File name:

Yandex.exe

Full analysis: https://app.any.run/tasks/3e0502e7-6886-490e-a848-8f92d4b93e80
Verdict: Malicious activity
Analysis date: July 13, 2024, 18:51:13
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

28EE3C895BE2B8771C06C2820D364B0F

SHA1:

78B61EDEF642DAE3A6C8BD5BEF2C59C5CAEF5879

SHA256:

B7ADE1749F7FCA0D886338D6EAA528530CE36237B46AB47CCD20D736E0B8E748

SSDEEP:

98304:TnbajsQOZzu2AvkuT9DcXr0SPAizoxcUfXto6qprqgYBHJbpcWSLQIJZmX1RuEW2:sxRx9w14mwAS/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Yandex.exe (PID: 2992)
      • ybF544.tmp (PID: 6988)
      • setup.exe (PID: 2860)
      • service_update.exe (PID: 3824)
      • Yandex.exe (PID: 2064)
    • Actions looks like stealing of personal data

      • setup.exe (PID: 5524)
      • service_update.exe (PID: 6348)
      • service_update.exe (PID: 3824)
      • service_update.exe (PID: 3508)
      • service_update.exe (PID: 6544)
      • setup.exe (PID: 2860)
      • service_update.exe (PID: 2452)
      • service_update.exe (PID: 1376)
      • explorer.exe (PID: 7136)
      • explorer.exe (PID: 2648)
      • clidmgr.exe (PID: 5888)
      • conhost.exe (PID: 1060)
      • conhost.exe (PID: 4780)
      • clidmgr.exe (PID: 2216)
      • browser.exe (PID: 6044)
      • browser.exe (PID: 3932)
      • browser.exe (PID: 5940)
      • browser.exe (PID: 2032)
      • browser.exe (PID: 3156)
      • browser.exe (PID: 368)
      • browser.exe (PID: 2260)
      • browser.exe (PID: 5708)
      • browser.exe (PID: 5316)
      • browser.exe (PID: 6324)
      • browser.exe (PID: 6720)
      • setup.exe (PID: 7144)
      • setup.exe (PID: 3532)
      • browser.exe (PID: 3660)
      • browser.exe (PID: 1992)
      • browser.exe (PID: 648)
      • browser.exe (PID: 1544)
    • Creates a writable file in the system directory

      • service_update.exe (PID: 1376)
    • Changes the autorun value in the registry

      • browser.exe (PID: 6324)
    • Steals credentials from Web Browsers

      • browser.exe (PID: 6324)
  • SUSPICIOUS

    • Checks Windows Trust Settings

      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 2860)
      • explorer.exe (PID: 2648)
    • Reads the date of Windows installation

      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 7068)
      • service_update.exe (PID: 3824)
      • explorer.exe (PID: 2648)
      • Yandex.exe (PID: 2064)
      • explorer.exe (PID: 6864)
    • Reads security settings of Internet Explorer

      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 2860)
      • setup.exe (PID: 7068)
      • service_update.exe (PID: 3824)
      • explorer.exe (PID: 2648)
      • Yandex.exe (PID: 2064)
      • explorer.exe (PID: 6864)
    • Starts application with an unusual extension

      • Yandex.exe (PID: 3780)
    • Application launched itself

      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 7068)
      • setup.exe (PID: 2860)
      • service_update.exe (PID: 1376)
      • service_update.exe (PID: 6544)
      • explorer.exe (PID: 2648)
      • browser.exe (PID: 6324)
      • setup.exe (PID: 7144)
    • Executable content was dropped or overwritten

      • ybF544.tmp (PID: 6988)
      • setup.exe (PID: 2860)
      • service_update.exe (PID: 3824)
      • Yandex.exe (PID: 2064)
    • Adds/modifies Windows certificates

      • setup.exe (PID: 2860)
      • explorer.exe (PID: 2648)
    • Starts itself from another location

      • service_update.exe (PID: 3824)
      • setup.exe (PID: 2860)
      • Yandex.exe (PID: 2064)
    • Creates a software uninstall entry

      • setup.exe (PID: 2860)
      • Yandex.exe (PID: 2064)
    • Executes as Windows Service

      • service_update.exe (PID: 1376)
    • The process creates files with name similar to system file names

      • setup.exe (PID: 2860)
      • Yandex.exe (PID: 2064)
    • Searches for installed software

      • setup.exe (PID: 2860)
    • Reads Mozilla Firefox installation path

      • browser.exe (PID: 6324)
  • INFO

    • Checks supported languages

      • Yandex.exe (PID: 2992)
      • Yandex.exe (PID: 3780)
      • ybF544.tmp (PID: 6988)
      • setup.exe (PID: 2860)
      • setup.exe (PID: 7068)
      • setup.exe (PID: 5524)
      • service_update.exe (PID: 3824)
      • service_update.exe (PID: 6544)
      • service_update.exe (PID: 6348)
      • service_update.exe (PID: 1376)
      • service_update.exe (PID: 3508)
      • service_update.exe (PID: 2452)
      • explorer.exe (PID: 2648)
      • explorer.exe (PID: 7136)
      • Yandex.exe (PID: 2064)
      • explorer.exe (PID: 6864)
      • clidmgr.exe (PID: 5888)
      • clidmgr.exe (PID: 2216)
      • browser.exe (PID: 6324)
      • browser.exe (PID: 6044)
      • browser.exe (PID: 3932)
      • browser.exe (PID: 5940)
      • browser.exe (PID: 3660)
      • browser.exe (PID: 2032)
      • browser.exe (PID: 368)
      • browser.exe (PID: 3156)
      • browser.exe (PID: 2260)
      • browser.exe (PID: 5708)
      • browser.exe (PID: 5316)
      • browser.exe (PID: 6720)
      • setup.exe (PID: 3532)
      • setup.exe (PID: 7144)
      • browser.exe (PID: 1544)
      • browser.exe (PID: 1992)
      • browser.exe (PID: 648)
    • Creates files or folders in the user directory

      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 5524)
      • setup.exe (PID: 2860)
      • explorer.exe (PID: 2648)
      • Yandex.exe (PID: 2064)
      • explorer.exe (PID: 6864)
      • clidmgr.exe (PID: 5888)
      • browser.exe (PID: 6324)
      • browser.exe (PID: 3660)
      • setup.exe (PID: 7144)
    • Create files in a temporary directory

      • Yandex.exe (PID: 2992)
      • ybF544.tmp (PID: 6988)
      • setup.exe (PID: 2860)
      • setup.exe (PID: 7068)
      • Yandex.exe (PID: 2064)
      • browser.exe (PID: 6720)
      • browser.exe (PID: 6324)
    • Process checks computer location settings

      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 7068)
      • service_update.exe (PID: 3824)
      • explorer.exe (PID: 2648)
      • Yandex.exe (PID: 2064)
      • explorer.exe (PID: 6864)
      • browser.exe (PID: 6324)
      • browser.exe (PID: 2260)
      • browser.exe (PID: 5316)
      • browser.exe (PID: 1992)
    • Reads the software policy settings

      • Yandex.exe (PID: 2992)
      • slui.exe (PID: 7124)
      • slui.exe (PID: 6504)
      • setup.exe (PID: 2860)
      • explorer.exe (PID: 2648)
      • browser.exe (PID: 6324)
    • Reads the machine GUID from the registry

      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 2860)
      • explorer.exe (PID: 2648)
      • browser.exe (PID: 6324)
    • Checks proxy server information

      • slui.exe (PID: 6504)
      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 2860)
      • browser.exe (PID: 6324)
    • Reads the computer name

      • ybF544.tmp (PID: 6988)
      • Yandex.exe (PID: 2992)
      • setup.exe (PID: 7068)
      • setup.exe (PID: 2860)
      • service_update.exe (PID: 3824)
      • service_update.exe (PID: 1376)
      • service_update.exe (PID: 6544)
      • service_update.exe (PID: 2452)
      • service_update.exe (PID: 6348)
      • explorer.exe (PID: 2648)
      • Yandex.exe (PID: 2064)
      • explorer.exe (PID: 6864)
      • clidmgr.exe (PID: 5888)
      • clidmgr.exe (PID: 2216)
      • browser.exe (PID: 6324)
      • browser.exe (PID: 5940)
      • browser.exe (PID: 3660)
      • browser.exe (PID: 3156)
      • browser.exe (PID: 368)
      • browser.exe (PID: 6720)
      • setup.exe (PID: 7144)
    • Creates files in the program directory

      • service_update.exe (PID: 3824)
    • Manual execution by a user

      • browser.exe (PID: 6324)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:07:10 12:38:10+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 1106432
InitializedDataSize: 9735680
UninitializedDataSize: -
EntryPoint: 0xdbe30
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 24.6.3.729
ProductVersionNumber: 24.6.3.729
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: YANDEX LLC
FileDescription: Yandex
FileVersion: 24.6.3.729
InternalName: lite_installer
LegalCopyright: Copyright (c) 2012-2024 YANDEX LLC. All Rights Reserved.
ProductName: Yandex
ProductVersion: 24.6.3.729
ProductChromiumVersion: 124.0.6367.243
ProductYandexVersion: 24.6.3.729
CompanyShortName: YANDEX LLC
ProductShortName: Yandex Installer
LastChange: b9d72f9a3142c72437f331cba038933e97726de0
OfficialBuild: 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
180
Monitored processes
40
Malicious processes
35
Suspicious processes
2

Behavior graph

Click at the process to see the details
start yandex.exe yandex.exe sppextcomobj.exe no specs slui.exe slui.exe ybf544.tmp setup.exe no specs setup.exe setup.exe service_update.exe service_update.exe service_update.exe service_update.exe service_update.exe service_update.exe explorer.exe explorer.exe yandex.exe explorer.exe no specs clidmgr.exe conhost.exe clidmgr.exe conhost.exe browser.exe browser.exe browser.exe browser.exe browser.exe browser.exe browser.exe browser.exe browser.exe browser.exe browser.exe browser.exe setup.exe setup.exe browser.exe browser.exe browser.exe

Process information

PID
CMD
Path
Indicators
Parent process
368"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=ru --service-sandbox-type=none --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --no-appcompat-clear --process-name="Video Capture" --field-trial-handle=3484,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=3496 --brver=24.6.3.729 /prefetch:8C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe
browser.exe
User:
admin
Company:
YANDEX LLC
Integrity Level:
MEDIUM
Description:
Yandex with voice assistant Alice
Version:
24.6.3.729
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\yandex\yandexbrowser\application\24.6.3.729\browser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
648"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=ru --service-sandbox-type=service --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --no-appcompat-clear --process-name="Data Decoder Service" --field-trial-handle=2104,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=5444 --brver=24.6.3.729 /prefetch:8C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe
browser.exe
User:
admin
Company:
YANDEX LLC
Integrity Level:
LOW
Description:
Yandex with voice assistant Alice
Exit code:
0
Version:
24.6.3.729
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\yandex\yandexbrowser\application\24.6.3.729\browser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
1060\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe
clidmgr.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1376"C:\Program Files (x86)\Yandex\YandexBrowser\24.6.3.729\service_update.exe" --run-as-serviceC:\Program Files (x86)\Yandex\YandexBrowser\24.6.3.729\service_update.exe
services.exe
User:
SYSTEM
Company:
YANDEX LLC
Integrity Level:
SYSTEM
Description:
Yandex
Version:
24.6.3.729
Modules
Images
c:\program files (x86)\yandex\yandexbrowser\24.6.3.729\service_update.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1544"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=utility --utility-sub-type=uwp_cookie_provider.mojom.UwpCookieProvider --lang=ru --service-sandbox-type=utility --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --no-appcompat-clear --process-name=uwp_cookie_provider.mojom.UwpCookieProvider --field-trial-handle=5580,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=2072 --brver=24.6.3.729 /prefetch:8C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe
browser.exe
User:
admin
Company:
YANDEX LLC
Integrity Level:
LOW
Description:
Yandex with voice assistant Alice
Version:
24.6.3.729
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\yandex\yandexbrowser\application\24.6.3.729\browser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
1992"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=renderer --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --web-ntp-url-for-renderer=https://webntp.yandex.ru/ --translate-security-origin=https://browser.translate.yandex.net/ --enable-instaserp --no-appcompat-clear --lang=ru --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --field-trial-handle=5148,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=4872 /prefetch:1C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe
browser.exe
User:
admin
Company:
YANDEX LLC
Integrity Level:
LOW
Description:
Yandex with voice assistant Alice
Version:
24.6.3.729
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\yandex\yandexbrowser\application\24.6.3.729\browser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\advapi32.dll
2032"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=ru --service-sandbox-type=service --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --no-appcompat-clear --process-name="Storage Service" --field-trial-handle=2848,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=2968 --brver=24.6.3.729 /prefetch:8C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe
browser.exe
User:
admin
Company:
YANDEX LLC
Integrity Level:
LOW
Description:
Yandex with voice assistant Alice
Version:
24.6.3.729
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\yandex\yandexbrowser\application\24.6.3.729\browser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
2064C:\Users\admin\AppData\Local\Yandex\YaPin\Yandex.exe --silentC:\Users\admin\AppData\Local\Yandex\YaPin\Yandex.exe
setup.exe
User:
admin
Integrity Level:
HIGH
Description:
YandexPin
Exit code:
0
Version:
3.7.9.0
Modules
Images
c:\users\admin\appdata\local\yandex\yapin\yandex.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2216"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\clidmgr.exe" --appid=yabrowser --vendor-xml-path="C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Temp\source2860_165440764\Browser-bin\clids_yandex.xml"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\clidmgr.exe
setup.exe
User:
admin
Company:
Yandex
Integrity Level:
HIGH
Description:
ClidManagerModule
Exit code:
0
Version:
1,0,0,44
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\clidmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2260"C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe" --type=renderer --user-id=9A38943E-F956-4C76-B7B7-6CAC5A1FFD62 --brand-id=yandex --partner-id=exp_firstscreen_2 --extension-process --help-url=https://api.browser.yandex.ru/redirect/help/ --user-agent-info --web-ntp-url-for-renderer=https://webntp.yandex.ru/ --translate-security-origin=https://browser.translate.yandex.net/ --enable-instaserp --no-appcompat-clear --allow-prefetch --lang=ru --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --field-trial-handle=3784,i,9161613198388848194,13284762320381900290,262144 --enable-features=InstallerNewIdentity2024 --variations-seed-version --mojo-platform-channel-handle=3780 /prefetch:2C:\Users\admin\AppData\Local\Yandex\YandexBrowser\Application\browser.exe
browser.exe
User:
admin
Company:
YANDEX LLC
Integrity Level:
LOW
Description:
Yandex with voice assistant Alice
Version:
24.6.3.729
Modules
Images
c:\users\admin\appdata\local\yandex\yandexbrowser\application\browser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\yandex\yandexbrowser\application\24.6.3.729\browser_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\winmm.dll
c:\windows\system32\advapi32.dll
Total events
44 401
Read events
43 508
Write events
791
Delete events
102

Modification events

(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\AppDataLow\Yandex
Operation:writeName:UICreated_admin
Value:
1
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:writeName:DistribInfoParams
Value:
win10pin=1&vup=1&browser=EdgeChromium/64/126.0.0&banerid=6400000000:6692cc2847d2731fe89dc615&bitness=64&def=1&statpromo=true&yandexuid=5671459881720896523&mongoID=6692cc2847d2731fe89dc615&pps=installID%3D5671459881720896523_1720896552422%26mongoID%3D6692cc2847d2731fe89dc615&download_date=1720896552
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:delete valueName:brand
Value:
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:delete valueName:BrandFile
Value:
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:delete valueName:PartnerFile
Value:
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:writeName:lang
Value:
ru
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:writeName:InstallerData
Value:
C:\Users\admin\AppData\Local\Temp\master_preferences
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:writeName:ClidsFile
Value:
C:\Users\admin\AppData\Local\Temp\clids.xml
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:writeName:YandexWebsiteIconFile
Value:
C:\Users\admin\AppData\Local\Temp\website.ico
(PID) Process:(2992) Yandex.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\YandexBrowser
Operation:writeName:AbtConfigResourceFile
Value:
C:\Users\admin\AppData\Local\Temp\abt_config_resource
Executable files
12
Suspicious files
264
Text files
132
Unknown types
32

Dropped files

PID
Process
Filename
Type
2992Yandex.exeC:\Users\admin\AppData\Local\Temp\website.ico
MD5:
SHA256:
2992Yandex.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\349D186F1CB5682FA0194D4F3754EF36_329286CE101A90C7D927A9DF52224760der
MD5:00F4DA8FDA2B30D0A486690FD8FC921C
SHA256:734519524A14E7581C90A34989BA0D17B57DCFE1DA27F3E127CE2B4A0CD2A219
2992Yandex.exeC:\Users\admin\AppData\Local\Temp\clids.xmlxml
MD5:94767E5BD3C7D598C990DCBA9E0ABF8B
SHA256:E1F801C2623ECA1D2EF8C5BEB325B64D3EECD2A36E92E8C2BCFCF9315F9773AF
2992Yandex.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B039FEA45CB4CC4BBACFC013C7C55604_50D7940D5D3FEDD8634D83074C7A46A3der
MD5:AB5877308272DA0D2179321B6AB0E305
SHA256:7E59918F5CFB8A790951BAFEBC43B8C656527620B5460C750256194E81B1EF43
2992Yandex.exeC:\Users\admin\AppData\Roaming\Yandex\uitext
MD5:249A8807FFBBFC46D197CD1E786E5235
SHA256:E1EE6F4AD9075630671E92AA00D6A58C5E83CFF9FDEF687A3600B68A5CFB2FA8
2992Yandex.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\349D186F1CB5682FA0194D4F3754EF36_329286CE101A90C7D927A9DF52224760binary
MD5:7A1083D7F1FDFAA51CB82F5B81E1AE09
SHA256:72769A20EABE902A8E930CB0113A600CBBE3EE65A81DFC9E5FB218208603456B
2992Yandex.exeC:\Users\admin\AppData\Local\Temp\distrib_infobinary
MD5:4A55E0848D1C97C43900E72E89DB7BAD
SHA256:6C81968C0A6418315FB8B2A50301496EFEE66B4AE80610F402D896BD5F217EBD
2992Yandex.exeC:\Users\admin\AppData\Local\Temp\lite_installer.logtext
MD5:BA9D765DBC5CBA326FD7826EA5C5233C
SHA256:AB2F70B76F74572DB5E508206E492D1D2A862F55CF096B6D801FA539F87DAA9A
2992Yandex.exeC:\Users\admin\AppData\Local\Temp\BrandFilecompressed
MD5:8F0AC7B9A5BDC1BDF3C7F2863F4ACC9C
SHA256:67DFEC4E93078B29356CBAB08A4B7C54CBBE0CE3187B4C32BC19306BE83EF885
2992Yandex.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\81B9B36F9ABC4DA631A4713EE66FAEC6_1E97890684BEEE785DD0BA79E29BED8Fder
MD5:C0B5B626823066D77A06391D9E2AD403
SHA256:879AF0870BBA4C9AF62913C14676ADC1E4E67AC8277433090ACCD3FB99F53607
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
23
TCP/UDP connections
108
DNS requests
39
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2992
Yandex.exe
GET
200
104.18.21.226:80
http://ocsp.globalsign.com/gsgccr45evcodesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQaCbVYh07WONuW4e63Ydlu4AlbDAQUJZ3Q%2FFkJhmPF7POxEztXHAOSNhECDG8SbJzCh95FjOiQ9g%3D%3D
unknown
whitelisted
2992
Yandex.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEDAPb6zdZph0fKlGNqd4Lbk%3D
unknown
whitelisted
2992
Yandex.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHUeP1PjGFkz6V8I7O6tApc%3D
unknown
whitelisted
2992
Yandex.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCDQHuXxad%2F5c1K2Rl1mo%3D
unknown
whitelisted
2992
Yandex.exe
GET
200
104.18.21.226:80
http://ocsp2.globalsign.com/rootr5/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQiD0S5cIHyfrLTJ1fvAkJWflH%2B2QQUPeYpSJvqB8ohREom3m7e0oPQn1kCDQHuXyKVQkkF%2BQGRqNw%3D
unknown
whitelisted
2992
Yandex.exe
GET
200
104.18.21.226:80
http://ocsp2.globalsign.com/rootr3/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCDQHuXyId%2FGI71DM6hVc%3D
unknown
whitelisted
2992
Yandex.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gseccovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBSTMjK03nNiYoQYvu4Izyfn9OJNdAQUWHuOdSr%2BYYCqkEABrtboB0ZuP0gCDA3dnOhPx5IoBNEilQ%3D%3D
unknown
whitelisted
2992
Yandex.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsrsaovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT%2BanRD3C1tW3nsrKeuXC7DPwQU%2BO9%2F8s14Z6jeb48kjYjxhwMCs%2BsCDAhWWiYI5dhngnR%2BOQ%3D%3D
unknown
whitelisted
2992
Yandex.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCDQHuXxad%2F5c1K2Rl1mo%3D
unknown
whitelisted
6116
svchost.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6116
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4032
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
2252
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2248
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2992
Yandex.exe
213.180.193.234:443
api.browser.yandex.net
YANDEX LLC
RU
whitelisted
2992
Yandex.exe
5.45.205.244:443
download.cdn.yandex.net
YANDEX LLC
RU
whitelisted
2992
Yandex.exe
104.18.20.226:80
ocsp.globalsign.com
CLOUDFLARENET
shared
2992
Yandex.exe
104.18.21.226:80
ocsp.globalsign.com
CLOUDFLARENET
shared

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.186.174
whitelisted
api.browser.yandex.net
  • 213.180.193.234
whitelisted
download.cdn.yandex.net
  • 5.45.205.244
  • 5.45.205.242
  • 5.45.205.243
  • 5.45.205.245
  • 5.45.205.241
whitelisted
api.browser.yandex.ru
  • 213.180.193.234
whitelisted
ocsp.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
ocsp2.globalsign.com
  • 104.18.21.226
  • 104.18.20.226
whitelisted
cachev2-ams01.cdn.yandex.net
  • 5.45.247.51
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 88.221.169.152
whitelisted

Threats

No threats detected
Process
Message
clidmgr.exe
GetLoggedCreds_WTSSessionInfo(): szUserName = admin, szDomain = DESKTOP-JGLLJLD, dwSessionId = 1
clidmgr.exe
GetSidFromEnumSess(): i = 0 : szUserName = Administrator, szDomain = DESKTOP-JGLLJLD, dwSessionId = 0
clidmgr.exe
GetSidFromEnumSess(): ProfileImagePath(1) = C:\Users\admin
clidmgr.exe
GetSidFromEnumSess(): LsaEnumerateLogonSessions() lpszSid = S-1-5-21-1693682860-607145093-2874071422-1001
clidmgr.exe
GetLoggedCreds_WTSSessionInfo(): szUserName = admin, szDomain = DESKTOP-JGLLJLD, dwSessionId = 1
clidmgr.exe
GetSidFromEnumSess(): i = 0 : szUserName = Administrator, szDomain = DESKTOP-JGLLJLD, dwSessionId = 0
clidmgr.exe
GetSidFromEnumSess(): ProfileImagePath(1) = C:\Users\admin
clidmgr.exe
GetSidFromEnumSess(): LsaEnumerateLogonSessions() lpszSid = S-1-5-21-1693682860-607145093-2874071422-1001