File name:

YandexDisk30Setup.exe

Full analysis: https://app.any.run/tasks/b6d2626f-a2c3-429d-a0e2-79bf9257f6e4
Verdict: Malicious activity
Analysis date: May 17, 2025, 01:29:39
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

9C41B0517FACC6DF37AD1C06838655D3

SHA1:

0DCDF08F37CBA736CEDDE34E42C04DC50E161FE2

SHA256:

EC8B052260B2D7D409B2FDEB24B0E1EEF0BC17071F02EDCE8F1BE1B1E058880D

SSDEEP:

98304:szs00prqcvT4dYC1RgB7PSHD4OP8cv2GllillSigNVh3pui43gSh/CJl7UotNUH:GRZ2g

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • YandexDisk2.exe (PID: 1764)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • YandexDisk30Setup.exe (PID: 1168)
      • YandexDisk30Setup_x64.exe (PID: 2088)
      • YandexDisk30Setup_x64.exe (PID: 6736)
      • StartMenuExperienceHost.exe (PID: 2568)
    • Reads the date of Windows installation

      • YandexDisk30Setup_x64.exe (PID: 6736)
      • StartMenuExperienceHost.exe (PID: 2568)
      • SearchApp.exe (PID: 7080)
    • Application launched itself

      • YandexDisk30Setup_x64.exe (PID: 6736)
    • Executable content was dropped or overwritten

      • YandexDisk30Setup_x64.exe (PID: 6736)
      • 7za.exe (PID: 4724)
      • 7za.exe (PID: 4696)
      • 7za.exe (PID: 900)
      • 7za.exe (PID: 2420)
      • 7za.exe (PID: 1568)
      • 7za.exe (PID: 4024)
      • 7za.exe (PID: 5344)
      • 7za.exe (PID: 668)
      • 7za.exe (PID: 5552)
      • 7za.exe (PID: 3304)
    • Drops 7-zip archiver for unpacking

      • YandexDisk30Setup_x64.exe (PID: 6736)
    • Process drops SQLite DLL files

      • 7za.exe (PID: 5344)
      • YandexDisk30Setup_x64.exe (PID: 6736)
    • Creates/Modifies COM task schedule object

      • YandexDisk30Setup_x64.exe (PID: 6736)
    • Creates a software uninstall entry

      • YandexDisk30Setup_x64.exe (PID: 6736)
    • Starts itself from another location

      • YandexDisk30Setup_x64.exe (PID: 6736)
  • INFO

    • The sample compiled with russian language support

      • YandexDisk30Setup.exe (PID: 1168)
      • 7za.exe (PID: 5552)
      • YandexDisk30Setup_x64.exe (PID: 6736)
    • Creates files or folders in the user directory

      • YandexDisk30Setup.exe (PID: 1168)
      • YandexDisk30Setup_x64.exe (PID: 6736)
      • explorer.exe (PID: 732)
    • Checks supported languages

      • YandexDisk30Setup.exe (PID: 1168)
      • YandexDisk30Setup_x64.exe (PID: 6736)
      • YandexDisk30Setup_x64.exe (PID: 2088)
      • 7za.exe (PID: 2504)
      • 7za.exe (PID: 4724)
      • 7za.exe (PID: 900)
      • 7za.exe (PID: 2420)
      • 7za.exe (PID: 4696)
      • 7za.exe (PID: 1568)
      • 7za.exe (PID: 4180)
      • 7za.exe (PID: 4024)
      • 7za.exe (PID: 5344)
      • 7za.exe (PID: 1764)
      • 7za.exe (PID: 668)
      • 7za.exe (PID: 900)
      • 7za.exe (PID: 6576)
      • 7za.exe (PID: 780)
      • 7za.exe (PID: 2340)
      • 7za.exe (PID: 7036)
      • 7za.exe (PID: 3676)
      • 7za.exe (PID: 6272)
      • 7za.exe (PID: 4944)
      • 7za.exe (PID: 5552)
      • 7za.exe (PID: 7084)
      • 7za.exe (PID: 5428)
      • 7za.exe (PID: 3304)
      • YandexDisk2.exe (PID: 1764)
      • TextInputHost.exe (PID: 5548)
      • StartMenuExperienceHost.exe (PID: 2568)
      • SearchApp.exe (PID: 7080)
      • YandexNotes.exe (PID: 1912)
      • YandexDisk3Installer-5089.exe (PID: 2384)
    • Reads the computer name

      • YandexDisk30Setup.exe (PID: 1168)
      • YandexDisk30Setup_x64.exe (PID: 6736)
      • YandexDisk30Setup_x64.exe (PID: 2088)
      • StartMenuExperienceHost.exe (PID: 2568)
      • TextInputHost.exe (PID: 5548)
      • SearchApp.exe (PID: 7080)
      • YandexDisk3Installer-5089.exe (PID: 2384)
    • Creates files in the program directory

      • YandexDisk30Setup.exe (PID: 1168)
    • Reads the machine GUID from the registry

      • YandexDisk30Setup.exe (PID: 1168)
      • YandexDisk30Setup_x64.exe (PID: 6736)
      • SearchApp.exe (PID: 7080)
    • Reads the software policy settings

      • YandexDisk30Setup.exe (PID: 1168)
      • YandexDisk30Setup_x64.exe (PID: 6736)
      • SearchApp.exe (PID: 7080)
    • Checks proxy server information

      • YandexDisk30Setup.exe (PID: 1168)
      • YandexDisk30Setup_x64.exe (PID: 6736)
      • SearchApp.exe (PID: 7080)
      • explorer.exe (PID: 732)
    • Process checks computer location settings

      • YandexDisk30Setup_x64.exe (PID: 6736)
      • StartMenuExperienceHost.exe (PID: 2568)
      • SearchApp.exe (PID: 7080)
    • Create files in a temporary directory

      • YandexDisk30Setup_x64.exe (PID: 6736)
      • 7za.exe (PID: 4724)
      • 7za.exe (PID: 4696)
      • 7za.exe (PID: 900)
      • 7za.exe (PID: 2504)
      • 7za.exe (PID: 2420)
      • 7za.exe (PID: 1568)
      • 7za.exe (PID: 4180)
      • 7za.exe (PID: 4024)
      • 7za.exe (PID: 5344)
      • 7za.exe (PID: 1764)
      • 7za.exe (PID: 780)
      • 7za.exe (PID: 900)
      • 7za.exe (PID: 6576)
      • 7za.exe (PID: 2340)
      • 7za.exe (PID: 7036)
      • 7za.exe (PID: 3676)
      • 7za.exe (PID: 6272)
      • 7za.exe (PID: 668)
      • 7za.exe (PID: 7084)
      • 7za.exe (PID: 5428)
      • 7za.exe (PID: 3304)
      • 7za.exe (PID: 4944)
      • 7za.exe (PID: 5552)
    • The sample compiled with english language support

      • 7za.exe (PID: 4724)
      • 7za.exe (PID: 4696)
      • 7za.exe (PID: 2420)
      • 7za.exe (PID: 1568)
      • 7za.exe (PID: 5344)
      • YandexDisk30Setup_x64.exe (PID: 6736)
      • 7za.exe (PID: 4024)
      • 7za.exe (PID: 668)
    • Failed to create an executable file in Windows directory

      • YandexDisk30Setup_x64.exe (PID: 6736)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 732)
    • Reads Environment values

      • SearchApp.exe (PID: 7080)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:07:31 14:08:55+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 2677760
InitializedDataSize: 1552384
UninitializedDataSize: -
EntryPoint: 0x211f6d
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 3.2.41.5053
ProductVersionNumber: 3.2.41.5053
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Russian
CharacterSet: Unicode
CompanyName: Яндекс
FileDescription: YandexDiskSetup
FileVersion: 3.2.41.5053
InternalName: YandexDiskSetup
LegalCopyright: © 2016-2024 ООО "ЯНДЕКС"
OriginalFileName: YandexDiskSetup.exe
ProductName: Яндекс.Диск
ProductVersion: 3.2.41.5053
Tag040904B0: -
Tag041F04B0: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
190
Monitored processes
59
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start yandexdisk30setup.exe sppextcomobj.exe no specs slui.exe no specs yandexdisk30setup_x64.exe yandexdisk30setup_x64.exe 7za.exe no specs conhost.exe no specs 7za.exe conhost.exe no specs 7za.exe conhost.exe no specs 7za.exe conhost.exe no specs 7za.exe conhost.exe no specs 7za.exe conhost.exe no specs 7za.exe no specs conhost.exe no specs 7za.exe conhost.exe no specs 7za.exe conhost.exe no specs 7za.exe no specs conhost.exe no specs 7za.exe conhost.exe no specs 7za.exe no specs conhost.exe no specs 7za.exe no specs conhost.exe no specs 7za.exe no specs conhost.exe no specs 7za.exe no specs conhost.exe no specs 7za.exe no specs conhost.exe no specs 7za.exe no specs conhost.exe no specs 7za.exe no specs conhost.exe no specs 7za.exe no specs conhost.exe no specs 7za.exe no specs conhost.exe no specs 7za.exe no specs conhost.exe no specs 7za.exe conhost.exe no specs 7za.exe conhost.exe no specs explorer.exe no specs yandexdisk2.exe yandexnotes.exe no specs textinputhost.exe no specs startmenuexperiencehost.exe no specs searchapp.exe yandexdisk3installer-5089.exe no specs mobsync.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
536\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe7za.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
668"C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe" x "C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\chrome_elf.dll.zip" -aoa -o"C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac"C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe
YandexDisk30Setup_x64.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip Standalone Console
Exit code:
0
Version:
9.20
Modules
Images
c:\users\admin\appdata\local\temp\yandexdisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
668\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe7za.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
732"C:\Windows\explorer.exe" /LOADSAVEDWINDOWSC:\Windows\explorer.exeYandexDisk30Setup_x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
780"C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe" x "C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\snapshot_blob.bin.zip" -aoa -o"C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac"C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exeYandexDisk30Setup_x64.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip Standalone Console
Exit code:
0
Version:
9.20
Modules
Images
c:\users\admin\appdata\local\temp\yandexdisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
896\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe7za.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
900"C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe" x "C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\libcairo-2.dll.zip" -aoa -o"C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac"C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe
YandexDisk30Setup_x64.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip Standalone Console
Exit code:
0
Version:
9.20
Modules
Images
c:\users\admin\appdata\local\temp\yandexdisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
900"C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe" x "C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\icudtl.dat.zip" -aoa -o"C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac"C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exeYandexDisk30Setup_x64.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip Standalone Console
Exit code:
0
Version:
9.20
Modules
Images
c:\users\admin\appdata\local\temp\yandexdisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
1116\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe7za.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1168"C:\Users\admin\AppData\Local\Temp\YandexDisk30Setup.exe" C:\Users\admin\AppData\Local\Temp\YandexDisk30Setup.exe
explorer.exe
User:
admin
Company:
Яндекс
Integrity Level:
MEDIUM
Description:
YandexDiskSetup
Version:
3.2.41.5053
Modules
Images
c:\users\admin\appdata\local\temp\yandexdisk30setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\wldap32.dll
Total events
29 259
Read events
28 968
Write events
267
Delete events
24

Modification events

(PID) Process:(6736) YandexDisk30Setup_x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\Yandex.Disk.2
Operation:delete valueName:PerUserInstallType
Value:
(PID) Process:(6736) YandexDisk30Setup_x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\Yandex.Disk.2.Installer3
Operation:delete valueName:InstallerPath
Value:
(PID) Process:(6736) YandexDisk30Setup_x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YandexDisk2
Operation:delete valueName:UninstallString
Value:
(PID) Process:(6736) YandexDisk30Setup_x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\Yandex.Disk.2
Operation:writeName:TelemostIsSeparateApplication
Value:
1
(PID) Process:(2088) YandexDisk30Setup_x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\Yandex.Disk.2.Installer3
Operation:delete valueName:InstallerPath
Value:
(PID) Process:(2088) YandexDisk30Setup_x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YandexDisk2
Operation:delete valueName:UninstallString
Value:
(PID) Process:(2088) YandexDisk30Setup_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Yandex\Yandex.Disk.2.Installer3
Operation:delete valueName:InstallerPath
Value:
(PID) Process:(2088) YandexDisk30Setup_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YandexDisk2
Operation:delete valueName:UninstallString
Value:
(PID) Process:(2088) YandexDisk30Setup_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Yandex\Yandex.Disk.2
Operation:writeName:MachineInstallPathWow64
Value:
C:\Program Files (x86)\Yandex\YandexDisk2\bin\
(PID) Process:(2088) YandexDisk30Setup_x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Yandex\Yandex.Disk.2
Operation:writeName:TelemostIsSeparateApplication
Value:
1
Executable files
24
Suspicious files
95
Text files
96
Unknown types
0

Dropped files

PID
Process
Filename
Type
1168YandexDisk30Setup.exeC:\ProgramData\Yandex\Yandex.Disk.2\{3FE0EF39-1462-4094-9A42-43B4EE3C383B}\YandexDisk30Setup_x64.exe
MD5:
SHA256:
25047za.exeC:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\YandexDisk2.exe
MD5:
SHA256:
6736YandexDisk30Setup_x64.exeC:\Users\admin\AppData\Roaming\Yandex\YandexDisk2\3.2.43.5089\YandexDisk2.exe
MD5:
SHA256:
1168YandexDisk30Setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9CB4373A4252DE8D2212929836304EC5_1AB74AA2E3A56E1B8AD8D3FEC287554Ebinary
MD5:5315B836FCE5A7237A28A113178F76B9
SHA256:7DBE0393F54E21BEC22A7CCCAA820257B20897CF85998A49284F472920B3FD8F
6736YandexDisk30Setup_x64.exeC:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\YandexDisk2.exe.zipcompressed
MD5:FE75F17C1E2FD1EC1EC376DB8B48BF06
SHA256:F8FE46FE01A890854EE5A36B5612C73089C78A58BC0081BA6704EFA3C99AAD46
1168YandexDisk30Setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9CB4373A4252DE8D2212929836304EC5_1AB74AA2E3A56E1B8AD8D3FEC287554Ebinary
MD5:21718B8E471B22B8B3B85E429BA2E7F8
SHA256:8CBB527F409E646E117601CBB9A2F8C39347F6189F5CDDA7B73D0641C588269E
1168YandexDisk30Setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\357F04AD41BCF5FE18FCB69F60C6680F_394487CAFBCFB8C5917AD7A10924C8A7binary
MD5:AAC84679343D44C5A539094C99EB8C0C
SHA256:596D112901FAD0AED88BC5057056A2F00CC59B49A6521231C154F7AD1E131B5E
46967za.exeC:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\YandexDiskScreenshotEditor.exeexecutable
MD5:A897E6EC56F7154E6574824DAB79D6D9
SHA256:1DB0553DCE9F40C48ACF3B528C7EE146DE4620BEB8AD4A43597C67F4EA3F65C3
6736YandexDisk30Setup_x64.exeC:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exeexecutable
MD5:42BADC1D2F03A8B1E4875740D3D49336
SHA256:C136B1467D669A725478A6110EBAAAB3CB88A3D389DFA688E06173C066B76FCF
6736YandexDisk30Setup_x64.exeC:\Users\admin\AppData\Roaming\Yandex\YandexDisk2\3.2.43.5089\YandexDiskScreenshotEditor.exeexecutable
MD5:A897E6EC56F7154E6574824DAB79D6D9
SHA256:1DB0553DCE9F40C48ACF3B528C7EE146DE4620BEB8AD4A43597C67F4EA3F65C3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
33
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1168
YandexDisk30Setup.exe
GET
200
151.101.194.133:80
http://ocsp.globalsign.com/codesigningrootr45/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQVFZP5vqhCrtRN5SWf40Rn6NM1IAQUHwC%2FRoAK%2FHg5t6W0Q9lWULvOljsCEHe9DgW3WQu2HUdhUx4%2Fde0%3D
unknown
whitelisted
1168
YandexDisk30Setup.exe
GET
200
151.101.194.133:80
http://ocsp.globalsign.com/gsgccr45evcodesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQaCbVYh07WONuW4e63Ydlu4AlbDAQUJZ3Q%2FFkJhmPF7POxEztXHAOSNhECDG8SbJzCh95FjOiQ9g%3D%3D
unknown
whitelisted
6736
YandexDisk30Setup_x64.exe
GET
200
151.101.66.133:80
http://crl.globalsign.net/root.crl
unknown
whitelisted
6736
YandexDisk30Setup_x64.exe
GET
200
151.101.66.133:80
http://ocsp2.globalsign.com/gscodesigng2/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRruLd2WRFk6cRYGFIqkQ4J8hxDogQUCG7YtpyKv%2B0%2B18N0XcyAH6gvUHoCEhEhD%2FZGK2PVWvuqgfnHNKeqlA%3D%3D
unknown
whitelisted
4724
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4724
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7080
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
1168
YandexDisk30Setup.exe
213.180.204.148:443
webdav.yandex.ru
YANDEX LLC
RU
whitelisted
1168
YandexDisk30Setup.exe
77.88.21.127:443
downloader.disk.yandex.ru
YANDEX LLC
RU
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.32.133:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
google.com
  • 142.250.184.238
whitelisted
webdav.yandex.ru
  • 213.180.204.148
whitelisted
downloader.disk.yandex.ru
  • 77.88.21.127
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 40.126.32.133
  • 20.190.160.20
  • 40.126.32.136
  • 20.190.160.65
  • 20.190.160.131
  • 20.190.160.22
  • 20.190.160.4
  • 20.190.160.128
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
ocsp.globalsign.com
  • 151.101.194.133
  • 151.101.66.133
  • 151.101.2.133
  • 151.101.130.133
whitelisted

Threats

No threats detected
No debug info