yac.exe

The application yac.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from 113.171.224.175 and multiple other hosts.
MD5:
251827e06a9f1e0a2263d8950e622465

SHA-1:
48136f2b2c76216094aa196ecd6e66a9f9ff1b1f

SHA-256:
0981c99055143e6fff4693e8e96b1825f3e39efc3a1a289ddcd0d11282cc912d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 8:07:25 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex.YAC (M)
16.6.17.18

File size:
13.7 MB (14,342,932 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\yac.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
393216:Rzava62O8XIKTEB0Vr4s16yHt0+MpCIumM:RzU376EB04s16yHS+MduT

Entry point:
6D, 20, E6, F5, 7D, 46, 00, 59, 1E, 4C, 83, 60, 97, 80, 80, 00, 00, 00, 00, 00, 7D, 00, 00, 00, 00, 00, 00, 00, A4, 6E, 8D, 75, 00, 40, 57, D8, EA, C7, F9, 46, 17, 95, C1, 8F, 4A, 85, B6, 30, 47, F0, 3B, 4A, 3B, CD, 21, 13, 80, BB, 12, D1, 73, C2, 9C, C3, E8, 28, 77, 3A, 5D, BA, 7C, A5, 3B, 96, 46, D1, EA, 99, 05, 55, 3E, 50, F2, DC, D1, D5, D0, A7, 15, A1, CA, E3, 93, 9E, 2F, B6, 7E, E5, A6, 57, E2, 13, EE, 4E, DB, C5, 88, 76, DE, D7, AE, AB, 93, 5F, E0, E5, 44, F6, 8D, 05, 90, 78, BC, 64, 37, EE, 84, 1F...
 
[+]

The file yac.exe has been seen being distributed by the following 3 URLs.

http://113.171.224.175/.../yac.exe

Remove yac.exe - Powered by Reason Core Security