:443
api.browser.yandex.net
YANDEX LLC
RU
whitelisted
2992
Yandex.exe
5.45.205.244:443
download.cdn.yandex.net
YANDEX LLC
RU
whitelisted
2992
Yandex.exe
104.18.20.226:80
ocsp.globalsign.com
CLOUDFLARENET
shared
2992
Yandex.exe
104.18.21.226:80
ocsp.globalsign.com
CLOUDFLARENET
shared

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.186.174
whitelisted
api.browser.yandex.net
  • 213.180.193.234
whitelisted
download.cdn.yandex.net
  • 5.45.205.244
  • 5.45.205.242
  • 5.45.205.243
  • 5.45.205.245
  • 5.45.205.241
whitelisted
api.browser.yandex.ru
  • 213.180.193.234
whitelisted
ocsp.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
ocsp2.globalsign.com
  • 104.18.21.226
  • 104.18.20.226
whitelisted
cachev2-ams01.cdn.yandex.net
  • 5.45.247.51
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 88.221.169.152
whitelisted

Threats

No threats detected
Process
Message
clidmgr.exe
GetLoggedCreds_WTSSessionInfo(): szUserName = admin, szDomain = DESKTOP-JGLLJLD, dwSessionId = 1
clidmgr.exe
GetSidFromEnumSess(): i = 0 : szUserName = Administrator, szDomain = DESKTOP-JGLLJLD, dwSessionId = 0
clidmgr.exe
GetSidFromEnumSess(): ProfileImagePath(1) = C:\Users\admin
clidmgr.exe
GetSidFromEnumSess(): LsaEnumerateLogonSessions() lpszSid = S-1-5-21-1693682860-607145093-2874071422-1001
clidmgr.exe
GetLoggedCreds_WTSSessionInfo(): szUserName = admin, szDomain = DESKTOP-JGLLJLD, dwSessionId = 1
clidmgr.exe
GetSidFromEnumSess(): i = 0 : szUserName = Administrator, szDomain = DESKTOP-JGLLJLD, dwSessionId = 0
clidmgr.exe
GetSidFromEnumSess(): ProfileImagePath(1) = C:\Users\admin
clidmgr.exe
GetSidFromEnumSess(): LsaEnumerateLogonSessions() lpszSid = S-1-5-21-1693682860-607145093-2874071422-1001