ysp_inst.exe

This is a setup program which is used to install the application. The file has been seen being downloaded from c-yspsetup128exe.a-ymessenger.http.atlas.cdn.yimg.com.
MD5:
1e942f0e3b0927148b0bc84529bc1f4a

SHA-1:
9745aeddaaa39944eeecb88257fa667b77416c45

SHA-256:
5f82635901e745face77606ee530d3520487b8f6c500ae8c940a460a7bdc0815

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 5:29:26 PM UTC  (today)

File size:
476.6 KB (488,054 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ysp_inst.exe

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
12288:JNJdv1c7cCim+S5FCfoeaTd49KEP0OtD0lgOzwg:v1c7cNm+Q0foeaReF0B

Entry point:
01, 5D, 00, 00, 20, 00, E0, 9D, 07, 00, 00, 00, 00, 00, 00, 26, 96, 8E, 70, 00, 17, F7, EC, 05, BB, EA, F4, FF, 94, 01, 2F, 44, EF, 7C, E6, F5, D8, E8, 08, 04, CB, D1, E8, 7B, D6, D9, 98, F0, 63, 6C, DD, 0B, 4B, 4E, B9, FC, A4, 17, 0C, F0, 54, 53, 3B, B0, AE, 1C, 70, 86, 0F, 1B, AE, A2, 22, 07, 9B, B7, 67, 57, 9A, 97, 04, 02, E8, 9B, A9, 7E, 08, FC, A7, 7E, 8A, 9A, 93, D3, 6F, 46, 7E, 3B, 8F, 5C, 91, 5E, D3, 94, 84, E1, 15, B9, B7, 39, 59, 27, FF, 64, AD, E4, 92, C5, 68, 09, 8F, 45, 8B, B4, 61, EF, 6F, 50...
 
[+]

Entropy:
7.9996  (probably packed)

The file ysp_inst.exe has been seen being distributed by the following URL.

Scan ysp_inst.exe - Powered by Reason Core Security