yandex.exe

Yandex

YANDEX LLC

The application yandex.exe by YANDEX has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. The file has been seen being downloaded from download.cdn.yandex.net. While running, it connects to the Internet address clck.yandex.ru on port 80 using the HTTP protocol.
Publisher:
YANDEX LLC  (signed and verified)

Product:
Yandex

Version:
17.1.1.1003

MD5:
9293409428bd6fccc2124fde7f5828be

SHA-1:
85fc7f538c9b19abc5f9419b20fec3ed405ebec1

SHA-256:
542ffe56bcc2f49a4a53e0c9b8bb45aa2cf2241be809d01b983df879b1e115aa

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 5:01:20 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Yandex (L)
17.2.15.15

File size:
2.9 MB (3,016,696 bytes)

Product version:
17.1.1.1003

Copyright:
Copyright © 2012-2016 YANDEX LLC. All Rights Reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\yandex.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/25/2015 1:44:52 PM

Valid to:
9/25/2017 1:44:52 PM

Subject:
E=pki@yandex-team.ru, CN=YANDEX LLC, O=YANDEX LLC, L=Moscow, S=Moscow, C=RU

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11210FF6462B63D55AFBAA81F9C734A7AA94

File PE Metadata
Compilation timestamp:
2/3/2017 6:19:59 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0x2E2E5

Entry point:
E8, BD, 08, 00, 00, E9, 8E, FE, FF, FF, CC, B9, 01, 00, 00, 00, F2, 0F, 10, 2D, 08, BA, 45, 00, EB, 1C, B9, 02, 00, 00, 00, F2, 0F, 10, 2D, 10, BA, 45, 00, EB, 0D, B9, 03, 00, 00, 00, F2, 0F, 10, 2D, 08, BA, 45, 00, 66, 0F, 7E, C0, 25, FF, FF, FF, 7F, 3D, 00, 00, 80, 7F, 0F, 83, 4C, 01, 00, 00, F3, 0F, 5A, C0, 83, F9, 02, 75, 18, F2, 0F, 10, 15, 28, BA, 45, 00, 66, 0F, 2F, C2, 76, 0A, BA, 10, 00, 00, 00, E8, 3D, 01, 00, 00, 66, 0F, 2F, C5, 0F, 83, 21, 01, 00, 00, F2, 0F, 10, 35, 00, BA, 45, 00, 66, 0F, 2F...
 
[+]

Code size:
329 KB (336,896 bytes)

The file yandex.exe has been seen being distributed by the following URL.

http://download.cdn.yandex.net/downloadable_soft/browser/.../Yandex.exe

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to api.browser.yandex.ru  (87.250.250.82:443)

TCP (HTTP):
Connects to clck.yandex.ru  (213.180.193.14:80)

TCP (HTTP):
Connects to cdn.yandex.net  (5.45.205.231:80)

TCP (HTTP):
Connects to cache-ams05.cdn.yandex.net  (5.45.247.13:80)

Remove yandex.exe - Powered by Reason Core Security