ytdsetup.exe

The application ytdsetup.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from d1vdt3k7hski9t.cloudfront.net.
MD5:
6765dac3bd66184df5b6d5392cdacf20

SHA-1:
9342541b2d4540dcbb487b2689f5e9ff9c364812

SHA-256:
c683afa54b8561b23d75a4ef8c3ffeaf2879661353da3c6fdc3caed633948961

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/29/2024 2:59:55 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.YTD.Installer (M)
16.8.9.9

File size:
11 MB (11,494,880 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\ytdsetup.exe

File PE Metadata
Compilation timestamp:
2/24/2012 11:19:59 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
196608:bnODXGlkUQ0AxysiUKiRGEHrLXJJsEc3wG9YfrvLFQ8:bODcQ0SWyrLL3YCTFQ8

Entry address:
0x39E3

Entry point:
60, 0F, B7, C0, 1A, DF, B8, 22, 3F, 64, AC, 8B, C9, F3, 80, DB, 97, C6, C2, 35, 3A, CD, B8, 61, B2, 90, 96, 83, E2, 00, C6, C7, 5A, 0F, B6, E9, 22, FA, F3, 4B, 0F, AF, DA, 69, ED, 5C, 8D, A2, 0A, 0F, B6, FF, 87, C9, F6, C7, 8C, 84, DA, 68, 26, 0C, 00, 00, 3D, C1, 9F, 00, 00, 70, 06, 8D, 35, 2D, D5, F1, A5, 5D, BE, 90, 42, 43, 1C, 69, F8, 55, DD, 18, 8B, 81, ED, 84, 06, 00, 00, 86, E9, 85, CB, 55, 84, E1, 5B, 81, E9, F4, 54, D9, 31, 81, F3, 35, 08, 00, 00, 69, CD, 26, 9E, EA, 07, 53, 88, E5, F3, 58, 3B, F0...
 
[+]

Entropy:
7.6507

Code size:
28 KB (28,672 bytes)

The file ytdsetup.exe has been seen being distributed by the following URL.

Remove ytdsetup.exe - Powered by Reason Core Security