yahoo_mobile_v3.exe

The application yahoo_mobile_v3.exe has been detected as a potentially unwanted program by 16 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from dnld.ironcust.com.
MD5:
ae10d6a84b30383b1dbcff833dbb9161

SHA-1:
df1ff20988eb8a8418c69d10bcb0a7af17c353ff

SHA-256:
d37282af6ba6cd168d8662e64424f5a08d77694efe22de244263eac0b68a540a

Scanner detections:
16 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/16/2024 4:30:55 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.52003
870

avast!
Win32:Installer-I [PUP]
140908-2

AVG
Generic
2015.0.3348

Bitdefender
Gen:Variant.Strictor.52003
1.0.20.1305

Emsisoft Anti-Malware
Gen:Variant.Strictor.52003
14.09.15

ESET NOD32
Win32/InstallCore.BH potentially unwanted application
7.0.302.0

F-Prot
W32/InstallCore.G4.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Strictor.52003
11.2014-18-09_5

G Data
Gen:Variant.Strictor.52003
14.9.24

K7 AntiVirus
Trojan
13.183.13407

MicroWorld eScan
Gen:Variant.Strictor.52003
15.0.0.783

Panda Antivirus
PUP/MultiToolbar.A
14.09.18.04

Reason Heuristics
Threat.Win.Reputation.IMP
15.8.11.23

Vba32 AntiVirus
3.12.26.3

VIPRE Antivirus
Threat.4786018
33120

File size:
623.6 KB (638,520 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\yahoo_mobile_v3.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:m5WeIrFoLLOizpaKsGApRBW9glTFnIG3H0jwg82cEZgTD:+ZcCOizIK8B5lTyG3HWwg84AD

Entry address:
0x13CFE0

Entry point:
60, BE, 00, D0, 4A, 00, 8D, BE, 00, 40, F5, FF, C7, 87, 10, 57, 0F, 00, 5E, 80, 18, 6E, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.8538

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
580 KB (593,920 bytes)

The file yahoo_mobile_v3.exe has been seen being distributed by the following URL.

Remove yahoo_mobile_v3.exe - Powered by Reason Core Security