yandex.exe

Yandex Installer

Yandex LLC

The application yandex.exe by Yandex has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from www.yandex.com.tr and multiple other hosts. While running, it connects to the Internet address cache-turk01.cdn.yandex.net on port 443.
Publisher:
Yandex LLC  (signed and verified)

Product:
Yandex Installer

Version:
47.0.2526.7146

MD5:
4a78b1a7ae5121bb8fe9a2274f435029

SHA-1:
a903cc59efc3e9694a45eec23a482e9891bc112d

SHA-256:
53662978f5656948e64db3e4c8e437b7502a1f7b79661076bf183c5326ec17f6

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/2/2024 8:22:55 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Yandex.Installer.Meta (L)
16.5.18.0

File size:
648.1 KB (663,672 bytes)

Product version:
47.0.2526.7146

Copyright:
Copyright © 2012-2015 YANDEX LLC. All Rights Reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\yandex.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
11/17/2015 6:42:24 PM

Valid to:
11/17/2017 6:42:24 PM

Subject:
E=pki@yandex-team.ru, CN=Yandex LLC, OU=Yandex LLC, O=Yandex LLC, L=Moscow, S=Moscow, C=RU

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112193734B618EB980DF4E9ED51D45352EB7

File PE Metadata
Compilation timestamp:
3/17/2016 4:46:56 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:/CCz+5/qQs+dwfQy9KzEVwYTX+OnEckJDMfFeU1l:KE+5/qtrV4YTuOELZG

Entry address:
0x21213

Entry point:
E8, 3B, D3, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 83, EC, 10, 83, 7D, 10, 00, 0F, 84, 9B, 00, 00, 00, 53, 56, 57, FF, 75, 14, 8D, 4D, F0, E8, CD, DC, FF, FF, 8B, 7D, 08, BE, FF, FF, FF, 7F, 85, FF, 74, 0E, 8B, 5D, 0C, 85, DB, 74, 07, 8B, 4D, 10, 3B, CE, 76, 12, E8, 81, 1F, 00, 00, C7, 00, 16, 00, 00, 00, E8, 9F, D2, FF, FF, EB, 4D, 8B, 45, F0, 83, B8, A8, 00, 00, 00, 00, 75, 0F, 51, 53, 57, E8, 65, D4, 00, 00, 83, C4, 0C, 8B, F0, EB, 32, 2B, FB, 0F, B6, 04, 1F, 8D, 4D, F0, 51, 50, E8, BF, DE, FF, FF, 8D...
 
[+]

Code size:
225 KB (230,400 bytes)

The file yandex.exe has been seen being distributed by the following 2 URLs.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to cdn.yandex.net  (5.45.205.232:443)

TCP (HTTP SSL):
Connects to cache-turk01.cdn.yandex.net  (5.255.197.17:443)

Remove yandex.exe - Powered by Reason Core Security