yet_another_cleaner_mat.exe

yacdl

Elex do Brasil Participações Ltda

The application yet_another_cleaner_mat.exe, “standard installer” by Elex do Brasil Participaçõesa has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from www.yac.mx and multiple other hosts.
Publisher:
Elex do Brasil Participações Ltda  (signed and verified)

Product:
yacdl

Description:
standard installer

Version:
1.0.71.19170

MD5:
06b3330538436899cea0a7d5aa6681f5

SHA-1:
202ad6ca22756f65584f03dd5167cf1c63499db5

SHA-256:
826896a2b6270c0e6c4a4195ac54223fd6e66ed8f626b8f04a824679652550db

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/25/2024 5:20:31 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.Installer.X
14.11.22.10

File size:
755.7 KB (773,808 bytes)

Product version:
1.0.71.19170

Copyright:
Copyright 2011-2014 Elex do Brasil Participações Ltda. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\yet_another_cleaner_mat.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/23/2014 5:30:00 AM

Valid to:
6/21/2015 5:29:59 AM

Subject:
CN=Elex do Brasil Participações Ltda, O=Elex do Brasil Participações Ltda, L=São Paulo, S=São Paulo, C=BR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5C6950D0A05A1CD63164D1E1EB1FFB8A

File PE Metadata
Compilation timestamp:
3/22/2010 6:29:04 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:Jc/tb3x3PzR8OUvSchKKFXQaJZgjdUD9Gk9re9fOwAPO1J0mJqv/qAIss:2VbhyJKchKKFNrUd5k5eAsJ0AgAs

Entry address:
0x114F

Entry point:
E9, AC, 55, 00, 00, E9, C7, 94, 00, 00, E9, 12, 99, 00, 00, E9, 6D, 94, 00, 00, E9, 88, A9, 00, 00, E9, 63, B9, 00, 00, E9, FE, 99, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC...
 
[+]

Entropy:
7.6909

Packer / compiler:
Xtreme-Protector v1.05

Code size:
57 KB (58,368 bytes)

The file yet_another_cleaner_mat.exe has been seen being distributed by the following 50 URLs.

http://www.yac.mx/download/.../down.php?pt=rke

http://ads.adsrvmedia.net/event/click/0/Q1vjwoBgEgIUdaTh51UUZYT6qoqID0sxcAybsIeTa0zKwAl3VBOmYVSPmrA_2GZDnTDaUMjQuuvuY0Kv62v7Jhp4LmWuIgcN0GLW9AD3PI7M5obGflhqy-MBKGpazNFl1QpeLvoPLXgZfETHClmo_1n2FlBghbf5RV6o4rUtH94s-UdB6hTc8R9myx2_fnvtwEyFACyfeQmQNpQzHgb4sK4hfdftRPc4G0CKXu7D5vs3PuF74CKtxQwP4836kda9BI1e_W3EIFpGhy3kQEQFoJXRndoEkOADVoJ8bB6CjoasY7Hdxn2dCzn2_Sb99k9XkgupnE-q0SrT2unafZgrDiHx0zORmTOva8h0phBU6Uxl-zcaEbCXr_ra0H_DmZn-Jixc3d2UJA8Kp2oEjmbxYD9T3ZRbkBsgZg-fgoF7l99MWyQ/.../

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=p2fd1S2-THo_sbro7xjQgxWqH32tudvkRhv536s6mGVbGKwTU9qNUqaA3L3EUaJkq_lpX79TDbvGLSsztnqRyRYB2rZYymx6RknU_boB-Mu37a56ImXBUltlY_xIfmL2wLNYweovtp2hO78OId_DONZ89NTrKvzw3hrEhKdiEDTKkUxFUqQo7OhfWo6PjfKE0C9PUEXM3v24NzOJ7k7xkmHM4O0JKwVp2rRn_NV1wpbsEjdPeuwesLlShUqgsda12JXYqMGmnBeEAseVRdwY9396i1pisa3w7sMKx836jy8ccUGs1UReoS5j_5teZKZiXC9Zk05T406zjvBWwIGosu8Y-xsl_XGodsfcRGxkqfmXimhYj0bcD4EVvQUrAo-hQG6NL1xo4Xn_dwKqyWg4JCtoofbHVkYY9673_go&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=z8b8LEar_e_JkUh3gv2U26OBC16MjNvKA2pO3ZXeKAtjo88_tOsUcwtjaVaR7xDE9R3SgyEqX3C_cZ1ILhvGiLuS4BhNKMOnG-krtj6PpAi1XkG2OUhy1GswCrg0mY32ePfXm9IoU---Wx7KYqmtQ77-2mpAbzsLPIw3KpnEFoYOvBLrlzMz7ZCObaYi-SuZewG-bbkYRvOleKeeVbBHGc8SJcfpWFDBlqLt_R1ju1JuxukFCBW8BY7bTT4wjtFQmdLBNTNR7VL4hLBSlsDKGUFJnStH4KG5dCe3K_c-u3I8dzRW1G99zCryoFZjthQ5uF1NLFg7B0pQXyEuF9XcDo7Fb-UjqqKas1AizSXQhH-KuDA095DAOmL9iZVRncXqbisO7tj9gXwIu_MXzoBUiRr_MbcqkP5U_Be-TmeQxkw1S0AhqTlq18koALg-qg&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=uA9-0I1pBevVG0hDsnU7BtCnyeuUb-P9wVQ8SbtrXkoO1ul12tTuffKX8fZbv5EJfMX2qAqggMZqideQb1uZq_0aTb1xRIOjpnKhUD7tDFZ41o_FigRGsI-uVVOICJrL5SzdhHYMaMFu-sW0H4DZB01aoJy9rxM4EqiOZBh6tHDvY2jDNZX6J3U1Nq5w7lOBwgYnHFa1Y9C6yTIwamDPq9YCWEyl2cGlzyGYtoywXuyjEhiSTu1OEeBLtagC8jYHk1xmuotOpJXgrAYu3YcQdxtMqPfeC6ZwIEJYv7RVi2gduIqa-eqRyXk8Dv2Uy4lbf2ZLlMCzGxW592I42jL8aDGIpRkqVcq6Pckf6AEKU08sffot-d4m1yB7s5Gg3RIT93YMwxOKRXV7LrG8zWJeEDcYcUPJhfgEoZ-0n10lFGpljE91Bxg&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://dl2.yac.mx/download/.../yet_another_cleaner_mmac.exe

http://ads.adsrvmedia.net/event/click/0/MDABWRrrmftkXkeKS3-cHVVJMftdfFsF9WHi2-Rk1bEB4y-oPkgLqVKvOmk2iae-CUtyR8N44gyoF9WGhO4UhtoRleB4LhHXEYvBTC1okpMJexC2FIx9ygmA9fJsYvF8IPuUutIrVmWzCXJcWEQYoYiMjJgUN_U2A3wMb6AQ2hmYOoHbFj5BC6RG1qdFCTD61wpR_3CQ7_XdShcJLDpSKtvI2wV5T-qhavxieOVIr1CKU4To0m980mXail9TDN-LwER2HqQMkRNIt8gNdl_6lROBAgxcc9ryJCGIYzRF-JoazxRmgZ7y9TYzVQCimtw9jea0pYZCUfJ5Ryxfolik0T9tW1sb5wDcc_OVHkZrsVVrEh761ohDMFoePQoWitS2SWO-yEAuswdvDkJtVcwzGOZHDF0WrUxdu4qGKw/.../

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=cy3jJFTfPp4qLttkxWPJ-_GZe4WjH3GODsnFCNS6VgQRVVsKYlBoefxPi0BYxGcatxzJhM0oUMOwVDEOZIctCuRZUIqdNzOzIzLHu7njJoFjpdID4hO-_-sS3g9lU4103gsnFPFKJPNoZgSQfP7kHIpj0A1FvV4YMyN6207iILg-ZLp7UiAjkKu85BBenJlKfRewS03Zod9IOl-Q_kPYqkR_4rFkE_eDRnCnzaJNb0PZdDkE8u9rZWw17FsYeiXhFW_nKBrakysKi9Z2lCHqNBRgLp4mPMnhy3LCYBMChE30yBd6qurH_j2_6-l1chA3byFSMqfEGMQsvtyKy1e6ULd4qqbCmqsw5NrQFXGxg_HjB9H-tBbvX8ucmi6OB9N6e4ITYmU8eAEryvrLfrrjdbL5n1CJjsyFseNpWfptf7mbNS10fZAsOsw&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://ads.adsrvmedia.net/event/click/0/iiqq9FeWGIPyOehI8950GyFh3yY_ahRv1YaBCAilX9-GdIQtBEzxaUG6wpI4FGQTHO7EOOqfIyxwdoaxHyTEbwa8iNCYAmGHdiT0G7STuM6LeXVENiMWUda89Rcz7B6J57VVnDy0id6EWvLbMIsHdsAAyUXSC0t4FpNbWquQA6AeT7OF_gX8oG-1ImbZXERh8YyvUDOr4exzx9hW4ZH4FbNnbkiLwnTwyCNp4Q-bmXmZ5GQnF1UNNjVr30z29Mg3zcaSg9LX3Qd2gTbyZYctVgw9frnKQWMUfgFXQmP4-05-ZaAJM3PxMxx5uvAhupXleNqBF1yxh0dorQcwr5k893u5cThEdeNRKv5w8XddiwdkD1cT58SWZYyljeKF6F6aBjMWpL5mZxSIJCja3p4WpzWyVh51ulrlRLYC2jPxK4Um6hwgLTGLiFyJaHWksQ/.../

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=PITKaFZ8t_AQrCnUI40zDJ7Y0G8V0XMWeCrQT2tE8htLA126HRbnK4a2G00-F59yXoC36jhsf3e-gQn-gNMsKOIn0Lr3KpkMI3zfCkbg2gMOpsLvhlPqUXenqtpm77etFb09IwKwXMs7b2QQaFJdsFUuq0D7leqvJ5yltNV-MW2wLXGnFU3ptaFgOebr-S_vUhI2wZ9TF8EDMHcH70Drp8mhCQ-o6is20vIwZNJlNSbABrXbCdYRcauVGYPodgJErS4Z_k3MHPkmPcZJco5-z_4n4JAV1CUbaExvUZGT2n2KsQZ2Nc_N5DCMa8hj-k-0j_t3GrrvLiHkkmIBbggX2RNfoAbDdft-8j5kd5EhaJRV9TSN4z_VEvjGG-0F7ZcwYSHB-BDfbRvre-gh04mGcSRJY4QoYpV1SAoWqbw&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://s2s.yac.mx/ads/adsavess?sid=yac&ptid=mmacn&subid=9dWu0fvSWMOoUieDFyKSMHtRw32LwcG7std8azMUlIvnl7dVHoNEt3QD7K_ADYYvkCLI1mi5TrXgesWxUwvtjTVMcVG567kBDsvArUljZzicNsLc7Rc_X5cEG6dsrBe8eTDNA-l9FMnY4yz-esatQpcMNQQaQ25tqyFX_8NDOrebNAYqC10F7mRf6CXDT-IMlFoQ19GIJpbEAWfSEcmucgCvxa_8qhNpTleGdsJkJmQqYDuilEKW5CgBqZEZWRbxbfUpYqzT3NFt7EWJM_ZQfTVgSkdlXRYVXSf9ZwFxx91LR85VrxNyU1oAWxcBFR3JXFXCEgm8WqlD_v_3hUJLcQ7joWmTw-JfxRKMZlMmDbaHjanYGTpPeznL2Cs75lBCJRuCZ36mNJaqO1hzCUrFvVvDFI8XlZat-wvDmoyJdB_kikM0_BrYXQ&lplink=http://www.yac.mx/download/.../down.php?pt=mmacn

http://ads.adsrvmedia.net/event/click/0/eqJuzz_3tzirHh-MP1mrx13LimOCfjpWyBiqdbeEmbUzosr7tqRKMSx3s7Z4RXA62auinYT-SHgIzOF79uUFh--p3s8jCC7ortejK2QtoNi2r9fBs5LISjIgsmHiwAWYQosgJY4AeVd4fLl7M-h90M-VothlZux1BbdLDH_NqaCduJHv5jfyJjaBOp76r4k667CH3QxOb8EplQxQbWN676CT43sRqL8240pzdN7QYJ02UaZLdxpIN65krzIJ3ThbjqzOdck5qkyPQ0wAtwKQheafIOCFQs6WzhqmjTXgOKxRcyZSw0APIiY4hgC3xlYLarWz5AfgB15hnvCevPAni_2CaDSBzC8pzy4M3Tw7WtZbEeumhWfmhWHlO_TIURGemW5j9-GP_MVhOr8x1ugm63C31y3PwGzy_cuIKbOnX_imJLw/.../

http://ads.adsrvmedia.net/event/click/0/KYQvigJa7XftskuOD2JLWrXIZQVAcKAuGGUPNCoiprr1UxzgWEXgVOu3YUq7iqMHUtoiwnhDDOegAvmfWhLC4o3-Pzoc35uCGpFDKfo-oEALmO_eR374y2Klpg0Gn6drBCl5USagBFWR2FTRuyZjPGpeuJf3n0Uif9nSEMnRDwQ-i24493exidLuuG55Y8AtRAy_qqwJhB_hSgKYyW66HVLr9BlSSI03xXpW9TFmYQ14JZOihZvnxlR7V_efJpYKp_ApCFXVMcPFcdiwK6XAD0s46HT3ev-FWaFLwx6FEt1S7ZxPWQBu1F1pxPcKtcGzxSOzAZNh56uy702VJ2S1sYzt4YL9jUNE2q0EZ9z0w4gEMuSDGsuaprvhQg8GhWKx8uCTyM7u0lPHGijU9RuYmQ/.../

http://ads.adsrvmedia.net/event/click/0/PFwegg11VNUecua5ZbPDv_1FgH81paGiOnOUBAjpNnpI28Ntc5NZpd7AyfsozDAtx_gCIbZzg008rQ03etij5YOjNWjF5YzQGs74fjczTNMLr6gIUNhOwQqVBFRqK3qVxa4ggFpRIDHcTielU4WTNUHaEO5rFcmDx3GgZvw-Se-viOaV_QJu_jCyC7tOwZIuSqiC3Bz5q-QSoMzLBXvaGrC0Ee82bXHBfRP5C74Rbd2TQTq6wmCFupMUeln9TNhnBRyZ8ZzRBBuOPWpvGuqqnu9G61vubgmxiRTfsK1PB9xW4X1qKGQJLZARSKlfhEiz9B0kvZMDW6M8PVanuufrxAV1f2Kw336iLmzztdpoMcvXb-0lTruzwobo3YNsze2CJEaRFtItTV9JzJNihnunBHi9NaYjNv37U_YZq31YHaxzznWbPk0n0IZbRfhS9LdE_MKUNLP8xLkQcg/.../

http://ads.adsrvmedia.net/event/click/0/ej-sxiFgb7MpgOYmeIloXQptzWQl_2AD7NQmyBii7432p0mnQcingcWcsT46-eC9SAFQFdT258hCBu8NExmPJ35vAvWEFRbrPggkrzSjDsl-ZU8330r6GPiaWQPW3AYhNQtxqwHP9i9ziFzXYqfYv_YtNvwiy-H30lnuftFwvkrDrIySbBy1B-vgEvDvUNDL-V8tOESyJ3_hTzgJ0RBY3-lIMQzaAfjYEROgA95SQHPKJ2XVNqmJy7pm7PK_-hpYMTFCmJbCkvORDDh2QzcHCtlI0aFjx4nKTVvjumNn_jKPGNyWe9bJVwIcktmcK2UsipUVjQ5SuKdo10rhr4BXOjxyyCxGF3dYf14rcOxcFX9f9xrBUWatN9oScrLqI930XIkrHSwWe5_JXr7J4wB3uRnw/.../

Latest 30 of 63 download URLs

Remove yet_another_cleaner_mat.exe - Powered by Reason Core Security