File name: | YandexDisk30Setup.exe |
Full analysis: | https://app.any.run/tasks/b6d2626f-a2c3-429d-a0e2-79bf9257f6e4 |
Verdict: | Malicious activity |
Analysis date: | May 17, 2025, 01:29:39 |
OS: | Windows 10 Professional (build: 19044, 64 bit) |
Tags: | |
Indicators: | |
MIME: | application/vnd.microsoft.portable-executable |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
MD5: | 9C41B0517FACC6DF37AD1C06838655D3 |
SHA1: | 0DCDF08F37CBA736CEDDE34E42C04DC50E161FE2 |
SHA256: | EC8B052260B2D7D409B2FDEB24B0E1EEF0BC17071F02EDCE8F1BE1B1E058880D |
SSDEEP: | 98304:szs00prqcvT4dYC1RgB7PSHD4OP8cv2GllillSigNVh3pui43gSh/CJl7UotNUH:GRZ2g |
.exe | | | Win32 Executable (generic) (52.9) |
---|---|---|
.exe | | | Generic Win/DOS Executable (23.5) |
.exe | | | DOS Executable Generic (23.5) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2024:07:31 14:08:55+00:00 |
ImageFileCharacteristics: | Executable, 32-bit |
PEType: | PE32 |
LinkerVersion: | 14.16 |
CodeSize: | 2677760 |
InitializedDataSize: | 1552384 |
UninitializedDataSize: | - |
EntryPoint: | 0x211f6d |
OSVersion: | 5.1 |
ImageVersion: | - |
SubsystemVersion: | 5.1 |
Subsystem: | Windows GUI |
FileVersionNumber: | 3.2.41.5053 |
ProductVersionNumber: | 3.2.41.5053 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | Russian |
CharacterSet: | Unicode |
CompanyName: | Яндекс |
FileDescription: | YandexDiskSetup |
FileVersion: | 3.2.41.5053 |
InternalName: | YandexDiskSetup |
LegalCopyright: | © 2016-2024 ООО "ЯНДЕКС" |
OriginalFileName: | YandexDiskSetup.exe |
ProductName: | Яндекс.Диск |
ProductVersion: | 3.2.41.5053 |
Tag040904B0: | - |
Tag041F04B0: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
536 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | 7za.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
668 | "C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe" x "C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\chrome_elf.dll.zip" -aoa -o"C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac" | C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe | YandexDisk30Setup_x64.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: MEDIUM Description: 7-Zip Standalone Console Exit code: 0 Version: 9.20 Modules
| |||||||||||||||
668 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | 7za.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
732 | "C:\Windows\explorer.exe" /LOADSAVEDWINDOWS | C:\Windows\explorer.exe | — | YandexDisk30Setup_x64.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
780 | "C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe" x "C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\snapshot_blob.bin.zip" -aoa -o"C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac" | C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe | — | YandexDisk30Setup_x64.exe | |||||||||||
User: admin Company: Igor Pavlov Integrity Level: MEDIUM Description: 7-Zip Standalone Console Exit code: 0 Version: 9.20 Modules
| |||||||||||||||
896 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | 7za.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
900 | "C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe" x "C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\libcairo-2.dll.zip" -aoa -o"C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac" | C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe | YandexDisk30Setup_x64.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: MEDIUM Description: 7-Zip Standalone Console Exit code: 0 Version: 9.20 Modules
| |||||||||||||||
900 | "C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe" x "C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\icudtl.dat.zip" -aoa -o"C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac" | C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe | — | YandexDisk30Setup_x64.exe | |||||||||||
User: admin Company: Igor Pavlov Integrity Level: MEDIUM Description: 7-Zip Standalone Console Exit code: 0 Version: 9.20 Modules
| |||||||||||||||
1116 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | 7za.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
1168 | "C:\Users\admin\AppData\Local\Temp\YandexDisk30Setup.exe" | C:\Users\admin\AppData\Local\Temp\YandexDisk30Setup.exe | explorer.exe | ||||||||||||
User: admin Company: Яндекс Integrity Level: MEDIUM Description: YandexDiskSetup Version: 3.2.41.5053 Modules
|
(PID) Process: | (6736) YandexDisk30Setup_x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Yandex\Yandex.Disk.2 |
Operation: | delete value | Name: | PerUserInstallType |
Value: | |||
(PID) Process: | (6736) YandexDisk30Setup_x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Yandex\Yandex.Disk.2.Installer3 |
Operation: | delete value | Name: | InstallerPath |
Value: | |||
(PID) Process: | (6736) YandexDisk30Setup_x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YandexDisk2 |
Operation: | delete value | Name: | UninstallString |
Value: | |||
(PID) Process: | (6736) YandexDisk30Setup_x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Yandex\Yandex.Disk.2 |
Operation: | write | Name: | TelemostIsSeparateApplication |
Value: 1 | |||
(PID) Process: | (2088) YandexDisk30Setup_x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Yandex\Yandex.Disk.2.Installer3 |
Operation: | delete value | Name: | InstallerPath |
Value: | |||
(PID) Process: | (2088) YandexDisk30Setup_x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YandexDisk2 |
Operation: | delete value | Name: | UninstallString |
Value: | |||
(PID) Process: | (2088) YandexDisk30Setup_x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Yandex\Yandex.Disk.2.Installer3 |
Operation: | delete value | Name: | InstallerPath |
Value: | |||
(PID) Process: | (2088) YandexDisk30Setup_x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YandexDisk2 |
Operation: | delete value | Name: | UninstallString |
Value: | |||
(PID) Process: | (2088) YandexDisk30Setup_x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Yandex\Yandex.Disk.2 |
Operation: | write | Name: | MachineInstallPathWow64 |
Value: C:\Program Files (x86)\Yandex\YandexDisk2\bin\ | |||
(PID) Process: | (2088) YandexDisk30Setup_x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Yandex\Yandex.Disk.2 |
Operation: | write | Name: | TelemostIsSeparateApplication |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
1168 | YandexDisk30Setup.exe | C:\ProgramData\Yandex\Yandex.Disk.2\{3FE0EF39-1462-4094-9A42-43B4EE3C383B}\YandexDisk30Setup_x64.exe | — | |
MD5:— | SHA256:— | |||
2504 | 7za.exe | C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\YandexDisk2.exe | — | |
MD5:— | SHA256:— | |||
6736 | YandexDisk30Setup_x64.exe | C:\Users\admin\AppData\Roaming\Yandex\YandexDisk2\3.2.43.5089\YandexDisk2.exe | — | |
MD5:— | SHA256:— | |||
1168 | YandexDisk30Setup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9CB4373A4252DE8D2212929836304EC5_1AB74AA2E3A56E1B8AD8D3FEC287554E | binary | |
MD5:5315B836FCE5A7237A28A113178F76B9 | SHA256:7DBE0393F54E21BEC22A7CCCAA820257B20897CF85998A49284F472920B3FD8F | |||
6736 | YandexDisk30Setup_x64.exe | C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\YandexDisk2.exe.zip | compressed | |
MD5:FE75F17C1E2FD1EC1EC376DB8B48BF06 | SHA256:F8FE46FE01A890854EE5A36B5612C73089C78A58BC0081BA6704EFA3C99AAD46 | |||
1168 | YandexDisk30Setup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9CB4373A4252DE8D2212929836304EC5_1AB74AA2E3A56E1B8AD8D3FEC287554E | binary | |
MD5:21718B8E471B22B8B3B85E429BA2E7F8 | SHA256:8CBB527F409E646E117601CBB9A2F8C39347F6189F5CDDA7B73D0641C588269E | |||
1168 | YandexDisk30Setup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\357F04AD41BCF5FE18FCB69F60C6680F_394487CAFBCFB8C5917AD7A10924C8A7 | binary | |
MD5:AAC84679343D44C5A539094C99EB8C0C | SHA256:596D112901FAD0AED88BC5057056A2F00CC59B49A6521231C154F7AD1E131B5E | |||
4696 | 7za.exe | C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\YandexDiskScreenshotEditor.exe | executable | |
MD5:A897E6EC56F7154E6574824DAB79D6D9 | SHA256:1DB0553DCE9F40C48ACF3B528C7EE146DE4620BEB8AD4A43597C67F4EA3F65C3 | |||
6736 | YandexDisk30Setup_x64.exe | C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe | executable | |
MD5:42BADC1D2F03A8B1E4875740D3D49336 | SHA256:C136B1467D669A725478A6110EBAAAB3CB88A3D389DFA688E06173C066B76FCF | |||
6736 | YandexDisk30Setup_x64.exe | C:\Users\admin\AppData\Roaming\Yandex\YandexDisk2\3.2.43.5089\YandexDiskScreenshotEditor.exe | executable | |
MD5:A897E6EC56F7154E6574824DAB79D6D9 | SHA256:1DB0553DCE9F40C48ACF3B528C7EE146DE4620BEB8AD4A43597C67F4EA3F65C3 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.216.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1168 | YandexDisk30Setup.exe | GET | 200 | 151.101.194.133:80 | http://ocsp.globalsign.com/codesigningrootr45/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQVFZP5vqhCrtRN5SWf40Rn6NM1IAQUHwC%2FRoAK%2FHg5t6W0Q9lWULvOljsCEHe9DgW3WQu2HUdhUx4%2Fde0%3D | unknown | — | — | whitelisted |
1168 | YandexDisk30Setup.exe | GET | 200 | 151.101.194.133:80 | http://ocsp.globalsign.com/gsgccr45evcodesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQaCbVYh07WONuW4e63Ydlu4AlbDAQUJZ3Q%2FFkJhmPF7POxEztXHAOSNhECDG8SbJzCh95FjOiQ9g%3D%3D | unknown | — | — | whitelisted |
6736 | YandexDisk30Setup_x64.exe | GET | 200 | 151.101.66.133:80 | http://crl.globalsign.net/root.crl | unknown | — | — | whitelisted |
6736 | YandexDisk30Setup_x64.exe | GET | 200 | 151.101.66.133:80 | http://ocsp2.globalsign.com/gscodesigng2/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRruLd2WRFk6cRYGFIqkQ4J8hxDogQUCG7YtpyKv%2B0%2B18N0XcyAH6gvUHoCEhEhD%2FZGK2PVWvuqgfnHNKeqlA%3D%3D | unknown | — | — | whitelisted |
4724 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
4724 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
7080 | SearchApp.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.216.77.6:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.35.229.160:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1168 | YandexDisk30Setup.exe | 213.180.204.148:443 | webdav.yandex.ru | YANDEX LLC | RU | whitelisted |
1168 | YandexDisk30Setup.exe | 77.88.21.127:443 | downloader.disk.yandex.ru | YANDEX LLC | RU | whitelisted |
3216 | svchost.exe | 172.211.123.250:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6544 | svchost.exe | 40.126.32.133:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
Domain | IP | Reputation |
---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
webdav.yandex.ru |
| whitelisted |
downloader.disk.yandex.ru |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
ocsp.globalsign.com |
| whitelisted |