ytab_setup.exe

Boris Vladimirovich BOBOVSKY

The setup package is an adware installer (using InstalleRex) that will deploy with little or no user consent adware offerings including but not limited to browser extensions (add-ins, toolbars) that will inject various forms of advertising in the user's browser. The application ytab_setup.exe by Boris Vladimirovich BOBOVSKY has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the WebPick InstalleRex installer.
Publisher:
Boris Vladimirovich BOBOVSKY  (signed and verified)

MD5:
7e9a309e5d8602bf986ae709b7730996

SHA-1:
bc3886e2f48029fe308ae692c83ac81dc87c6014

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Bundles additional adware products (monetized browser extensions, ad injectors) in the installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/19/2024 7:58:50 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WebPick.BorisVladimirovichBOBOVSKY.Bundler (M)
16.2.28.6

File size:
1.6 MB (1,665,488 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
WebPick InstalleRex

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\addons\ytab_setup.exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
12/27/2013 8:31:44 AM

Valid to:
12/27/2014 8:31:44 AM

Subject:
E=bob@borr.info, CN="Open Source Developer, Boris Vladimirovich BOBOVSKY", O=Boris Vladimirovich BOBOVSKY, C=UA

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
1ADBC4E5D3604FB9725702528437E82A

File PE Metadata
Compilation timestamp:
1/2/2014 1:54:31 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:/jZAuHdBA9PX2IgoAgBDfYeagzijnyj9IthEHCPR/s26fqxu2:6UdiVXh5BDAe5zqyjqtNPx6f8u2

Entry address:
0xD91B

Entry point:
E8, 7E, 44, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 98, DB, 41, 00, E8, DF, 12, 00, 00, E8, CB, 0F, 00, 00, 0F, B7, F0, 6A, 02, E8, 11, 44, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 96, 01, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.9378  (probably packed)

Code size:
86 KB (88,064 bytes)

The file ytab_setup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to i1.stylefun.info  (198.7.61.118:80)

TCP (HTTP):
Connects to dl.softservers.net  (184.154.145.171:80)

TCP (HTTP):
Connects to c1.getapplicationmy.info  (54.201.215.30:80)

Remove ytab_setup.exe - Powered by Reason Core Security