yaps.exe

SteelBytes yaps

SteelBytes

This is a setup program which is used to install the application. The file has been seen being downloaded from doc-0k-08-docs.googleusercontent.com.
Publisher:
SteelBytes

Product:
SteelBytes yaps

Description:
yaps

Version:
1.2.2.47

MD5:
fc167612cef19f43576c5622d8468131

SHA-1:
98fd2d77dbfcbd96fd38ca1a55a40d9bf9a93943

SHA-256:
7f447f0a1d70bb8fc183eb123fcdc8907c7a1dbb1c7f3e9c1c8fca5808b733b7

Scanner detections:
6 / 68

Status:
Clean  (6 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
12/28/2024 11:08:27 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.Packed
1.3.0.4959

Comodo Security
Heur.Packed.Unknown
19846

ESET NOD32
Win32/NetTool.YASP.AA (variant)
8.10585

Quick Heal
(Suspicious) - DNAScan
10.14.14.00

Trend Micro House Call
HKTL_PORTSCAN
7.2.299

Trend Micro
HKTL_PORTSCAN
10.465.26

File size:
131.6 KB (134,732 bytes)

Product version:
1.2.2.47

Copyright:
Copyright © 2001-2011 SteelBytes

Original file name:
yaps.exe

File type:
Executable application (Win32 EXE)

Language:
English (Australia)

File PE Metadata
Compilation timestamp:
9/13/2011 11:53:59 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
3072:dp0Eq1bBGsOZ0eBiuEkmTF7l8iqAgYUm0/zhlZJce:UEq1Ms0lEvTF7XqAg5zpKe

Entry address:
0x24A00C

Entry point:
3B, C0, 74, 02, 81, 84, 55, 3B, DB, 74, 02, 81, 81, 53, 3B, ED, 74, 01, BA, 56, 3B, E4, 74, 02, 81, 86, 57, E8, 00, 00, 00, 00, 3B, E4, 74, 01, BC, 5D, 8B, D5, 81, ED, 2C, 10, 22, 01, 3B, C0, 74, 02, 81, 86, 2B, 95, 66, 11, 22, 01, 81, EA, 2C, 00, 00, 00, 80, BD, A4, 11, 22, 01, 00, 74, 18, 8B, 85, 8A, 11, 22, 01, 03, 85, 94, 11, 22, 01, 3B, C0, 74, 01, BC, 05, FA, 05, 00, 00, FF, E0, 3B, DB, 74, 01, B8, 8B, FA, 3B, C0, 74, 01, B9, 8D, 85, BC, 11, 22, 01, 50, 3B, DB, 74, 02, 81, 83, FF, 95, 98, 11, 22, 01...
 
[+]

Entropy:
7.9644  (probably packed)

Code size:
210.5 KB (215,552 bytes)

The file yaps.exe has been seen being distributed by the following URL.

Scan yaps.exe - Powered by Reason Core Security