| File name: | Yandex.exe |
| Full analysis: | https://app.any.run/tasks/3e0502e7-6886-490e-a848-8f92d4b93e80 |
| Verdict: | Malicious activity |
| Analysis date: | July 13, 2024, 18:51:13 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 28EE3C895BE2B8771C06C2820D364B0F |
| SHA1: | 78B61EDEF642DAE3A6C8BD5BEF2C59C5CAEF5879 |
| SHA256: | B7ADE1749F7FCA0D886338D6EAA528530CE36237B46AB47CCD20D736E0B8E748 |
| SSDEEP: | 98304:TnbajsQOZzu2AvkuT9DcXr0SPAizoxcUfXto6qprqgYBHJbpcWSLQIJZmX1RuEW2:sxRx9w14mwAS/ |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:07:10 12:38:10+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 1106432 |
| InitializedDataSize: | 9735680 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xdbe30 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 24.6.3.729 |
| ProductVersionNumber: | 24.6.3.729 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | YANDEX LLC |
| FileDescription: | Yandex |
| FileVersion: | 24.6.3.729 |
| InternalName: | lite_installer |
| LegalCopyright: | Copyright (c) 2012-2024 YANDEX LLC. All Rights Reserved. |
| ProductName: | Yandex |
| ProductVersion: | 24.6.3.729 |
| ProductChromiumVersion: | 124.0.6367.243 |
| ProductYandexVersion: | 24.6.3.729 |
| CompanyShortName: | YANDEX LLC |
| ProductShortName: | Yandex Installer |
| LastChange: | b9d72f9a3142c72437f331cba038933e97726de0 |
| OfficialBuild: | 1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 368 | "C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=ru --service-sandbox-type=none --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --no-appcompat-clear --process-name="Video Capture" --field-trial-handle=3484,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=3496 --brver=24.6.3.729 /prefetch:8 | C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe | browser.exe | ||||||||||||
User: admin Company: YANDEX LLC Integrity Level: MEDIUM Description: Yandex with voice assistant Alice Version: 24.6.3.729 Modules
| |||||||||||||||
| 648 | "C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=ru --service-sandbox-type=service --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --no-appcompat-clear --process-name="Data Decoder Service" --field-trial-handle=2104,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=5444 --brver=24.6.3.729 /prefetch:8 | C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe | browser.exe | ||||||||||||
User: admin Company: YANDEX LLC Integrity Level: LOW Description: Yandex with voice assistant Alice Exit code: 0 Version: 24.6.3.729 Modules
| |||||||||||||||
| 1060 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | clidmgr.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1376 | "C:\Program Files (x86)\Yandex\YandexBrowser\24.6.3.729\service_update.exe" --run-as-service | C:\Program Files (x86)\Yandex\YandexBrowser\24.6.3.729\service_update.exe | services.exe | ||||||||||||
User: SYSTEM Company: YANDEX LLC Integrity Level: SYSTEM Description: Yandex Version: 24.6.3.729 Modules
| |||||||||||||||
| 1544 | "C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=utility --utility-sub-type=uwp_cookie_provider.mojom.UwpCookieProvider --lang=ru --service-sandbox-type=utility --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --no-appcompat-clear --process-name=uwp_cookie_provider.mojom.UwpCookieProvider --field-trial-handle=5580,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=2072 --brver=24.6.3.729 /prefetch:8 | C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe | browser.exe | ||||||||||||
User: admin Company: YANDEX LLC Integrity Level: LOW Description: Yandex with voice assistant Alice Version: 24.6.3.729 Modules
| |||||||||||||||
| 1992 | "C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=renderer --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --web-ntp-url-for-renderer=https://webntp.yandex.ru/ --translate-security-origin=https://browser.translate.yandex.net/ --enable-instaserp --no-appcompat-clear --lang=ru --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --field-trial-handle=5148,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=4872 /prefetch:1 | C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe | browser.exe | ||||||||||||
User: admin Company: YANDEX LLC Integrity Level: LOW Description: Yandex with voice assistant Alice Version: 24.6.3.729 Modules
| |||||||||||||||
| 2032 | "C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=ru --service-sandbox-type=service --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --no-appcompat-clear --process-name="Storage Service" --field-trial-handle=2848,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=2968 --brver=24.6.3.729 /prefetch:8 | C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe | browser.exe | ||||||||||||
User: admin Company: YANDEX LLC Integrity Level: LOW Description: Yandex with voice assistant Alice Version: 24.6.3.729 Modules
| |||||||||||||||
| 2064 | C:\Users\admin\AppData\Local\Yandex\YaPin\Yandex.exe --silent | C:\Users\admin\AppData\Local\Yandex\YaPin\Yandex.exe | setup.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: YandexPin Exit code: 0 Version: 3.7.9.0 Modules
| |||||||||||||||
| 2216 | "C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\clidmgr.exe" --appid=yabrowser --vendor-xml-path="C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Temp\source2860_165440764\Browser-bin\clids_yandex.xml" | C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\clidmgr.exe | setup.exe | ||||||||||||
User: admin Company: Yandex Integrity Level: HIGH Description: ClidManagerModule Exit code: 0 Version: 1,0,0,44 Modules
| |||||||||||||||
| 2260 | "C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=renderer --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --extension-process --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --web-ntp-url-for-renderer=https://webntp.yandex.ru/ --translate-security-origin=https://browser.translate.yandex.net/ --enable-instaserp --no-appcompat-clear --allow-prefetch --lang=ru --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --field-trial-handle=3784,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=3780 /prefetch:2 | C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe | browser.exe | ||||||||||||
User: admin Company: YANDEX LLC Integrity Level: LOW Description: Yandex with voice assistant Alice Version: 24.6.3.729 Modules
| |||||||||||||||
| (PID) Process: | (2992) Yandex.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\AppDataLow\Yandex |
| Operation: | write | Name: | UICreated_admin |
Value: 1 | |||
| (PID) Process: | (2992) Yandex.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser |
| Operation: | write | Name: | DistribInfoParams |
Value: win10pin=1&vup=1&browser=EdgeChromium/64/126.0.0&banerid=6400000000:6692cc2847d2731fe89dc615&bitness=64&def=1&statpromo=true&yandexuid=5671459881720896523&mongoID=6692cc2847d2731fe89dc615&pps=installID%3D5671459881720896523_1720896552422%26mongoID%3D6692cc2847d2731fe89dc615&download_date=1720896552 | |||
| (PID) Process: | (2992) Yandex.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser |
| Operation: | delete value | Name: | brand |
Value: | |||
| (PID) Process: | (2992) Yandex.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser |
| Operation: | delete value | Name: | BrandFile |
Value: | |||
| (PID) Process: | (2992) Yandex.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser |
| Operation: | delete value | Name: | PartnerFile |
Value: | |||
| (PID) Process: | (2992) Yandex.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser |
| Operation: | write | Name: | lang |
Value: ru | |||
| (PID) Process: | (2992) Yandex.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser |
| Operation: | write | Name: | InstallerData |
Value: C:\Users\admin\AppData\Local\Temp\master_preferences | |||
| (PID) Process: | (2992) Yandex.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser |
| Operation: | write | Name: | ClidsFile |
Value: C:\Users\admin\AppData\Local\Temp\clids.xml | |||
| (PID) Process: | (2992) Yandex.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser |
| Operation: | write | Name: | YandexWebsiteIconFile |
Value: C:\Users\admin\AppData\Local\Temp\website.ico | |||
| (PID) Process: | (2992) Yandex.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser |
| Operation: | write | Name: | AbtConfigResourceFile |
Value: C:\Users\admin\AppData\Local\Temp\abt_config_resource | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2992 | Yandex.exe | C:\Users\admin\AppData\Local\Temp\website.ico | — | |
MD5:— | SHA256:— | |||
| 2992 | Yandex.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B039FEA45CB4CC4BBACFC013C7C55604_50D7940D5D3FEDD8634D83074C7A46A3 | der | |
MD5:AB5877308272DA0D2179321B6AB0E305 | SHA256:7E59918F5CFB8A790951BAFEBC43B8C656527620B5460C750256194E81B1EF43 | |||
| 2992 | Yandex.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0DA515F703BB9B49479E8697ADB0B955_7DAD5545724AA2C98C55095F428499FB | der | |
MD5:6F2A874CCE4BB2C3A26F10B294DB75E8 | SHA256:57F0D9FBFEABF6F5DE7624EF1D73D0DA76EBCF950545AF8B6DFBAB55B88E1390 | |||
| 2992 | Yandex.exe | C:\Users\admin\AppData\Local\Temp\clids.xml | xml | |
MD5:94767E5BD3C7D598C990DCBA9E0ABF8B | SHA256:E1F801C2623ECA1D2EF8C5BEB325B64D3EECD2A36E92E8C2BCFCF9315F9773AF | |||
| 2992 | Yandex.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\66F835E41EC6A985EB9271E4A70169D7_CF44E3C99F7F4AC558EEB35244F7E046 | der | |
MD5:3D7D74560BD0AD12988D2C75AAD53EEA | SHA256:F21D3B888EFEFED33892DAB4B22FEE974C8F86EAEE864D72F5A19EF60C547EE0 | |||
| 2992 | Yandex.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0DA515F703BB9B49479E8697ADB0B955_4136D3715888E22D65EBE484B233D81B | der | |
MD5:78FD56A8B79B5860484CFC19F18B0CCB | SHA256:B7CD1BEC3682718BA966CE7D27572BC998CF83616160DA69BC60B02E41CC5FEB | |||
| 2992 | Yandex.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0DA515F703BB9B49479E8697ADB0B955_4136D3715888E22D65EBE484B233D81B | binary | |
MD5:83D04575C4A2FC6184B0D1EC6653DC1C | SHA256:F18E6DED96509181951F85FD69A02B4504E9999A1F316FCCBBAD504EBB8456B4 | |||
| 2992 | Yandex.exe | C:\Users\admin\AppData\Local\Temp\master_preferences | binary | |
MD5:DCA3CACDD7B0D9DBE1F527D6541F6176 | SHA256:46A81699619BA59256404D73A3815D402748C91574619728FF924101E84BE92E | |||
| 2992 | Yandex.exe | C:\Users\admin\AppData\Local\Temp\lite_installer.log | text | |
MD5:BA9D765DBC5CBA326FD7826EA5C5233C | SHA256:AB2F70B76F74572DB5E508206E492D1D2A862F55CF096B6D801FA539F87DAA9A | |||
| 2992 | Yandex.exe | C:\Users\admin\AppData\Roaming\Yandex\ui | text | |
MD5:249A8807FFBBFC46D197CD1E786E5235 | SHA256:E1EE6F4AD9075630671E92AA00D6A58C5E83CFF9FDEF687A3600B68A5CFB2FA8 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2992 | Yandex.exe | GET | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/rootr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHUeP1PjGFkz6V8I7O6tApc%3D | unknown | — | — | whitelisted |
2992 | Yandex.exe | GET | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/rootr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCDQHuXxad%2F5c1K2Rl1mo%3D | unknown | — | — | whitelisted |
2992 | Yandex.exe | GET | 200 | 104.18.21.226:80 | http://ocsp2.globalsign.com/rootr5/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQiD0S5cIHyfrLTJ1fvAkJWflH%2B2QQUPeYpSJvqB8ohREom3m7e0oPQn1kCDQHuXyKVQkkF%2BQGRqNw%3D | unknown | — | — | whitelisted |
2992 | Yandex.exe | GET | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/rootr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCDQHuXxad%2F5c1K2Rl1mo%3D | unknown | — | — | whitelisted |
2992 | Yandex.exe | GET | 200 | 104.18.21.226:80 | http://ocsp2.globalsign.com/rootr3/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCDQHuXyId%2FGI71DM6hVc%3D | unknown | — | — | whitelisted |
2992 | Yandex.exe | GET | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/gseccovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBSTMjK03nNiYoQYvu4Izyfn9OJNdAQUWHuOdSr%2BYYCqkEABrtboB0ZuP0gCDA3dnOhPx5IoBNEilQ%3D%3D | unknown | — | — | whitelisted |
2992 | Yandex.exe | GET | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/gsrsaovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT%2BanRD3C1tW3nsrKeuXC7DPwQU%2BO9%2F8s14Z6jeb48kjYjxhwMCs%2BsCDDrrc53tnvLvSvE9AA%3D%3D | unknown | — | — | whitelisted |
2992 | Yandex.exe | GET | 200 | 104.18.20.226:80 | http://ocsp.globalsign.com/gsrsaovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT%2BanRD3C1tW3nsrKeuXC7DPwQU%2BO9%2F8s14Z6jeb48kjYjxhwMCs%2BsCDAhWWiYI5dhngnR%2BOQ%3D%3D | unknown | — | — | whitelisted |
6116 | svchost.exe | GET | 200 | 23.48.23.156:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6116 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
6116 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4032 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2252 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2248 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2992 | Yandex.exe | 213.180.193.234:443 | api.browser.yandex.net | YANDEX LLC | RU | whitelisted |
2992 | Yandex.exe | 5.45.205.244:443 | download.cdn.yandex.net | YANDEX LLC | RU | whitelisted |
2992 | Yandex.exe | 104.18.20.226:80 | ocsp.globalsign.com | CLOUDFLARENET | — | shared |
2992 | Yandex.exe | 104.18.21.226:80 | ocsp.globalsign.com | CLOUDFLARENET | — | shared |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
api.browser.yandex.net |
| whitelisted |
download.cdn.yandex.net |
| whitelisted |
api.browser.yandex.ru |
| whitelisted |
ocsp.globalsign.com |
| whitelisted |
ocsp2.globalsign.com |
| whitelisted |
cachev2-ams01.cdn.yandex.net |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
clidmgr.exe | GetLoggedCreds_WTSSessionInfo(): szUserName = admin, szDomain = DESKTOP-JGLLJLD, dwSessionId = 1
|
clidmgr.exe | GetSidFromEnumSess(): i = 0 : szUserName = Administrator, szDomain = DESKTOP-JGLLJLD, dwSessionId = 0
|
clidmgr.exe | GetSidFromEnumSess(): ProfileImagePath(1) = C:\Users\admin
|
clidmgr.exe | GetSidFromEnumSess(): LsaEnumerateLogonSessions() lpszSid = S-1-5-21-1693682860-607145093-2874071422-1001
|
clidmgr.exe | GetLoggedCreds_WTSSessionInfo(): szUserName = admin, szDomain = DESKTOP-JGLLJLD, dwSessionId = 1
|
clidmgr.exe | GetSidFromEnumSess(): i = 0 : szUserName = Administrator, szDomain = DESKTOP-JGLLJLD, dwSessionId = 0
|
clidmgr.exe | GetSidFromEnumSess(): ProfileImagePath(1) = C:\Users\admin
|
clidmgr.exe | GetSidFromEnumSess(): LsaEnumerateLogonSessions() lpszSid = S-1-5-21-1693682860-607145093-2874071422-1001
|