yet_another_cleaner_brof.exe

yacdl

Elex do Brasil Participações Ltda

The application yet_another_cleaner_brof.exe, “standard installer” by Elex do Brasil Participaçõesa has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from www.yac.mx and multiple other hosts.
Publisher:
Elex do Brasil Participações Ltda  (signed and verified)

Product:
yacdl

Description:
standard installer

Version:
1.0.108.22616

MD5:
3bf8523f02b8b3f7724ba36e00dbda25

SHA-1:
b76ec50d04734fc4db841842cd9a9b6071d02dfc

SHA-256:
add92fad9b8ef6ebe23ea5dff42feac644cde56de6c13e7fdf9917ac30c3bf07

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 2:21:37 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.Installer.ELEX
15.2.6.12

File size:
2.1 MB (2,213,088 bytes)

Product version:
1.0.108.22616

Copyright:
Copyright 2011-2014 Elex do Brasil Participações Ltda. All rights reserved.

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\yet_another_cleaner_brof.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/23/2014 1:00:00 AM

Valid to:
6/21/2015 12:59:59 AM

Subject:
CN=Elex do Brasil Participações Ltda, O=Elex do Brasil Participações Ltda, L=São Paulo, S=São Paulo, C=BR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5C6950D0A05A1CD63164D1E1EB1FFB8A

File PE Metadata
Compilation timestamp:
4/10/2010 1:19:23 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:3LOQXu03Ef0kfOPrcOV/dIyX6U6gU7tZZM1mlMdi/4tFj1XpF:3Lru0U8kfOPrBldIxgU7tZ61mlPM11

Entry address:
0x33E9

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 70, 85, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 55, FF, 15, B0, 82, 40, 00, 6A, 08, A3, 78, 06, 47, 00, E8, 67, 27, 00, 00, 55, 68, B4, 02, 00, 00, A3, 90, 05, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 6C, 85, 40, 00, FF, 15, 80, 81, 40, 00, 68, 54, 85, 40, 00, 68, 80, 85, 46, 00, E8, 35, 26, 00, 00, FF, 15, B0, 80, 40, 00, 50, BF, A0, 10, 4C, 00, 57, E8, 23, 26, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)

The file yet_another_cleaner_brof.exe has been seen being distributed by the following 50 URLs.

http://www.yac.mx/download/.../down.php?pt=matf&subid=128955

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=JqsSj6mmbaaKEhphSRjt9eLcEhIrEY37D_lwF6dD4oTF4Rm5PtBXLhnqIbm4qhfo2T6TuSb5iaqbJSOGbjeAzvTsQ27ag6-bG0LhnGHK2MZ-8orhrWsUFw_lRldAe--7dIdkwTteyDy-FPDiKORGR6ru4OT5Wtc7e2ISeHA23lyM2-qIiV7bE88SSScgdiXmgEV4NkKO1-YFPMo9n6Lx3mNSJv4deV7-jzqrdPERSfXW1WcHGyMWpF3eyJsdOcoUGqUDakx3P3AnAL6vXgp2YBigz6xziSE0oli75u15P6xRD6XR_oh8WoqwYrBtw6sSkGLg2TSNtX6jtAYgSsWQJt_jbIoERrtSIv71-Oswpm5KwEuTyF9EWn4OmpOpN5JCEtuniaqKeBFdUSMFfN8ux7fc9Iib1PtNCkG5Nmdcdg&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://www.yac.mx/download/.../down.php?pt=epo&subid=

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=ACUEX1DAeSK9UzZC0HgMC0KVKTdSRSsOhuTpOk0JrDYaLTbUl1mI5PKi0oarzEl4zWZOYrm43ldMYyh2SeScJZUqHSWJF6-lgowRlHtqLQXddFmXvBIu62Tibg0OOk0FGcaR6nBTTa3jiJPHI-Ie6AgH85LJICIIq5DiwIOfSx_8Wcmy16dmi3hFiESn3vTjUIC6JivG6Fm4T-GjsSGZkmSbnwHekRunUQPYkhybRm2CzjZbsFW8uXvzNEHg5K7NHFsS_ITPxl3fWgojW1jyXA6KD__mT-uYXtZG7_mA14_6b5z_FCL-Roq1MbjQwVOSmffP7f8cFzPICOB22x9DAyj2zlkP_lQhvVNNMMDxe4-eaoBZr4j7M7Jpb28teZrcnzWk6pJIFBvVrYan8bvYPL_Av-uIUeIRK4Zh6NDZN_tL&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=r3ABF9wecn54vW9xcM2RL1kLImBVmhDsZu8ksrtci61jamN4fmwTaygAApZAMSNctuhaI6oylxwX0W_5J-PMkweWCeOE5ZTp1QAvLBnHbvIOXf18zTeubmdDps9AovpZGHakWfY0vNEzVinffKKUwQKq3W1xVMS7qIljKTtwFCBJ2dWhChBJR-K5hZT-DBGcIMD6VAV7d3p6UqtaoFELo3BHia51j9czA1ESTpvT8_dtCMQuOyZ86LkOgpvJkzTdOJUOPXHpzIXTmCczDdoHrXSxt24MwxDiYhkW0lGMFqFNVnLjFJvO7R3Egv0MBHVYK5WhoC_bPkZccZdC0Mw4zFHx2DlaWnS7qGvNqtaGnAjBCnFVekCykkVhCN3E_946YSLO--vied1Md6i1o5hX2zqP7iZ1A7nE8LWmj_hUkcUWDdZ3aM2iqWAkjmzKt7PNHBOR&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://www.yac.mx/download/.../down.php?pt=gam&subid=12508

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=rHwM63KB_hhoPh2ny0nSZZAD4h22jkscHMqGxvnZMpAkuLKx9eByUkQwGpD1pg2g6COvn_xtcCL3lxHiEuts0AgrnySUoeeCgLbkOPOAKsrfqrqRyLEKxxFHWrc0gZuWAC3PXI-IbEdPX1cj2SenwEOI0BCzK4F7Cejc9weqwSaHuVc2oZZZ8gv5yTqB70N7eIHGOC3yi6mFWwVkBq49rCtHIeZXLPBM9eBRml-w-FmL_38CEyKAPx6XHL0xivDqeoqSrisLjS3x-4NeoZOixGBxj2BqKTWFAzCW1CIlspOW2_sI2oIolIm-YBrMbsoiW4-W1hklVGcXxAjRs6E62LKqtHU5VXQEq-9L8HmbI0yziaF0njeRDTFbRJG_S80dDms28Xgqh3Lumj3o4N4_hazTFtW38jh_h5axEa9zC53v&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=rYoVoZ0Q9A5-hlE8SOrLPBLYAcPtdErKn4v4Lk11ALsnUXLRl4-mKU1dbDBHeWZTrJNtlepAtQPehfZ4zZhXbFMN6Ry_AeJ41z_zjOhIX845eXNZhMG5R1SWDq0P9FxW5f13j3GVDPdPcMDB-diPRptZriVR4stCXepNK_HxGx9i1AEucit3lQ-OAY5Hj2T5h0z8_ytWtTnjg6cGvo6-u8plf5piMVEvuNt25dC30iiSX4YaYAZTKf7Rq_GHdoRfnVRP8762sHL5M8P7fvz8cR6KCESbsICIgmmHGOQyyR5XZGWiSTCBe5rfjpV8WpbdLl365TAQ65s6o7RbqqQWTs8dbVMMkZR3DPqcmHCNoB95CfsHBxR5xZuMEEcw9hprJZrHBmhgLFYNQV4ze0dfR8JaVwrkZOPek8LEEBoYFgH8WoA5Uw&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=mzlSP7YP_341s31k5KJ9TMYUgUm2INqvJqVtjWIuKaAdFJ3EwK2laT29Bb_QN5AcLhuO2L6VtHW05Q-2__9Pp61hyfK33QniNJ0sRmsqtg-Ow4Klp7KmApCzYEKOB1ROOuA4LpGBxKbUaOpg4Fr-8goAevwMp9P2RJYELu69bn4tzA2yJdVTzmFYffagDF3A1N6HSGMlQZRCj22t6Y5hvmWcaYhcskx2mvPw6F48OyN-NyLspUq9deCYmQd5T3TT4p2xgp75EPv2n_J4mhDPiMP4tWoA94-cy6x_IWTDS-EtTz2MB1a3g3US9CA7aMlvyxKU5fm0J8ZKa_55yMix2mJ1QAI996gGNpCKZM9MzXieEyqxfa456GELLgd5AT-Ew491dQsA_VN8iG63WNqhN2QM8J6hv2wx0N0Txc2lbPu46v6zjtulCcuqwJ2UkA&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=qwGYpK2uKXl7onhjUtVl2cVx0G2UH02dWPksI4wvJ2N5YasJlz4cjQJvcj86S6B1Lwu2LhgaVb-p6VitGy-fkymjqV91Kodd0_vc3CItyQk8PI3x004Tw5sbtFwuPg89HnhEjCsVoucL7DdnKgI6NkIZw8J7377g8mBEzbfxkY3l8bevHxVbv9Jd-qmKl-eIR1y9DOp49cAodph4TbZ9ellRfj8tfUSQcyknyHtijmChtbPpz3aSRVg4BsLLd__nBcDi3xESL5I8YqqepCORcZ1l7Z27VcKc1yOg76_7YOohkcrRxpPyW4HP2ghJe2WalwKP1IyCipAbtfxT_guHop7-bwE9orG_6x05gq5BbZsF6GSd8AvZNcYAiydkWyW1U6iR_AnCkzQGk46jzTq1p4JPuQyIM2YKD0j2tJ6K0xNZqoHiusDV4aiE&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=6a97SXgHfY0Dr1sKA33KU2xXEP4f5ItO7gdfWOJdF1kgFgqWic-Uo3rPjhsyHEMcbuA2yIaQfh91Hb3HCc8xUWjIaPpEYM7580JL3Pbk1qWgUoJy2H2cHAcRt7aDWQWpkRg3L_vm6eHa8NLBZJ2Cib1iZkFbpVJ8ayoAVMtk8Sjwq6tDG_q4HsZzu-yBHYxnVVA8_uI9KIODa5EAucL8yNqQVjlTS7PY5_F4lfpnzoUC_2aOEYmP84oHMHOlNANXKyBCb0_EE7-eh7iF9AZICb6_NUwzKYYLj0wlan9nktEBQGmkVJ4rbQw3dWuucYiXtLUySX4IRQ18n75iHEbD_Mn3jtRhAwA14uQ1VRY31qU6izXKoH8BdX_V13SDWkFvQZ75G20yf3aeKQsD4WUdEOQOdn2c4Q4vkobp5Zo&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=484IEQ4qaNyVCFVx9O9PZcEn_ZYvblS20T14Tr7oG3xYKdXEi1R5x1kHBE31JuoqsUlrjEwJ0_coal_WVCkrqBy3eP1QN7e6z9v4L7i7v-R1BUxsPCP3sAjV9LFh2GK3Ou2hjOa0y7AqxghaFJR0ReYt6cuRwQ4BNuiKjD0BDgDi2BA4puRTuww1WHtBIIJM_D-hL8Hj8wjA7mwYt1-NsmOa4CjsafKhbbMqc-kjVeE8J7IGErAneraCTL5tjLOtFlitpBvAIdG2IFGnBfi9FcWZ7HKY77I0Z1E8_AIoane4O2frLoWCD8QZqZZpBhE2rPzlHkixGwMiZQd8joh-9t1RauJiUidw2GfNuADgqoYZhAmxw5ZBlQN1b3Oc7zYfveKuZX_Et43YFOWigMMN35cB1ml07SLVWIaOsvlH8oz3va6KM60Jy-P4uA&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=QVJkA7V4XfML_ODpfQOecmsmIfsihxoxJe18CPfRKaDSbiKnG5E2Q6pOS80-mnv0NMqYGXpwDyjYXzHUQAuaMCSkgHglixBGyOynuirznhOJOLg-i8qXkgYYFVPwKtOZhED7gI_TfUEEP0HUlq8JjKSq6A5RlhrzMPjZQqa4fI8fJri4gli7fAy176dDtBCtE6pvIqKPjclAi4wFhA2Q6tuop7EULOQZjcJgvo2dEUngLn3kwET1IHEm1xmkrnYjs6OChOAIO3sd1WWFXPF4t4bPqRKDMZRegvlDe2VbL6Y-5JuROtgvQY_ZHe92n41t6Mw4l552DPWW56cfuKOSaaJ5zmbNRfphS4X5Hr7osdAWyRNw1-mu8Rf94l5daqCKYb7bl6o68_pnI77wk8-ei9izS0SupJhFERITS6k&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=yPbjl2JLims498LUX1s622c7ewtdfxHc9HRHKEmOq5YEd98SpjgTCiOL6iSLsPb-b4d0SdKIZPQktwv-suEsOLBzdQwBPP49m-r7GZmcPET8N-VfF3aTF4eTCfBekCJVjT_foo-gYBdrPHqDJUTOz6sQhRmSvYUwO5F-ldH3ptDzNsiyI1Cwy0JCy7FzL_74ZD8bB47PsmNZZ7L_WLUxdRllFahbLyllwEnclujhmJGT2hTL2o7IlFYCj4Dmmm_TMlPaAHGoc2CXQXWJK321ljSerL4ch7Zo_KFTBbD_KFoSOaLjyMOMiPregHGW77H_NpsySMiS7AGwGfIoAM3nexoafAUTfxgB7_gv5i54wXsJn-25DEl-UNMMHJxiKZ7BEJAEK_hCTmwI3hlZvmf4FXsjqkYVKcOMhqim9-QdG_uIqAf3bQ&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

Latest 30 of 61 download URLs

Remove yet_another_cleaner_brof.exe - Powered by Reason Core Security