yandexdisksetupru.exe

Яндекс.Диск

YANDEX LLC

This is a setup and installation application. The file has been seen being downloaded from downloader.disk.yandex.ru and multiple other hosts.
Publisher:
Яндекс  (signed by YANDEX LLC)

Product:
Яндекс.Диск

Description:
YandexDiskSetup

Version:
1.4.4.4724

MD5:
fab98cc5a0391ca385963d1ecafc1228

SHA-1:
0f9effd69dbf29b6204fe378696aa75b9faf9e24

SHA-256:
1efa0f588a18b3ab17e0d6de174870229543ed4c331d99f2e7f1978615fb9320

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/12/2024 6:56:21 AM UTC  (today)

File size:
1.5 MB (1,546,664 bytes)

Product version:
1.4.4.4902

Copyright:
© 2012-2015 ООО "ЯНДЕКС"

Original file name:
YandexDiskSetup.dll

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\yandexdisksetupru.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/25/2015 1:44:52 PM

Valid to:
9/25/2017 1:44:52 PM

Subject:
E=pki@yandex-team.ru, CN=YANDEX LLC, O=YANDEX LLC, L=Moscow, S=Moscow, C=RU

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11210FF6462B63D55AFBAA81F9C734A7AA94

File PE Metadata
Compilation timestamp:
12/2/2015 3:31:30 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:x9z+6uqf0SF8rI+7nNnz6pJYcyIgYZnfTVizrRlnSNpZ3oEo+zEohC7Trw4KkN2A:xBf0SaV61yHKVIXgpZ3+7TrwIH8a

Entry address:
0x75661

Entry point:
E8, 17, B8, 00, 00, E9, 79, FE, FF, FF, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 69, 33, C0, 8A, 44, 24, 08, 84, C0, 75, 16, 81, FA, 00, 01, 00, 00, 72, 0E, 83, 3D, A8, CE, 55, 00, 00, 74, 05, E9, CE, B8, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83, E2, 03, C1, E9, 02, 74, 06, F3, AB, 85, D2, 74, 0A, 88, 07, 83, C7, 01, 83, EA, 01, 75, F6, 8B, 44...
 
[+]

Code size:
749.5 KB (767,488 bytes)

The file yandexdisksetupru.exe has been seen being distributed by the following 50 URLs.

https://downloader.disk.yandex.ru/share/57456fec0ed892b49830274c965bbee037aa62cdd8f3924bfb3621b5a157be35/56be076f/.../x-msdownload&fsize=1546664&hid=f42650a90ad2c4aa8e9e1dd70a657bbd&media_type=executable&tknv=v2&etag=fab98cc5a0391ca385963d1ecafc1228

https://downloader.disk.yandex.ru/share/fa3e7bfdede380d9f613744f127271d25ad76b0c66a852917592b12c35c224ce/5688046d/.../x-msdownload&fsize=1546664&hid=f42650a90ad2c4aa8e9e1dd70a657bbd&media_type=executable&tknv=v2&etag=fab98cc5a0391ca385963d1ecafc1228

https://downloader.disk.yandex.ru/share/105390b8f7047b3b2e37260af72fadd1db7bc080721e895939f51d02607e0499/568674ac/.../x-msdownload&fsize=1546664&hid=f42650a90ad2c4aa8e9e1dd70a657bbd&media_type=executable&tknv=v2&etag=fab98cc5a0391ca385963d1ecafc1228

https://downloader-default14d.disk.yandex.net/rshare/10f6bc4a7bda7dfc9bbea54678b940eab447ebe68d40f9de9f43f875e8b988a8/567f15bd/.../x-msdownload&fsize=1546664&hid=f42650a90ad2c4aa8e9e1dd70a657bbd&media_type=executable&tknv=v2&etag=fab98cc5a0391ca385963d1ecafc1228&rtoken=3cb9d8bd1317bf8724cdc29be74550f7&force_default=no&ycrid=na-1632f7ad365eeaf6cc776cf39b751497-downloader4g

https://downloader.disk.yandex.ru/share/544a1e268e45c2803ee858d79184b30a774b92e945a0161380ee09313d9eea63/566c1fe8/.../x-msdownload&fsize=1546664&hid=f42650a90ad2c4aa8e9e1dd70a657bbd&media_type=executable&tknv=v2&etag=fab98cc5a0391ca385963d1ecafc1228

https://downloader.disk.yandex.ru/share/e138de48faffa5a6cac1b9e1779012387cd412b4bab24b2c70047e57d420c919/566eeb05/.../x-msdownload&fsize=1546664&hid=f42650a90ad2c4aa8e9e1dd70a657bbd&media_type=executable&tknv=v2&etag=fab98cc5a0391ca385963d1ecafc1228

Latest 30 of 79 download URLs

Scan yandexdisksetupru.exe - Powered by Reason Core Security