downloader.exe

Setup Downloader

YANDEX LLC

This is a setup and installation application. This is installed with multiple programs including Yandex.Disk. The file has been seen being downloaded from cache-novosibmgf02.cdn.yandex.net and multiple other hosts.
Publisher:
YANDEX LLC  (signed and verified)

Product:
Setup Downloader

Version:
0.1.0.31

MD5:
70fe52d099713fd74b6ac07cc5c9703b

SHA-1:
b4f1692fbd5038f27f1e7c37db23047b0fb5b03f

SHA-256:
304318534e2d5d671d90185cff006716ffe488b3607f11d73caea2b58aa759d9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 4:20:26 PM UTC  (today)

File size:
177.3 KB (181,544 bytes)

Product version:
0.1.0.31

Copyright:
Copyright (C) 2015 Yandex LLC

Original file name:
downloader.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\downloader.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/15/2013 5:00:00 AM

Valid to:
1/16/2016 4:59:59 AM

Subject:
CN=YANDEX LLC, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=YANDEX LLC, L=Moscow, S=Moscow, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3667E158B524C8FFBFE538172786F1E2

File PE Metadata
Compilation timestamp:
3/5/2015 7:28:41 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
3072:q79ht0sZHwSYteJF/xnVVq+OYkdG3u89rMQLNyBknk:q7qsKQ0jnAt4Bknk

Entry address:
0x9A36

Entry point:
E8, 5A, 88, 00, 00, E9, 7F, FE, FF, FF, 57, 56, 8B, 74, 24, 10, 8B, 4C, 24, 14, 8B, 7C, 24, 0C, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, 68, 03, 00, 00, 0F, BA, 25, A4, A9, 42, 00, 01, 73, 07, F3, A4, E9, 17, 03, 00, 00, 81, F9, 80, 00, 00, 00, 0F, 82, CE, 01, 00, 00, 8B, C7, 33, C6, A9, 0F, 00, 00, 00, 75, 0E, 0F, BA, 25, 70, 94, 42, 00, 01, 0F, 82, DA, 04, 00, 00, 0F, BA, 25, A4, A9, 42, 00, 00, 0F, 83, A7, 01, 00, 00, F7, C7, 03, 00, 00, 00, 0F, 85, B8, 01, 00, 00, F7, C6, 03, 00, 00, 00...
 
[+]

Code size:
118.5 KB (121,344 bytes)

The file downloader.exe has been discovered within the following programs.

DevID Agent  by DevID
About 6% of users remove it
Yandex.Disk  by Yandex
Publisher's description - “Files on Yandex.Disk won't get lost if your phone or computer breaks. You'll have enough storage space for your most precious photos and important documents. Share your Yandex.Disk files with family, colleagues or friends. You control who has access to your files.”
disk.yandex.ru
20% remove it
 
Powered by Should I Remove It?

The file downloader.exe has been seen being distributed by the following 50 URLs.

http://cache-novosibmgf02.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

https://cache-default03d.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

http://cache-mskdataline06.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

http://cache-turk04.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

http://browser.yandex.ru/.../?from=link_main_search_10_|&banerid=0401030266&download_date=1412519829&.exe

http://cache-mskdataline05.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

http://cache-ektmts06.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

http://cache-mskdataline02.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

http://cache-vladmts05.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

http://cache-mskdataline03.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

http://cache-mskdataline04.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

http://cache-novosibbln01.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

http://cache-mskdataline10.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

http://cache-spb05.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

http://cache-novosibmgf05.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

http://cache-mskdataline07.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

http://cache-novosibbln02.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

http://cache-ash01.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

http://cache-mskdataline09.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

http://cache-mskdataline01.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

http://cache-spb06.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

http://cache-novosibbln05.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

https://cache-default06d.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

https://cache-default04h.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

https://cache-default05e.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

http://cache-mskm906.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

https://cache-default06f.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

http://cache-krasmts03.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

https://cache-default04f.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

http://cache-stav01.cdn.yandex.net/download.yandex.ru/yandex-pack/.../downloader.exe

Latest 30 of 205 download URLs

Scan downloader.exe - Powered by Reason Core Security