bestvideodownloadersetup.exe

Best Video Downloader

Alactro LLC

This is the installer/setup program for a Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application bestvideodownloadersetup.exe by Alactro has been detected as adware by 9 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from download.bestvideodownloader.com. While running, it connects to the Internet address api.yontoo.com on port 80 using the HTTP protocol.
Publisher:
Alactro LLC  (signed and verified)

Product:
Best Video Downloader

Description:
Installer

Version:
2011.8.19.1357

MD5:
1abdfa7dd550513acc25c0b08d94009f

SHA-1:
eabbba76622edac1f1c4db557cd76cf1204163d3

SHA-256:
30b4766f04f210aaef20631c54dc799fd76066a32a27f3e638f87468ecb55e16

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Belongs to the Sambreel/Yontoo progam that inserts various forms of advertising in the user's web browser, installed with minimal or no user consent.

Analysis date:
11/15/2024 12:50:53 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Adware.Generic
7.1.1

Avira AntiVirus
ADWARE/Yontoo.Gen2
7.11.109.96

Baidu Antivirus
AdWare.Win32.Yontoo
4.0.3.14514

Comodo Security
UnclassifiedMalware
17153

Dr.Web
Adware.Plugin.8
9.0.1.0134

ESET NOD32
Win32/Adware.Yontoo (variant)
8.8962

NANO AntiVirus
Trojan.Win32.Plugin.cfldzw
0.26.0.55532

Reason Heuristics
PUP.Installer.Alactro.Y
14.8.8.0

VIPRE Antivirus
Yontoo
22700

File size:
1.2 MB (1,249,696 bytes)

Product version:
1.00

Copyright:
Copyright (c) 2011 Alactro LLC. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\bestvideodownloadersetup.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
5/26/2011 2:13:23 PM

Valid to:
5/26/2012 2:13:23 PM

Subject:
CN=Alactro LLC, O=Alactro LLC, L=Carlsbad, S=CA, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
27E40C73BA04BA

File PE Metadata
Compilation timestamp:
3/10/2011 7:55:28 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:2bfU+Co0GFyhqFniAAC8i87eHkx21vDlk84ufz7zTmCGZW:3Po4hmn99TweH8QDlka7/eW

Entry address:
0x15B4

Entry point:
55, 8B, EC, 81, EC, CC, 05, 00, 00, 53, 56, 33, DB, 57, C6, 85, 34, FA, FF, FF, 00, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 00, 40, 40, 00, FF, 15, 70, 30, 40, 00, 89, 45, F8, 8D, 85, 3C, FE, FF, FF, 50, C7, 85, 3C, FE, FF, FF, 94, 00, 00, 00, FF, 15, 6C, 30, 40, 00, 85, C0, 75, 21, FF, 15, 14, 30, 40, 00, 50, 68, A8, 32, 40, 00, E8, 36, FA, FF, FF, 59, C7, 05, 04, 40, 40, 00, FF, 00, 00, 00, E9, 20, 02, 00, 00, 8B, 35, 68, 30, 40, 00, 68, 94, 32, 40, 00, 68, 84, 32, 40, 00, FF, D6, 50, FF, 15, 64, 30, 40...
 
[+]

Entropy:
7.9971

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file bestvideodownloadersetup.exe has been seen being distributed by the following URL.

http://download.bestvideodownloader.com/BestVideoDownloaderSetup.exe

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to wac.edgecastcdn.net  (72.21.81.13:80)

TCP (HTTP):
Connects to service.yontoo.com  (8.25.35.148:80)

TCP (HTTP):
Connects to api.yontoo.com  (8.25.35.15:80)

Remove bestvideodownloadersetup.exe - Powered by Reason Core Security