yet_another_cleaner_kwo.exe

yacdl

Elex do Brasil Participações Ltda

The application yet_another_cleaner_kwo.exe, “standard installer” by Elex do Brasil Participaçõesa has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from s2s.yac.mx and multiple other hosts.
Publisher:
Elex do Brasil Participações Ltda  (signed and verified)

Product:
yacdl

Description:
standard installer

Version:
1.0.108.22616

MD5:
5d0b317d4318bc77c06ecf84a285ed16

SHA-1:
aa6249696c0f7f323b3bdd5f55fe0c67271cda8b

SHA-256:
df840bbc49115126ab87f58dccf5e4cc01bed659092ad4bbcd50432c0f75e26b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 12:26:37 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.Installer.ELEX
15.2.6.13

File size:
2.1 MB (2,213,088 bytes)

Product version:
1.0.108.22616

Copyright:
Copyright 2011-2014 Elex do Brasil Participações Ltda. All rights reserved.

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\yet_another_cleaner_kwo.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/23/2014 2:00:00 AM

Valid to:
6/21/2015 1:59:59 AM

Subject:
CN=Elex do Brasil Participações Ltda, O=Elex do Brasil Participações Ltda, L=São Paulo, S=São Paulo, C=BR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5C6950D0A05A1CD63164D1E1EB1FFB8A

File PE Metadata
Compilation timestamp:
4/10/2010 2:19:23 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:o0aC2fscqRgLufzFj/MUwdLW/tYeDDhneCv0863mJ/QvAono9RXORMGHvS8MtMlA:oLnLS9dDlT6fkIZjnYqtIGoeVVLQ

Entry address:
0x33E9

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 70, 85, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 55, FF, 15, B0, 82, 40, 00, 6A, 08, A3, 78, 06, 47, 00, E8, 67, 27, 00, 00, 55, 68, B4, 02, 00, 00, A3, 90, 05, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 6C, 85, 40, 00, FF, 15, 80, 81, 40, 00, 68, 54, 85, 40, 00, 68, 80, 85, 46, 00, E8, 35, 26, 00, 00, FF, 15, B0, 80, 40, 00, 50, BF, A0, 10, 4C, 00, 57, E8, 23, 26, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)

The file yet_another_cleaner_kwo.exe has been seen being distributed by the following 50 URLs.

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=v2M7p9vrz542LLXkiW3CHlkerWSjGmZEHK3bhxfiEIu0qpsJrIj0RzVPmGYgBVMo4TYpu6ssXybnodAZuVUUMk2hPagxJ_vPLKldf6j3z1gn9FRtcv8YOAMnSo-z8BYOXVa7OZYlvfdTbo6Wp_kFCaL3HmAtJye4Ve4f5JQDv2jM4vLuDjSq3xx7niqHaVk0Be5787ScVuIOmMWlM32STgEcElvW2v4nqxLnx2kZSeetXNWacT9Bji7aXRsZ9hvujTRbWcLqc8gqXbLe-2FiXnN0ik2XD9uLTTRtboYeCFC7WXPEJZ0V49lCtlapG_KV2U1Ti9DVhP4KmtEp69emWf-XaKIGkTcZs6zNcqK-zw84GCbKzbqxSBk3NrR8Pe3Uje52UTCPX372IGyAi7DQJbUY4CeDRKf9pnhiyMh41ishxASD08Mr&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://www.yac.mx/download/.../down.php?pt=gam&subid=11656

http://mmtrkjy.com/mt/.../&subid1=29556873061423036430

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=4nbjXycCLUxr8nzYRAlgkLrDOT3RVsey1RNXzEoL4wrxg-jtWbcghvJCGIiOQOFToOA_rbECbqqQUFyiX2W980lgdd8iUno_FLvDFheCn4_oNMds5_jENUys6ZJ_rDZyQrgV8sN4pX6jy3jBvstR1B1SEh61ifNMueP8EZEXUe0fdxauBX-Ts3I0a7j06l9DeezDmVfX_SZ_y6jesghPOpT4bNKno6UP55LGR-tEbXW6OFvUAlyOM6zLXaKJIiVrgCiM45pdrXf3QgL5JarJRcSFXsurmvTlVu8wlUr-8peDmPeZpK7r338Y46pvR76DohPxmXynIWM0VAhzm1DRkOZKaiojjXWcQ8ZtVDaYXV8FwIjsqWoiPR6WSyXbFK-_Y0aEWtH4cdjJkNpUH5yqfx4nbR479fP00ZDDh__s31tMFKupQdY&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=c2PKm5Gtc6pQ2Bqkkr-L8Vw6jXG3BeNERKsuyOotBU3Dy8RsmCdmlLzzwsxEkvWsIsmdDTcHV4ofIY6rOFb2t0k7EmyE7sgROuacZ-CIDuCtx237tLZDaNpB7ogI42pQf2MZY7vUU0HTmW8RZYrZHYchP_nSuY146PSFMnjjudYnGOK7X1eKFsQ9Iq-zBUqp4dtFPrQeA4yNerPclP7iySun_cqxGTAX-OMOIB7yYjlkFociprEkF4VQ058KxJs9Ghs8l3vJedeyRDPmT2B9iUxfxs5kMPwnKu5rpmSUXb0nwnbtooEyCLdP8l1rWteRCA3IaB9YUnTXWZU0nz9K-4y56zAM-5oktwIYjSWCSjXgWJs_bDLK3wd0cVr_nKH0qGsVP76gaipLm8xug8-gkzT6DbCJQNMWSWe-8uSmlWdFvdpC&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://mmtrkjy.com/mt/.../&subid1=29557599201423492844

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=wYdfI7DYqR6ibqm1nlZ0TnpJbXZnyE3zBdRfHNhQ3PCSccMtcONXDR0BnPYRyYPTZ2Wij328dQQlKMKHCmlUQzn4tpmRTC8MWxsAo7n1ufIBo_43Sel3gMNH7D-PMuRQQiwKS5foaldtJ7a765e_FjlUGYk9f1MdLOJ4FirVlz7BcunW-K-RrfW7V7MwZlUrIvgFLugUePqT8FgETP9FkRyPC-Pf4jhlimvBom9ZdGs3bAvlU6R1rRnYK2vNvjpux-kgZQcQz2MkxXVNLF4wfjvZPuEC5yAZXy8uMKujUIvgctmn5k6BiRAnXMM5BE_u9n6NQ4kNUyDFO-jqkZqQptSzi0W_5Wf_8gxDRAaaMhxtNENY4a5dTaMm267N_ujK8Pyvh4VQ5_4GOv2dmxrcI6UcnP1S0s9xNYVwsQ-0sHwLqKGK6r9UiPyv&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://dl2.yac.mx/download/.../yet_another_cleaner_muncd.exe

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=O6nuH075WTlRCAECntXO07i02HaUwmUK89nNsUBVOfQgJFkOz54XMvbAUn83FS0LnvTlLwzvBQwDgXFBdy9OA_JtX3yYDesaxlIXtvGiEYyhKLz3Zx93znxpV3RWji5O1Gtd6Y5wtvLg_PbkxL4zeRTTx3Eb8N_WxFV-AV1Y37qMjeZVgyh6ECOsz90ibu8hXrx-4TmaaIbfcC93nwR4xvyzFsvl2wIcw5jLGYwaEBuhg9LjDHjtoL5cTKUkLZqcT3ofUkF3l2VhN0xQU3x8JdelpaRFk-qjNO0S-oMb76IxZsqplQmCUnncLsSYjpW6on81vBIT6isEnKzMrnbTUdc-yxwdNFvISh7v_IdwdXZEQTEOdVDGH1nt9Gx7mwb-gsRCta5U0pE0-XtdEmhlGY4ANrmssSbLfR-yDT6qoOx2Jjtqog_3ZbCVgKYTcUACmKka&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=Ja8NHNaYx9ed50AWM8OEw5mqzjWra9gMIWJZIU8hlu9x43rWiLe58SU46KMy56s4JBz_yY6QFzTp84_CRChOIFp-ccLn-7G7ZhyMDdMyg9WhXIVKHVKgxa67TSMAsZCZka2uLzXro1iyCfq555CRgbfY-McgaSxtJQtVkDHjuoKFkvEJwFenuneDgrCTfh1JeWVLrvmoZhKkpG8QFfotQTdrSZ3F6BzYhsY7hHI8g04Y7CZZiqoftmaZE-NI89iu7kGeP2eaIp7wxSgOBsjSbEx_INFIN5gbcW0NDOYO4Kp7qvEo9D4roq2UCpqqBdv2cZorRP1Tdzjepv90g9VLzxWu5kkjkaegPFAdedVzNDJcptBcih2PPp7l9RkjptxjKQ09Rfr526hCP0zgb1fDmR5CHzwMmQo4QL1IT1onPA9JCnTY8aGOdHaFDewA&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://www.yac.mx/download/.../down.php?pt=dne&subid=

http://www.yac.mx/download/.../down.php?pt=mat&subid=152743

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=YiHNc5x95RUqmnnbCM-00YjkNjoZBbtthUqAhiIV7aebEZs4TJ0vjBmXLGMDqkPNCDaWbW-itew8Pu1sRUlBSox1Iycb1N46Qgd0IeuUvI2moBVAI6PFDk6xbYKp2xndKVxh-cJ6FFeW1sfi8EZXQDjvNgPRc_NSbzS0B25lIiiiuQ2npvNrQesJeTtwNUDh5t-17047kd7_hvimWyQfY8V7oJtX0kxUr3-rBM6mi1z1hwlBOPNB0iLyXLCscTkFZxTTFGg-pHCQvaUhbYIJUjMedkSUoTfTcGdwqkzIQeYCaw4QRmOKw9g8zASUs3dv9uuManfMtgsH-kHv4F50hq_sOSldIgJH4eAITM5AQwiYkcSKUGHYaCRBi4MTyyh3GqcaowelnkZ1fqCZFt1BYn8lHqzfcsX0XqoS1nfmetIhcX3Tew&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://www.yac.mx/download/.../down.php?pt=ymb&subid=16100

Latest 30 of 53 download URLs

Remove yet_another_cleaner_kwo.exe - Powered by Reason Core Security