yji01.exe

The application yji01.exe has been detected as a potentially unwanted program by 16 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from doc-04-3g-docsviewer.googleusercontent.com and multiple other hosts.
MD5:
c586b6f4e5cd660a38cc296e567a8c2b

SHA-1:
8d32d78da0725e1e0075d80d32aaa27128fa3adb

SHA-256:
883b6659fff9ae287fe8fde92c3894e83a21dc113058be19ab2945183dfeafe4

Scanner detections:
16 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 1:14:27 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
SPR/Tool.Keygen.6983
7.11.166.24

avast!
Win32:Malware-gen
2014.9-140813

AVG
Crack
2015.0.3383

Bkav FE
W32.Clod44c.Trojan
1.3.0.4959

Fortinet FortiGate
W32/KeyGen.A!tr
8/13/2014

IKARUS anti.virus
not-a-virus.Keygen.Corel
t3scan.1.6.1.0

McAfee
RDN/Generic PUP.z!dh
5600.7039

Microsoft Security Essentials
1.10802

NANO AntiVirus
Trojan.Win32.Rogue.cylkwg
0.28.2.61349

Norman
Suspicious_Gen4.CWNQW
11.20140813

Quick Heal
Trojan.ZAgent.r3
8.14.14.00

Rising Antivirus
PE:Trojan.Win32.Generic.15A59506!363173126
23.00.65.14811

Sophos
Mal/KeyGen-A
4.98

Trend Micro House Call
TROJ_SPNR.08LC13
7.2.225

Trend Micro
TROJ_SPNR.08LC13
10.465.13

VIPRE Antivirus
HackTool.Win32.Keygen
32042

File size:
375.5 KB (384,512 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\yji01.exe

File PE Metadata
Compilation timestamp:
3/7/2013 2:41:14 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:SvWvSrIIIjTFn7b/F5RnD3vc2+dmpda6DQXCaujulTBt0M1SPCmCITy:SuqrNkTFn7J5BDvldYCauSpBtTSPbJT

Entry address:
0xBE2B0

Entry point:
60, BE, 00, 10, 47, 00, 8D, BE, 00, 00, F9, FF, C7, 87, 8C, C7, 07, 00, B0, 21, 2F, BA, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.6047

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
312 KB (319,488 bytes)

The file yji01.exe has been seen being distributed by the following 4 URLs.

https://doc-04-3g-docsviewer.googleusercontent.com/viewer/securedownload/8vv644r3q137msospovg7f7ero6m1r8d/1r9k62goeogrp9dedkk2pi00frkblvm1/1385693100000/ZXhwbG9yZXI=/.../MEIzeWdVNnlqSG5mRGNFa3pWMGhJU1Y4NFdVaw==?a=dl&filename=????X6???.rar&sec=AHSqidYvLr4IZrZSiqFm-5JCwOJEKFXL6mbz4m0Y5PWbcgu8y2jRe2fHxrhNjE-HiKSAlLD88uy4&rel=rar;r1;?|?n?|?vX6???U??.exe

https://drive.google.com/uc?id=0B0p-mFoOiP3WSWltaFR4R2NLSlU&export=download

Remove yji01.exe - Powered by Reason Core Security