| File name: | YandexDisk30Setup.exe |
| Full analysis: | https://app.any.run/tasks/b6d2626f-a2c3-429d-a0e2-79bf9257f6e4 |
| Verdict: | Malicious activity |
| Analysis date: | May 17, 2025, 01:29:39 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | 9C41B0517FACC6DF37AD1C06838655D3 |
| SHA1: | 0DCDF08F37CBA736CEDDE34E42C04DC50E161FE2 |
| SHA256: | EC8B052260B2D7D409B2FDEB24B0E1EEF0BC17071F02EDCE8F1BE1B1E058880D |
| SSDEEP: | 98304:szs00prqcvT4dYC1RgB7PSHD4OP8cv2GllillSigNVh3pui43gSh/CJl7UotNUH:GRZ2g |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:07:31 14:08:55+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.16 |
| CodeSize: | 2677760 |
| InitializedDataSize: | 1552384 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x211f6d |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.2.41.5053 |
| ProductVersionNumber: | 3.2.41.5053 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Russian |
| CharacterSet: | Unicode |
| CompanyName: | Яндекс |
| FileDescription: | YandexDiskSetup |
| FileVersion: | 3.2.41.5053 |
| InternalName: | YandexDiskSetup |
| LegalCopyright: | © 2016-2024 ООО "ЯНДЕКС" |
| OriginalFileName: | YandexDiskSetup.exe |
| ProductName: | Яндекс.Диск |
| ProductVersion: | 3.2.41.5053 |
| Tag040904B0: | - |
| Tag041F04B0: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 536 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | 7za.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 668 | "C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe" x "C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\chrome_elf.dll.zip" -aoa -o"C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac" | C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe | YandexDisk30Setup_x64.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: MEDIUM Description: 7-Zip Standalone Console Exit code: 0 Version: 9.20 Modules
| |||||||||||||||
| 668 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | 7za.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 732 | "C:\Windows\explorer.exe" /LOADSAVEDWINDOWS | C:\Windows\explorer.exe | — | YandexDisk30Setup_x64.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 780 | "C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe" x "C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\snapshot_blob.bin.zip" -aoa -o"C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac" | C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe | — | YandexDisk30Setup_x64.exe | |||||||||||
User: admin Company: Igor Pavlov Integrity Level: MEDIUM Description: 7-Zip Standalone Console Exit code: 0 Version: 9.20 Modules
| |||||||||||||||
| 896 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | 7za.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 900 | "C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe" x "C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\libcairo-2.dll.zip" -aoa -o"C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac" | C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe | YandexDisk30Setup_x64.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: MEDIUM Description: 7-Zip Standalone Console Exit code: 0 Version: 9.20 Modules
| |||||||||||||||
| 900 | "C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe" x "C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\icudtl.dat.zip" -aoa -o"C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac" | C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe | — | YandexDisk30Setup_x64.exe | |||||||||||
User: admin Company: Igor Pavlov Integrity Level: MEDIUM Description: 7-Zip Standalone Console Exit code: 0 Version: 9.20 Modules
| |||||||||||||||
| 1116 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | 7za.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1168 | "C:\Users\admin\AppData\Local\Temp\YandexDisk30Setup.exe" | C:\Users\admin\AppData\Local\Temp\YandexDisk30Setup.exe | explorer.exe | ||||||||||||
User: admin Company: Яндекс Integrity Level: MEDIUM Description: YandexDiskSetup Version: 3.2.41.5053 Modules
| |||||||||||||||
| (PID) Process: | (6736) YandexDisk30Setup_x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Yandex\Yandex.Disk.2 |
| Operation: | delete value | Name: | PerUserInstallType |
Value: | |||
| (PID) Process: | (6736) YandexDisk30Setup_x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Yandex\Yandex.Disk.2.Installer3 |
| Operation: | delete value | Name: | InstallerPath |
Value: | |||
| (PID) Process: | (6736) YandexDisk30Setup_x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YandexDisk2 |
| Operation: | delete value | Name: | UninstallString |
Value: | |||
| (PID) Process: | (6736) YandexDisk30Setup_x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Yandex\Yandex.Disk.2 |
| Operation: | write | Name: | TelemostIsSeparateApplication |
Value: 1 | |||
| (PID) Process: | (2088) YandexDisk30Setup_x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Yandex\Yandex.Disk.2.Installer3 |
| Operation: | delete value | Name: | InstallerPath |
Value: | |||
| (PID) Process: | (2088) YandexDisk30Setup_x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YandexDisk2 |
| Operation: | delete value | Name: | UninstallString |
Value: | |||
| (PID) Process: | (2088) YandexDisk30Setup_x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Yandex\Yandex.Disk.2.Installer3 |
| Operation: | delete value | Name: | InstallerPath |
Value: | |||
| (PID) Process: | (2088) YandexDisk30Setup_x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YandexDisk2 |
| Operation: | delete value | Name: | UninstallString |
Value: | |||
| (PID) Process: | (2088) YandexDisk30Setup_x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Yandex\Yandex.Disk.2 |
| Operation: | write | Name: | MachineInstallPathWow64 |
Value: C:\Program Files (x86)\Yandex\YandexDisk2\bin\ | |||
| (PID) Process: | (2088) YandexDisk30Setup_x64.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Yandex\Yandex.Disk.2 |
| Operation: | write | Name: | TelemostIsSeparateApplication |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1168 | YandexDisk30Setup.exe | C:\ProgramData\Yandex\Yandex.Disk.2\{3FE0EF39-1462-4094-9A42-43B4EE3C383B}\YandexDisk30Setup_x64.exe | — | |
MD5:— | SHA256:— | |||
| 2504 | 7za.exe | C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\YandexDisk2.exe | — | |
MD5:— | SHA256:— | |||
| 6736 | YandexDisk30Setup_x64.exe | C:\Users\admin\AppData\Roaming\Yandex\YandexDisk2\3.2.43.5089\YandexDisk2.exe | — | |
MD5:— | SHA256:— | |||
| 1168 | YandexDisk30Setup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9CB4373A4252DE8D2212929836304EC5_1AB74AA2E3A56E1B8AD8D3FEC287554E | binary | |
MD5:21718B8E471B22B8B3B85E429BA2E7F8 | SHA256:8CBB527F409E646E117601CBB9A2F8C39347F6189F5CDDA7B73D0641C588269E | |||
| 2088 | YandexDisk30Setup_x64.exe | C:\Users\admin\AppData\Local\Yandex\Yandex.Disk.2\YandexDiskInstaller.log | text | |
MD5:753CD3AD66F6766BF6EF18016555643F | SHA256:53C7AB03C018A778672296117360E3003AACCA3DCD56DCD1E12A4A0E7CA2531C | |||
| 6736 | YandexDisk30Setup_x64.exe | C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\7za.exe | executable | |
MD5:42BADC1D2F03A8B1E4875740D3D49336 | SHA256:C136B1467D669A725478A6110EBAAAB3CB88A3D389DFA688E06173C066B76FCF | |||
| 2420 | 7za.exe | C:\Users\admin\AppData\Local\Temp\YandexDisk-9d2493d4a6ec4492aad5a61fc10946ac\libpng14-14-x64.dll | executable | |
MD5:3F30DBAFCB7D089DC9BADC1965F52039 | SHA256:8ECE62BA54EF506B231A7EA5ABB55F8AA29B203746FCFC922BD112291E4258A9 | |||
| 1168 | YandexDisk30Setup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9CB4373A4252DE8D2212929836304EC5_1AB74AA2E3A56E1B8AD8D3FEC287554E | binary | |
MD5:5315B836FCE5A7237A28A113178F76B9 | SHA256:7DBE0393F54E21BEC22A7CCCAA820257B20897CF85998A49284F472920B3FD8F | |||
| 6736 | YandexDisk30Setup_x64.exe | C:\Users\admin\AppData\Roaming\Yandex\YandexDisk2\3.2.43.5089\YandexDisk3ShellExt-1511.dll | executable | |
MD5:3653CA11F37EDB8DBD60076559FCE552 | SHA256:3D0077A6A7CBB8A18BDAB7C2DDCDDAB358F7C9B6647413D29689BF43BF433DB5 | |||
| 1168 | YandexDisk30Setup.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\357F04AD41BCF5FE18FCB69F60C6680F_394487CAFBCFB8C5917AD7A10924C8A7 | binary | |
MD5:AAC84679343D44C5A539094C99EB8C0C | SHA256:596D112901FAD0AED88BC5057056A2F00CC59B49A6521231C154F7AD1E131B5E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.216.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1168 | YandexDisk30Setup.exe | GET | 200 | 151.101.194.133:80 | http://ocsp.globalsign.com/codesigningrootr45/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQVFZP5vqhCrtRN5SWf40Rn6NM1IAQUHwC%2FRoAK%2FHg5t6W0Q9lWULvOljsCEHe9DgW3WQu2HUdhUx4%2Fde0%3D | unknown | — | — | whitelisted |
1168 | YandexDisk30Setup.exe | GET | 200 | 151.101.194.133:80 | http://ocsp.globalsign.com/gsgccr45evcodesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQaCbVYh07WONuW4e63Ydlu4AlbDAQUJZ3Q%2FFkJhmPF7POxEztXHAOSNhECDG8SbJzCh95FjOiQ9g%3D%3D | unknown | — | — | whitelisted |
6736 | YandexDisk30Setup_x64.exe | GET | 200 | 151.101.66.133:80 | http://ocsp2.globalsign.com/gscodesigng2/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRruLd2WRFk6cRYGFIqkQ4J8hxDogQUCG7YtpyKv%2B0%2B18N0XcyAH6gvUHoCEhEhD%2FZGK2PVWvuqgfnHNKeqlA%3D%3D | unknown | — | — | whitelisted |
6736 | YandexDisk30Setup_x64.exe | GET | 200 | 151.101.66.133:80 | http://crl.globalsign.net/root.crl | unknown | — | — | whitelisted |
4724 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
4724 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
7080 | SearchApp.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.216.77.6:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.35.229.160:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1168 | YandexDisk30Setup.exe | 213.180.204.148:443 | webdav.yandex.ru | YANDEX LLC | RU | whitelisted |
1168 | YandexDisk30Setup.exe | 77.88.21.127:443 | downloader.disk.yandex.ru | YANDEX LLC | RU | whitelisted |
3216 | svchost.exe | 172.211.123.250:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6544 | svchost.exe | 40.126.32.133:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
webdav.yandex.ru |
| whitelisted |
downloader.disk.yandex.ru |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
ocsp.globalsign.com |
| whitelisted |