bestvideodownloadersetup.exe

Yontoo Layers Runtime

Alactro LLC

This is the installer/setup program for a Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application bestvideodownloadersetup.exe by Alactro has been detected as adware by 8 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from download.bestvideodownloader.com. While running, it connects to the Internet address api.yontoo.com on port 80 using the HTTP protocol.
Publisher:
Yontoo LLC  (signed by Alactro LLC)

Product:
Yontoo Layers Runtime

Description:
Installer

Version:
2011.6.20.2036

MD5:
fc9f24c75d410f02681470f0de6c6345

SHA-1:
069b8b1b583787a48b70e67a0d21786c7d1531aa

SHA-256:
c5787d0ed57dcc1cfb40ab9655f60f079706074ea3cadd810442dad7ead5c39a

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Belongs to the Sambreel/Yontoo progam that inserts various forms of advertising in the user's web browser, installed with minimal or no user consent.

Analysis date:
4/24/2024 8:06:13 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Adware.Generic
7.1.1

AVG
AdInject.Alactro
2016.0.3150

Comodo Security
UnclassifiedMalware
21518

ESET NOD32
Win32/Adware.Yontoo (variant)
9.11367

Fortinet FortiGate
Riskware/Yontoo
4/4/2015

Malwarebytes
PUP.Optional.Yontoo.A
v2015.04.04.05

Reason Heuristics
PUP.Installer.Yontoo
15.4.4.5

VIPRE Antivirus
Yontoo
38720

File size:
778.6 KB (797,256 bytes)

Product version:
1.10.01

Copyright:
Copyright (c) 2011 Yontoo LLC. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\bestvideodownloadersetup.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
5/27/2011 7:13:23 AM

Valid to:
5/27/2012 7:13:23 AM

Subject:
CN=Alactro LLC, O=Alactro LLC, L=Carlsbad, S=CA, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
27E40C73BA04BA

File PE Metadata
Compilation timestamp:
3/11/2011 1:55:28 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:VmzFk1A5AGbS6x5dWIKRlDMFlmUL779Xo0RKo1heFHIw1PQo/KAyRhlXR9aqDxPP:htxWKRlDMFlf/nAchkvPybRTXCA

Entry address:
0x15B4

Entry point:
55, 8B, EC, 81, EC, CC, 05, 00, 00, 53, 56, 33, DB, 57, C6, 85, 34, FA, FF, FF, 00, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 00, 40, 40, 00, FF, 15, 70, 30, 40, 00, 89, 45, F8, 8D, 85, 3C, FE, FF, FF, 50, C7, 85, 3C, FE, FF, FF, 94, 00, 00, 00, FF, 15, 6C, 30, 40, 00, 85, C0, 75, 21, FF, 15, 14, 30, 40, 00, 50, 68, A8, 32, 40, 00, E8, 36, FA, FF, FF, 59, C7, 05, 04, 40, 40, 00, FF, 00, 00, 00, E9, 20, 02, 00, 00, 8B, 35, 68, 30, 40, 00, 68, 94, 32, 40, 00, 68, 84, 32, 40, 00, FF, D6, 50, FF, 15, 64, 30, 40...
 
[+]

Entropy:
7.9936

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file bestvideodownloadersetup.exe has been seen being distributed by the following URL.

http://download.bestvideodownloader.com/BestVideoDownloaderSetup.exe

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to wac.edgecastcdn.net  (72.21.81.13:80)

TCP (HTTP):
Connects to service.yontoo.com  (8.25.35.148:80)

TCP (HTTP):
Connects to api.yontoo.com  (8.25.35.15:80)

Remove bestvideodownloadersetup.exe - Powered by Reason Core Security