y_installer.exe

Yahoo New Tab & Search

Visicom Media Inc.

This is part of the Visicom VMN web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application y_installer.exe, “Yahoo New Tab & Search Installer” by Visicom Media has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address visicom-83.nationalnet.com on port 443.
Publisher:
Visicom Media Inc.  (signed and verified)

Product:
Yahoo New Tab & Search

Description:
Yahoo New Tab & Search Installer

Version:
1.0.0.2

MD5:
b80812b1cf6c94283a65d04503b9d77a

SHA-1:
1a091c78f050d45cc84f5697377413bb1bbd64cd

SHA-256:
0a2a951a53ded1f8c485ca878c89b869ef6dda736a9272d1937b32197a05620f

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/14/2024 2:58:59 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Visicom (M)
17.3.3.5

File size:
343.3 KB (351,520 bytes)

Product version:
1.0.0.2

Copyright:
Copyright 1996-2017 Visicom Media Inc.

Trademarks:
Yahoo New Tab & Search is a trademark of Visicom Media Inc.

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\y_installer.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
2/8/2017 4:00:00 AM

Valid to:
2/13/2019 3:59:59 AM

Subject:
CN=Visicom Media Inc., OU=Visicom Media Inc., O=Visicom Media Inc., L=brossard, S=Quebec, C=CA

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
3CFA6262847A2117C1487969214E39EA

File PE Metadata
Compilation timestamp:
12/6/2009 2:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9472

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP SSL):
Connects to visicom-83.nationalnet.com  (69.50.129.56:443)

Remove y_installer.exe - Powered by Reason Core Security