File name:

Yandex.exe

Full analysis: https://app.any.run/tasks/3e0502e7-6886-490e-a848-8f92d4b93e80
Verdict: Malicious activity
Analysis date: July 13, 2024, 18:51:13
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

28EE3C895BE2B8771C06C2820D364B0F

SHA1:

78B61EDEF642DAE3A6C8BD5BEF2C59C5CAEF5879

SHA256:

B7ADE1749F7FCA0D886338D6EAA528530CE36237B46AB47CCD20D736E0B8E748

SSDEEP:

98304:TnbajsQOZzu2AvkuT9DcXr0SPAizoxcUfXto6qprqgYBHJbpcWSLQIJZmX1RuEW2:sxRx9w14mwAS/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Yandex.exe (PID: 2992)
      • ybF544.tmp (PID: 6988)
      • service_update.exe (PID: 3824)
      • setup.exe (PID: 2860)
      • Yandex.exe (PID: 2064)
    • Actions looks like stealing of personal data

      • setup.exe (PID: 5524)
      • service_update.exe (PID: 3824)
      • service_update.exe (PID: 6348)
      • service_update.exe (PID: 3508)
      • service_update.exe (PID: 1376)
      • service_update.exe (PID: 6544)
      • service_update.exe (PID: 2452)
      • explorer.exe (PID: 7136)
      • setup.exe (PID: 2860)
      • explorer.exe (PID: 2648)
      • conhost.exe (PID: 4780)
      • conhost.exe (PID: 1060)
      • clidmgr.exe (PID: 2216)
      • clidmgr.exe (PID: 5888)
      • browser.exe (PID: 6044)
      • browser.exe (PID: 5940)
      • browser.exe (PID: 2032)
      • browser.exe (PID: 3932)
      • browser.exe (PID: 368)
      • browser.exe (PID: 5708)
      • browser.exe (PID: 3156)
      • browser.exe (PID: 5316)
      • browser.exe (PID: 2260)
      • browser.exe (PID: 6720)
      • browser.exe (PID: 3660)
      • browser.exe (PID: 1992)
      • setup.exe (PID: 7144)
      • setup.exe (PID: 3532)
      • browser.exe (PID: 648)
      • browser.exe (PID: 1544)
      • browser.exe (PID: 6324)
    • Creates a writable file in the system directory

      • service_update.exe (PID: 1376)
    • Changes the autorun value in the registry

      • browser.exe (PID: 6324)
    • Steals credentials from Web Browsers

      • browser.exe (PID: 6324)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 7068)
      • setup.exe (PID: 2860)
      • service_update.exe (PID: 3824)
      • explorer.exe (PID: 2648)
      • Yandex.exe (PID: 2064)
      • explorer.exe (PID: 6864)
    • Reads the date of Windows installation

      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 7068)
      • service_update.exe (PID: 3824)
      • explorer.exe (PID: 2648)
      • Yandex.exe (PID: 2064)
      • explorer.exe (PID: 6864)
    • Executable content was dropped or overwritten

      • ybF544.tmp (PID: 6988)
      • service_update.exe (PID: 3824)
      • setup.exe (PID: 2860)
      • Yandex.exe (PID: 2064)
    • Application launched itself

      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 2860)
      • setup.exe (PID: 7068)
      • service_update.exe (PID: 1376)
      • service_update.exe (PID: 6544)
      • explorer.exe (PID: 2648)
      • browser.exe (PID: 6324)
      • setup.exe (PID: 7144)
    • Checks Windows Trust Settings

      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 2860)
      • explorer.exe (PID: 2648)
    • Starts application with an unusual extension

      • Yandex.exe (PID: 3780)
    • Starts itself from another location

      • service_update.exe (PID: 3824)
      • setup.exe (PID: 2860)
      • Yandex.exe (PID: 2064)
    • Adds/modifies Windows certificates

      • setup.exe (PID: 2860)
      • explorer.exe (PID: 2648)
    • Executes as Windows Service

      • service_update.exe (PID: 1376)
    • The process creates files with name similar to system file names

      • Yandex.exe (PID: 2064)
      • setup.exe (PID: 2860)
    • Creates a software uninstall entry

      • Yandex.exe (PID: 2064)
      • setup.exe (PID: 2860)
    • Reads Mozilla Firefox installation path

      • browser.exe (PID: 6324)
    • Searches for installed software

      • setup.exe (PID: 2860)
  • INFO

    • Checks supported languages

      • Yandex.exe (PID: 2992)
      • Yandex.exe (PID: 3780)
      • setup.exe (PID: 7068)
      • ybF544.tmp (PID: 6988)
      • setup.exe (PID: 5524)
      • setup.exe (PID: 2860)
      • service_update.exe (PID: 6348)
      • service_update.exe (PID: 1376)
      • service_update.exe (PID: 3824)
      • service_update.exe (PID: 3508)
      • service_update.exe (PID: 6544)
      • service_update.exe (PID: 2452)
      • explorer.exe (PID: 2648)
      • explorer.exe (PID: 7136)
      • Yandex.exe (PID: 2064)
      • explorer.exe (PID: 6864)
      • clidmgr.exe (PID: 5888)
      • clidmgr.exe (PID: 2216)
      • browser.exe (PID: 6324)
      • browser.exe (PID: 6044)
      • browser.exe (PID: 5940)
      • browser.exe (PID: 3660)
      • browser.exe (PID: 2032)
      • browser.exe (PID: 3932)
      • browser.exe (PID: 3156)
      • browser.exe (PID: 5708)
      • browser.exe (PID: 2260)
      • browser.exe (PID: 368)
      • browser.exe (PID: 5316)
      • browser.exe (PID: 6720)
      • setup.exe (PID: 3532)
      • setup.exe (PID: 7144)
      • browser.exe (PID: 1992)
      • browser.exe (PID: 648)
      • browser.exe (PID: 1544)
    • Creates files or folders in the user directory

      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 5524)
      • setup.exe (PID: 2860)
      • explorer.exe (PID: 2648)
      • Yandex.exe (PID: 2064)
      • explorer.exe (PID: 6864)
      • clidmgr.exe (PID: 5888)
      • browser.exe (PID: 6324)
      • browser.exe (PID: 3660)
      • setup.exe (PID: 7144)
    • Reads the computer name

      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 7068)
      • ybF544.tmp (PID: 6988)
      • setup.exe (PID: 2860)
      • service_update.exe (PID: 6348)
      • service_update.exe (PID: 3824)
      • service_update.exe (PID: 6544)
      • service_update.exe (PID: 2452)
      • service_update.exe (PID: 1376)
      • Yandex.exe (PID: 2064)
      • explorer.exe (PID: 2648)
      • explorer.exe (PID: 6864)
      • clidmgr.exe (PID: 5888)
      • clidmgr.exe (PID: 2216)
      • browser.exe (PID: 6324)
      • browser.exe (PID: 5940)
      • browser.exe (PID: 3660)
      • browser.exe (PID: 3156)
      • browser.exe (PID: 6720)
      • browser.exe (PID: 368)
      • setup.exe (PID: 7144)
    • Checks proxy server information

      • Yandex.exe (PID: 2992)
      • slui.exe (PID: 6504)
      • setup.exe (PID: 2860)
      • browser.exe (PID: 6324)
    • Process checks computer location settings

      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 7068)
      • service_update.exe (PID: 3824)
      • explorer.exe (PID: 2648)
      • Yandex.exe (PID: 2064)
      • explorer.exe (PID: 6864)
      • browser.exe (PID: 6324)
      • browser.exe (PID: 2260)
      • browser.exe (PID: 5316)
      • browser.exe (PID: 1992)
    • Create files in a temporary directory

      • Yandex.exe (PID: 2992)
      • ybF544.tmp (PID: 6988)
      • setup.exe (PID: 7068)
      • setup.exe (PID: 2860)
      • Yandex.exe (PID: 2064)
      • browser.exe (PID: 6324)
      • browser.exe (PID: 6720)
    • Reads the machine GUID from the registry

      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 2860)
      • explorer.exe (PID: 2648)
      • browser.exe (PID: 6324)
    • Reads the software policy settings

      • slui.exe (PID: 7124)
      • Yandex.exe (PID: 2992)
      • slui.exe (PID: 6504)
      • setup.exe (PID: 2860)
      • explorer.exe (PID: 2648)
      • browser.exe (PID: 6324)
    • Creates files in the program directory

      • service_update.exe (PID: 3824)
    • Manual execution by a user

      • browser.exe (PID: 6324)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:07:10 12:38:10+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 1106432
InitializedDataSize: 9735680
UninitializedDataSize: -
EntryPoint: 0xdbe30
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 24.6.3.729
ProductVersionNumber: 24.6.3.729
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: YANDEX LLC
FileDescription: Yandex
FileVersion: 24.6.3.729
InternalName: lite_installer
LegalCopyright: Copyright (c) 2012-2024 YANDEX LLC. All Rights Reserved.
ProductName: Yandex
ProductVersion: 24.6.3.729
ProductChromiumVersion: 124.0.6367.243
ProductYandexVersion: 24.6.3.729
CompanyShortName: YANDEX LLC
ProductShortName: Yandex Installer
LastChange: b9d72f9a3142c72437f331cba038933e97726de0
OfficialBuild: 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
180
Monitored processes
40
Malicious processes
35
Suspicious processes
2

Behavior graph

Click at the process to see the details
start yandex.exe yandex.exe sppextcomobj.exe no specs slui.exe slui.exe ybf544.tmp setup.exe no specs setup.exe setup.exe service_update.exe service_update.exe service_update.exe service_update.exe service_update.exe service_update.exe explorer.exe explorer.exe yandex.exe explorer.exe no specs clidmgr.exe conhost.exe clidmgr.exe conhost.exe browser.exe browser.exe browser.exe browser.exe browser.exe browser.exe browser.exe browser.exe browser.exe browser.exe browser.exe browser.exe setup.exe setup.exe browser.exe browser.exe browser.exe

Process information

PID
CMD
Path
Indicators
Parent process
368"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=ru --service-sandbox-type=none --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --no-appcompat-clear --process-name="Video Capture" --field-trial-handle=3484,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=3496 --brver=24.6.3.729 /prefetch:8C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe
browser.exe
User:
admin
Company:
YANDEX LLC
Integrity Level:
MEDIUM
Description:
Yandex with voice assistant Alice
Version:
24.6.3.729
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\yandex\yandexbrowser\application\24.6.3.729\browser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
648"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=ru --service-sandbox-type=service --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --no-appcompat-clear --process-name="Data Decoder Service" --field-trial-handle=2104,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=5444 --brver=24.6.3.729 /prefetch:8C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe
browser.exe
User:
admin
Company:
YANDEX LLC
Integrity Level:
LOW
Description:
Yandex with voice assistant Alice
Exit code:
0
Version:
24.6.3.729
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\yandex\yandexbrowser\application\24.6.3.729\browser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
1060\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe
clidmgr.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1376"C:\Program Files (x86)\Yandex\YandexBrowser\24.6.3.729\service_update.exe" --run-as-serviceC:\Program Files (x86)\Yandex\YandexBrowser\24.6.3.729\service_update.exe
services.exe
User:
SYSTEM
Company:
YANDEX LLC
Integrity Level:
SYSTEM
Description:
Yandex
Version:
24.6.3.729
Modules
Images
c:\program files (x86)\yandex\yandexbrowser\24.6.3.729\service_update.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1544"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=utility --utility-sub-type=uwp_cookie_provider.mojom.UwpCookieProvider --lang=ru --service-sandbox-type=utility --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --no-appcompat-clear --process-name=uwp_cookie_provider.mojom.UwpCookieProvider --field-trial-handle=5580,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=2072 --brver=24.6.3.729 /prefetch:8C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe
browser.exe
User:
admin
Company:
YANDEX LLC
Integrity Level:
LOW
Description:
Yandex with voice assistant Alice
Version:
24.6.3.729
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\yandex\yandexbrowser\application\24.6.3.729\browser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
1992"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=renderer --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --web-ntp-url-for-renderer=https://webntp.yandex.ru/ --translate-security-origin=https://browser.translate.yandex.net/ --enable-instaserp --no-appcompat-clear --lang=ru --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --field-trial-handle=5148,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=4872 /prefetch:1C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe
browser.exe
User:
admin
Company:
YANDEX LLC
Integrity Level:
LOW
Description:
Yandex with voice assistant Alice
Version:
24.6.3.729
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\yandex\yandexbrowser\application\24.6.3.729\browser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\advapi32.dll
2032"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=ru --service-sandbox-type=service --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --no-appcompat-clear --process-name="Storage Service" --field-trial-handle=2848,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=2968 --brver=24.6.3.729 /prefetch:8C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe
browser.exe
User:
admin
Company:
YANDEX LLC
Integrity Level:
LOW
Description:
Yandex with voice assistant Alice
Version:
24.6.3.729
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\yandex\yandexbrowser\application\24.6.3.729\browser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
2064C:\Users\admin\AppData\Local\Yandex\YaPin\Yandex.exe --silentC:\Users\admin\AppData\Local\Yandex\YaPin\Yandex.exe
setup.exe
User:
admin
Integrity Level:
HIGH
Description:
YandexPin
Exit code:
0
Version:
3.7.9.0
Modules
Images
c:\users\admin\appdata\local\yandex\yapin\yandex.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2216"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\clidmgr.exe" --appid=yabrowser --vendor-xml-path="C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Temp\source2860_165440764\Browser-bin\clids_yandex.xml"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\clidmgr.exe
setup.exe
User:
admin
Company:
Yandex
Integrity Level:
HIGH
Description:
ClidManagerModule
Exit code:
0
Version:
1,0,0,44
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\clidmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2260"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=renderer --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --extension-process --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --web-ntp-url-for-renderer=https://webntp.yandex.ru/ --translate-security-origin=https://browser.translate.yandex.net/ --enable-instaserp --no-appcompat-clear --allow-prefetch --lang=ru --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --field-trial-handle=3784,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=3780 /prefetch:2C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe
browser.exe
User:
admin
Company:
YANDEX LLC
Integrity Level:
LOW
Description:
Yandex with voice assistant Alice
Version:
24.6.3.729
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\yandex\yandexbrowser\application\24.6.3.729\browser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\advapi32.dll
Total events
44 401
Read events
43 508
Write events
791
Delete events
102

Modification events

(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\AppDataLow\Yandex
Operation:writeName:UICreated_admin
Value:
1
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:writeName:DistribInfoParams
Value:
win10pin=1&vup=1&browser=EdgeChromium/64/126.0.0&banerid=6400000000:6692cc2847d2731fe89dc615&bitness=64&def=1&statpromo=true&yandexuid=5671459881720896523&mongoID=6692cc2847d2731fe89dc615&pps=installID%3D5671459881720896523_1720896552422%26mongoID%3D6692cc2847d2731fe89dc615&download_date=1720896552
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:delete valueName:brand
Value:
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:delete valueName:BrandFile
Value:
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:delete valueName:PartnerFile
Value:
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:writeName:lang
Value:
ru
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:writeName:InstallerData
Value:
C:\Users\admin\AppData\Local\Temp\master_preferences
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:writeName:ClidsFile
Value:
C:\Users\admin\AppData\Local\Temp\clids.xml
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:writeName:YandexWebsiteIconFile
Value:
C:\Users\admin\AppData\Local\Temp\website.ico
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:writeName:AbtConfigResourceFile
Value:
C:\Users\admin\AppData\Local\Temp\abt_config_resource
Executable files
12
Suspicious files
264
Text files
132
Unknown types
32

Dropped files

PID
Process
Filename
Type
2992Yandex.exeC:\Users\admin\AppData\Local\Temp\website.ico
MD5:
SHA256:
2992Yandex.exeC:\Users\admin\AppData\Roaming\Yandex\uitext
MD5:249A8807FFBBFC46D197CD1E786E5235
SHA256:E1EE6F4AD9075630671E92AA00D6A58C5E83CFF9FDEF687A3600B68A5CFB2FA8
2992Yandex.exeC:\Users\admin\AppData\Local\Temp\PartnerFilecompressed
MD5:CF1C376060414285ADDCECC4C8205F52
SHA256:A6180163F97158D636E7B5FA34C8193BA942636B7AEFE4E9D00BEBE2B4F5FD6C
2992Yandex.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\66F835E41EC6A985EB9271E4A70169D7_CF44E3C99F7F4AC558EEB35244F7E046der
MD5:3D7D74560BD0AD12988D2C75AAD53EEA
SHA256:F21D3B888EFEFED33892DAB4B22FEE974C8F86EAEE864D72F5A19EF60C547EE0
2992Yandex.exeC:\Users\admin\AppData\Local\Temp\BrandFilecompressed
MD5:8F0AC7B9A5BDC1BDF3C7F2863F4ACC9C
SHA256:67DFEC4E93078B29356CBAB08A4B7C54CBBE0CE3187B4C32BC19306BE83EF885
2992Yandex.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\349D186F1CB5682FA0194D4F3754EF36_329286CE101A90C7D927A9DF52224760der
MD5:00F4DA8FDA2B30D0A486690FD8FC921C
SHA256:734519524A14E7581C90A34989BA0D17B57DCFE1DA27F3E127CE2B4A0CD2A219
2992Yandex.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0DA515F703BB9B49479E8697ADB0B955_7DAD5545724AA2C98C55095F428499FBbinary
MD5:75CD99A92A8E90EE959D0D616952D0E9
SHA256:A746E700A35EEA0165EB839411C364884A3944962B7496D374552980DCFC016E
2992Yandex.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0DA515F703BB9B49479E8697ADB0B955_7DAD5545724AA2C98C55095F428499FBder
MD5:6F2A874CCE4BB2C3A26F10B294DB75E8
SHA256:57F0D9FBFEABF6F5DE7624EF1D73D0DA76EBCF950545AF8B6DFBAB55B88E1390
2992Yandex.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B039FEA45CB4CC4BBACFC013C7C55604_50D7940D5D3FEDD8634D83074C7A46A3der
MD5:AB5877308272DA0D2179321B6AB0E305
SHA256:7E59918F5CFB8A790951BAFEBC43B8C656527620B5460C750256194E81B1EF43
2992Yandex.exeC:\Users\admin\AppData\Local\Temp\abt_config_resourcebinary
MD5:74C9597D6E22A1E15C30643AD0692549
SHA256:892B791F54E1A10B2B72AFBD1AD0E561D9948B6CBDE73C75723AEFECBAC3D88E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
23
TCP/UDP connections
108
DNS requests
39
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2992
Yandex.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHUeP1PjGFkz6V8I7O6tApc%3D
unknown
whitelisted
2992
Yandex.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCDQHuXxad%2F5c1K2Rl1mo%3D
unknown
whitelisted
2992
Yandex.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCDQHuXxad%2F5c1K2Rl1mo%3D
unknown
whitelisted
2992
Yandex.exe
GET
200
104.18.21.226:80
http://ocsp2.globalsign.com/rootr3/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCDQHuXyId%2FGI71DM6hVc%3D
unknown
whitelisted
2992
Yandex.exe
GET
200
104.18.21.226:80
http://ocsp2.globalsign.com/rootr5/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQiD0S5cIHyfrLTJ1fvAkJWflH%2B2QQUPeYpSJvqB8ohREom3m7e0oPQn1kCDQHuXyKVQkkF%2BQGRqNw%3D
unknown
whitelisted
2992
Yandex.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gseccovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBSTMjK03nNiYoQYvu4Izyfn9OJNdAQUWHuOdSr%2BYYCqkEABrtboB0ZuP0gCDA3dnOhPx5IoBNEilQ%3D%3D
unknown
whitelisted
2992
Yandex.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsrsaovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT%2BanRD3C1tW3nsrKeuXC7DPwQU%2BO9%2F8s14Z6jeb48kjYjxhwMCs%2BsCDDrrc53tnvLvSvE9AA%3D%3D
unknown
whitelisted
2992
Yandex.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsrsaovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT%2BanRD3C1tW3nsrKeuXC7DPwQU%2BO9%2F8s14Z6jeb48kjYjxhwMCs%2BsCDAhWWiYI5dhngnR%2BOQ%3D%3D
unknown
whitelisted
6116
svchost.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6116
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6116
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4032
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
2252
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2248
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2992
Yandex.exe
213.180.193.234:443
api.browser.yandex.net
YANDEX LLC
RU
whitelisted
2992
Yandex.exe
5.45.205.244:443
download.cdn.yandex.net
YANDEX LLC
RU
whitelisted
2992
Yandex.exe
104.18.20.226:80
ocsp.globalsign.com
CLOUDFLARENET
shared
2992
Yandex.exe
104.18.21.226:80
ocsp.globalsign.com
CLOUDFLARENET
shared

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.186.174
whitelisted
api.browser.yandex.net
  • 213.180.193.234
whitelisted
download.cdn.yandex.net
  • 5.45.205.244
  • 5.45.205.242
  • 5.45.205.243
  • 5.45.205.245
  • 5.45.205.241
whitelisted
api.browser.yandex.ru
  • 213.180.193.234
whitelisted
ocsp.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
ocsp2.globalsign.com
  • 104.18.21.226
  • 104.18.20.226
whitelisted
cachev2-ams01.cdn.yandex.net
  • 5.45.247.51
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 88.221.169.152
whitelisted

Threats

No threats detected
Process
Message
clidmgr.exe
GetLoggedCreds_WTSSessionInfo(): szUserName = admin, szDomain = DESKTOP-JGLLJLD, dwSessionId = 1
clidmgr.exe
GetSidFromEnumSess(): i = 0 : szUserName = Administrator, szDomain = DESKTOP-JGLLJLD, dwSessionId = 0
clidmgr.exe
GetSidFromEnumSess(): ProfileImagePath(1) = C:\Users\admin
clidmgr.exe
GetSidFromEnumSess(): LsaEnumerateLogonSessions() lpszSid = S-1-5-21-1693682860-607145093-2874071422-1001
clidmgr.exe
GetLoggedCreds_WTSSessionInfo(): szUserName = admin, szDomain = DESKTOP-JGLLJLD, dwSessionId = 1
clidmgr.exe
GetSidFromEnumSess(): i = 0 : szUserName = Administrator, szDomain = DESKTOP-JGLLJLD, dwSessionId = 0
clidmgr.exe
GetSidFromEnumSess(): ProfileImagePath(1) = C:\Users\admin
clidmgr.exe
GetSidFromEnumSess(): LsaEnumerateLogonSessions() lpszSid = S-1-5-21-1693682860-607145093-2874071422-1001