yandex.exe

Yandex Installer

YANDEX LLC

The application yandex.exe by YANDEX has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from browser.yandex.com.tr and multiple other hosts.
Publisher:
YANDEX LLC  (signed and verified)

Product:
Yandex Installer

Version:
40.0.2214.3645

MD5:
7c96ac45f39b1e1c0a8a441d9cc5fd80

SHA-1:
c1f6b8f5567e90ead070460fae9901ae28de5814

SHA-256:
42779efa8a88efcf86f22e08e0f170fdaa9cc15de9f50e935c6fa308fe26f595

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/18/2024 8:15:06 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Yandex.Installer.Meta (L)
16.7.8.11

File size:
2.1 MB (2,172,368 bytes)

Product version:
40.0.2214.3645

Copyright:
Copyright © 2012-2014 YANDEX LLC. All Rights Reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\yandex.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/15/2013 2:00:00 AM

Valid to:
1/16/2016 1:59:59 AM

Subject:
CN=YANDEX LLC, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=YANDEX LLC, L=Moscow, S=Moscow, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3667E158B524C8FFBFE538172786F1E2

File PE Metadata
Compilation timestamp:
3/1/2015 1:25:50 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
49152:7KNTp3vWU6yTKvf5Se5aAPcZbAdMSMcmzkQ:7U3vWByuvRSF+cZkMSM

Entry address:
0x14723C

Entry point:
E8, 03, 15, 01, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 53, 8B, 5D, 10, 8B, C3, 56, 83, E8, 00, 0F, 84, DD, 16, 00, 00, 48, 0F, 84, C5, 16, 00, 00, 48, 0F, 84, 8F, 16, 00, 00, 48, 0F, 84, 3E, 16, 00, 00, 8B, 55, 0C, 48, 0F, 84, AC, 15, 00, 00, 8B, 75, 08, 57, 83, FB, 20, 0F, 82, A1, 04, 00, 00, 8B, 06, 3B, 02, 0F, 84, 80, 00, 00, 00, 0F, B6, F8, 0F, B6, 02, 2B, F8, 74, 16, 33, C9, 85, FF, 0F, 9F, C1, 8D, 0C, 4D, FF, FF, FF, FF, 85, C9, 0F, 85, 9B, 08, 00, 00, 0F, B6, 7E, 01, 0F, B6, 42, 01, 2B, F8, 74, 16, 33...
 
[+]

Code size:
1.4 MB (1,481,728 bytes)

The file yandex.exe has been seen being distributed by the following 50 URLs.

https://browser.yandex.com.tr/.../?partner_id=350041&utm_referrer=http://www.oyunkolu.com/3d-oyunlar/maynkiraft.html?oyunu=oyna&_rdr=safe&lite=1

https://browser.yandex.com.tr/.../?partner_id=350041&utm_referrer=http://www.oyunkolu.com/3d-oyunlar/counter-strike-16-online.html?oyunu=oyna&_rdr=safe&lite=1

https://browser.yandex.com.tr/.../?partner_id=350041&download_date=1440886426&.exe

https://browser.yandex.com.tr/.../?partner_id=350041&utm_referrer=http://www.oyunkolu.com/3d-oyunlar/3d-polis-arabasi-park-etme.html?oyunu=oyna&banerid=6500000000:eyJpZHMiOlsiMjQ0NDY3ODkiXSwicmVmIjoiaHR0cCUzQSUyRiUyRnd3dy5veXVua29sdS5jb20lMkYzZC1veXVubGFyJTJGM2QtcG9saXMtYXJhYmFzaS1wYXJrLWV0bWUuaHRtbCUzRm95dW51JTNEb3luYSIsInVhIjoiTW96aWxsYS81LjAgKFdpbmRvd3MgTlQgNi4zOyBXT1c2NCkgQXBwbGVXZWJLaXQvNTM3LjM2IChLSFRNTCwgbGlrZSBHZWNrbykgQ2hyb21lLzUxLjAuMjcwNC44NCBTYWZhcmkvNTM3LjM2IiwiaXAiOiIzMS4yMDYuMTgyLjI4IiwidXJsIjoiL2Rlc2t0b3AvP3BhcnRuZXJfaWQ9MzUwMDQxIiwiaG9zdCI6ImJyb3dzZXIueWFuZGV4LmNvbS50ciIsInl1aWQiOiIzMjE1MTM2NzgxNDU5Nzc2NzE1In0=&zih=1&lite=1

https://browser.yandex.com.tr/.../?partner_id=350041&utm_referrer=http://www.oyunkolu.com/3d-oyunlar/minecraft.html?oyunu=oyna&banerid=6500000000&zih=1&lite=1

https://browser.yandex.com.tr/.../?partner_id=350041&download_date=1453898903&.exe

https://browser.yandex.com.tr/.../?partner_id=350041&utm_referrer=http://www.oyunkolu.com/3d-oyunlar/3d-sniper-egitimi.html?oyunu=oyna&banerid=6500000000&zih=1&lite=1

https://browser.yandex.com.tr/.../?partner_id=350041&utm_referrer=http://www.oyunkolu.com/nisan-oyunlari/counter-strike.html?oyunu=oyna&banerid=6500000000&zih=1&lite=1

https://browser.yandex.com.tr/.../?partner_id=350041&download_date=1454258346&.exe

https://browser.yandex.com.tr/.../?partner_id=350041&utm_referrer=http://www.oyunkolu.com/3d-oyunlar/minecraft-dunyasi.html?oyunu=oyna&banerid=6500000000&zih=1&lite=1

https://browser.yandex.com.tr/.../?partner_id=350041&download_date=1450633252&.exe

https://browser.yandex.com.tr/.../?partner_id=350041&banerid=6500000000:eyJpZHMiOlsiMjQ0NDY3ODkiXSwicmVmIjoiaHR0cCUzQSUyRiUyRnd3dy5veXVua29sdS5jb20lMkYzZC1veXVubGFyJTJGY291bnRlci1zdHJpa2UtMTYtb25saW5lLmh0bWwlM0ZveXVudSUzRG95bmEiLCJ1YSI6Ik1vemlsbGEvNS4wIChXaW5kb3dzIE5UIDYuMzsgV09XNjQpIEFwcGxlV2ViS2l0LzUzNy4zNiAoS0hUTUwsIGxpa2UgR2Vja28pIENocm9tZS81MS4wLjI3MDQuMTA2IFNhZmFyaS81MzcuMzYiLCJpcCI6IjJhMDI6NmI4OmIwMTA6MzAwZDo6NCIsInVybCI6Ii9kZXNrdG9wLz9wYXJ0bmVyX2lkPTM1MDA0MSIsImhvc3QiOiJicm93c2VyLnlhbmRleC5jb20udHIiLCJ5dWlkIjoiNDY5ODc4MzU3MTQzNzI0MjcyOSJ9&utm_referrer=http://www.oyunkolu.com/3d-oyunlar/counter-strike-16-online.html?oyunu=oyna&zih=1&lite=1

https://browser.yandex.com.tr/.../?partner_id=350041&download_date=1454155031&.exe

https://browser.yandex.com.tr/download/.../cGFydG5lcl9pZD0zNTAwNDEiLCJob3N0IjoiYnJvd3Nlci55YW5kZXguY29tLnRyIiwieXVpZCI6IjcxOTg0OTMyMTE0NjAyNzY5NjYifQ==&zih=1&lite=1

https://browser.yandex.com.tr/.../?partner_id=350041&download_date=1442652513&.exe

https://browser.yandex.com.tr/.../?partner_id=350041&utm_referrer=http://www.oyunkolu.com/3d-oyunlar/subway-surfers.html?oyunu=oyna&_rdr=safe&lite=1

https://browser.yandex.com.tr/.../?partner_id=350041&banerid=6500000000:eyJpZHMiOlsiMjQ0NDY3ODkiXSwicmVmIjoiaHR0cCUzQSUyRiUyRnd3dy5veXVua29sdS5jb20lMkYzZC1veXVubGFyJTJGM2QtdGFrc2ktc2ltdWxhc3lvbnUuaHRtbCUzRm95dW51JTNEb3luYSIsInVhIjoiTW96aWxsYS81LjAgKFdpbmRvd3MgTlQgMTAuMDsgV09XNjQpIEFwcGxlV2ViS2l0LzUzNy4zNiAoS0hUTUwsIGxpa2UgR2Vja28pIENocm9tZS81MS4wLjI3MDQuMTAzIFNhZmFyaS81MzcuMzYiLCJpcCI6IjJhMDI6NmI4OmIwMTA6NTAzYjo6NSIsInVybCI6Ii9kZXNrdG9wLz9wYXJ0bmVyX2lkPTM1MDA0MSIsImhvc3QiOiJicm93c2VyLnlhbmRleC5jb20udHIiLCJ5dWlkIjoiNjQyMjk4Nzk1MTQ2NjgwMDQxNCJ9&utm_referrer=http://www.oyunkolu.com/3d-oyunlar/3d-taksi-simulasyonu.html?oyunu=oyna&zih=1&lite=1

https://browser.yandex.com.tr/.../?partner_id=350041&download_date=1450022031&.exe

https://browser.yandex.com.tr/.../?partner_id=350041&download_date=1441475415&.exe

https://browser.yandex.com.tr/.../?partner_id=350041&utm_referrer=http://www.oyunkolu.com/3d-oyunlar/minecraft.html?oyunu=oyna&_rdr=safe&lite=1

https://browser.yandex.com.tr/.../?partner_id=350041&utm_referrer=http://www.oyunkolu.com/3d-oyunlar/kung-fu-dede-kacis.html?oyunu=oyna&banerid=6500000000&zih=1&lite=1

https://browser.yandex.com.tr/.../?partner_id=350041&download_date=1451827917&.exe

https://browser.yandex.com.tr/.../?partner_id=350041&download_date=1452009480&.exe

https://browser.yandex.com.tr/.../?partner_id=350041&download_date=1453637411&.exe

https://browser.yandex.com.tr/.../?partner_id=350041&download_date=1433584113

https://browser.yandex.com.tr/download/.../cGFydG5lcl9pZD0zNTAwNDEiLCJ5dWlkIjoiNTY2MjgxMTYwMTQ2NjYwNjU1OCJ9&zih=1&lite=1

https://browser.yandex.com.tr/.../?partner_id=350041&download_date=1445081151&.exe

https://browser.yandex.com.tr/.../?partner_id=350041&utm_referrer=http://www.oyunkolu.com/dovus-oyunlari/drunken-wrestlers.html?oyunu=oyna&_rdr=safe&lite=1

https://browser.yandex.com.tr/.../?partner_id=350041&download_date=1434018109

https://browser.yandex.com.tr/.../?partner_id=350041&download_date=1453743126&.exe

Latest 30 of 80 download URLs

Remove yandex.exe - Powered by Reason Core Security