yet_another_cleaner_cnt.exe

YAC Security Protection

Elex do Brasil Participações Ltda

The application yet_another_cleaner_cnt.exe by Elex do Brasil Participaçõesa has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from mmtrkjy.com and multiple other hosts.
Publisher:
Elex do Brasil Participações Ltda  (signed and verified)

Product:
YAC Security Protection

Description:
Setup

Version:
6.0.171.23102

MD5:
63e0830aca6ec2c2964586843878afb5

SHA-1:
db4d6728b3d82da795f74654d049f45160b53fd2

SHA-256:
be03204e3fb871e547114597d759095d4dc9038ba2e44e37e2bef606aaf77d36

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/27/2024 6:05:58 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.Installer.ELEX
15.3.5.8

File size:
18.9 MB (19,847,136 bytes)

Product version:
6.0.171.23102

Copyright:
Copyright (c) 2011-2014 Elex do Brasil Participações Ltda

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\yet_another_cleaner_cnt.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/23/2014 10:00:00 AM

Valid to:
6/21/2015 9:59:59 AM

Subject:
CN=Elex do Brasil Participações Ltda, O=Elex do Brasil Participações Ltda, L=São Paulo, S=São Paulo, C=BR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5C6950D0A05A1CD63164D1E1EB1FFB8A

File PE Metadata
Compilation timestamp:
3/3/2015 8:46:36 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
393216:5wwc7e5WF51tQkS36eY4KEP4r2Bl1qt4JOoeksabBZSysw2UIpuDu0M/rLfYL1Zj:G7YWFzSKMChta1ekjbBZSYLBDu0M/rcL

Entry address:
0x3F7C2

Entry point:
E8, 9E, 1A, 01, 00, E9, 39, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, 3C, F5, 90, 29, 48, 00, 00, 75, 13, 56, E8, 91, 00, 00, 00, 59, 85, C0, 75, 08, 6A, 11, E8, B0, 88, 00, 00, 59, FF, 34, F5, 90, 29, 48, 00, FF, 15, 78, E0, 46, 00, 5E, 5D, C3, E8, 41, 29, 00, 00, 85, C0, 75, 0B, FF, 74, 24, 04, 50, FF, 15, 5C, E2, 46, 00, 68, FF, 00, 00, 00, E8, 58, 87, 00, 00, 59, C3, 56, 57, BE, 90, 29, 48, 00, 8B, FE, 53, 8B, 1F, 85, DB, 74, 17, 83, 7F, 04, 01, 74, 11, 53, FF, 15, AC, E0, 46, 00, 53, E8, 8F, BE, FF...
 
[+]

Entropy:
7.9318  (probably packed)

Code size:
433 KB (443,392 bytes)

The file yet_another_cleaner_cnt.exe has been seen being distributed by the following 34 URLs.

http://mmtrkjy.com/mt/.../&subid1=31705153301426032572

http://www.softonic.com/sads/tracker.php?ev=c&co=ES&sid=bee89441c830fc8a03ac055ebf0e3660&upv=2f21105d8503ad8fbadec2c4ea4d5b3a&z=results&sk=0&abt=&eid=&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAC9B15663BFCC32A4B420C96190DC24F2C4EC6E561351677C77086EC499320CAC3CA5E7EB440B9F07FCB18AD5BF214204C928115CED1814963D5F04BB0E0A5F70CB805F124E203DD4B267FC5F763B1323CD12E48AE03118C9C1ADC0242867478F7B50CFB4EDFD1B07E255D4E1958E4B369ECE03D73707504779AD1218CF05EC4047CAA77A77FB0FC3588D7D641EAAC7D491F10E217EF4349EA7772EC100C55D9F&h=B590D886CD14807EBF6E5D92E67A3A1D1BA4C444015DE338A33C77C9409865D8&directdownload=1&f=69665508&d=http://dl.yac.mx/download/.../yet_another_cleaner_sftc.exe

http://www.softonic.it/sads/tracker.php?ev=c&co=IT&sid=490cfcb6e065980f3e2358542a1217d2&upv=46220c1e97e158d4b1c023ed88d8689b&z=results&sk=0&abt=&eid=&params=F24F8F4D368AFA5D32C8A90D9EFD1CBADD0CB244B8D47EE8EF2B6FDF0EA0CE237E8B55F716ADC97C70D5F4DB55B100F52B99BFFE4D97830D754403A3750929189819C8BE305B8D969481ECA843FA18CB6498DD70EAF8E8622C2A0514F40A41AC09E51F71DB8CD5243EF7B3D529CE788B900DECDFA5B1F95B5D1966E3B77910B26E4F8C22C96AD8488A79EC4861FDE338B7D2A98D4027A4E67F7CC7FC7900A6B61FF7712484058A4106D9FF147229D996&h=3456A64A8C562BE7167E9F44D24541B98E25B0F2B1055A93C295C45B30BA3392&directdownload=1&f=69665508&d=http://dl.yac.mx/download/.../yet_another_cleaner_sftc.exe

http://www.softonic.com/sads/tracker.php?ev=c&co=ES&sid=dc6935a24ef3e7ae50646c12958a3521&upv=ee53371068eb252db73526154a0bb600&z=results&sk=0&abt=&eid=&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAC9B15663BFCC32A4B420C96190DC24F2C4EC6E561351677C77086EC499320CAC9B8E047912B5F50B29CA76B7BF0DA2F4FC8DDA59D6914735D24819B583A8F1E1643EA0F99E25760D7BF809D05372D3416741965916D72964AC54918D9D3A5C220C705BA12CAFCAA0C6DEADC19A3A7E6BD12CA4FAC851AC1C2FFAE91C1F67B17C05D5DBF9189C605497306EE74DC37871B5A1EAD3EB3BE1940DAABD20263061A0&h=A6793DEA2A55DC7B15A059365DC205F30BACA9A77DC76AA7A4C1E61EC3CF36DC&directdownload=1&f=69665508&d=http://dl.yac.mx/download/.../yet_another_cleaner_sftc.exe

http://www.softonic.com/sads/tracker.php?ev=c&co=ES&sid=95b2a3e5a059834194cd1ada70be5977&upv=747d3319a0fb9b90c83cd3346776c4af&z=results&sk=0&abt=&eid=&params=F24F8F4D368AFA5D32C8A90D9EFD1CBAC9B15663BFCC32A4B420C96190DC24F2C4EC6E561351677C77086EC499320CAC3CA5E7EB440B9F07FCB18AD5BF214204C928115CED1814963D5F04BB0E0A5F70CB805F124E203DD4B267FC5F763B1323E5CC1F243E5EE61B4A80F0D1F1BD1E131A5E9EBCD50516EBD8A9F99D120D1D8374B21741C7091B965A76FD7285F8DF84CB6D0DA696406573DF64534C209AFE568EB3D63F302E09B0483A82EB818746D8&h=ABC239E8AEB374EAF6797406B0A9D21ED735CD1B55F2B4BCE3A1F2D211ECCA8F&directdownload=1&f=69665508&d=http://dl.yac.mx/download/.../yet_another_cleaner_sftc.exe

http://www.softonic.it/sads/tracker.php?ev=c&co=IT&sid=5ad83a8a453814ce126c15d8f978fd3c&upv=6310555b784254478907db032d97190b&z=results&sk=0&abt=&eid=&params=F24F8F4D368AFA5D32C8A90D9EFD1CBADD0CB244B8D47EE8EF2B6FDF0EA0CE237E8B55F716ADC97C70D5F4DB55B100F5959C9F7BBC6266E2ED40D8E7A7F3945080BDD09C71C4C6BB29E0E389E2639E5DC83598062969E9152662AD2634ED91EA89D3BFC357839D87D50E5D3FABB2F3C9E4F97DC446A40E510D77C54631D153620E73693A9EFBF706C44B093E91DE99E5558E5C95F5873BAD91370312CB38F5A0AD82ED1D7E14ADD0A11725D7DCCFCBC4&h=C00426DA0327D624EDFD5705D9E02C66E16929AC45416442C6269C7994F022AC&directdownload=1&f=69665508&d=http://dl.yac.mx/download/.../yet_another_cleaner_sftc.exe

http://mmtrkjy.com/mt/.../&subid1=u6dff5aaa547eda5819dc48fe53

http://mmtrkjy.com/mt/.../&subid1=7832125921427043517

http://www.yac.mx/download/.../down.php?pt=mav&subid=

http://mmtrkjy.com/mt/.../&subid1=30494197761425602515

Latest 30 of 34 download URLs

Remove yet_another_cleaner_cnt.exe - Powered by Reason Core Security