yac.exe

The application yac.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from dl.yac.mx.
MD5:
f4c89d03a95cb8a9ecb692c394581dd2

SHA-1:
68742f14e3e683a535270d62f13e8d854666095d

SHA-256:
1340beb6c7d1e970b167fc223ff8410b30391891fcbba38cd58781a6dea8edc5

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/20/2024 12:34:36 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex.YAC (M)
16.6.17.18

File size:
13.7 MB (14,319,125 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\yac.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
196608:aMYzY7vvS1YRPUwr4z1j6kpHcW1mCoM70BHHBb9YPrwMjn9dGhquIx/r1vyweeom:adzava1scwM12xW8uS9eMMjnLGB71J6

Entry point:
6D, 20, E6, F5, 7D, 46, 00, 59, 01, 02, BA, 40, 94, 27, 80, 00, 00, 00, 00, 00, 7D, 00, 00, 00, 00, 00, 00, 00, BF, B2, E6, 2E, 00, 40, 57, D8, EA, C7, F9, 46, 17, 95, C1, B8, D1, 69, 0B, 29, AE, 63, 91, F8, 50, 8D, FA, 1D, C4, E1, 2C, 00, F9, DA, 12, 70, 84, 85, 12, 7F, A0, 55, BC, B9, 98, C5, 87, 2F, B9, D2, 08, B0, 2E, 3C, 4C, EB, 67, 0E, F2, 8D, BA, A9, 10, 79, 11, 6E, F1, FB, 30, A5, D9, CF, 58, 18, 89, 42, 01, EF, 89, 37, 57, C8, 5C, 89, CF, 1E, 4D, AF, 04, DB, 2D, 11, 8A, 4D, B9, 70, C3, 81, 7D, BD...
 
[+]

Entropy:
8.0000  (probably packed)

The file yac.exe has been seen being distributed by the following URL.

Remove yac.exe - Powered by Reason Core Security