The YandexPackLoader exe (Setup Downloader) File Malware Analysis
Gridinsoft Logo
File Icon

The YandexPackLoader.exe (Setup Downloader) File Analysis

Technical Analysis

File Name YandexPackLoader.exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows
SSDEEP Hash
12288:vLgtTrX65XVeLnt1iIMfxcxlR7UYIpsS8BNzVAbX3kW8jqZNpL7kB:vLwrX0gsFJcx37B7qZT
Scanner Version 1.0.182.174
Database Version 2024-07-16 16:00:25 UTC

Suspicious File Detected

Detected by 11 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
17%
Detection Rate
745,792
File Size (bytes)
11/64
Engines Detected
2024-07-16
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
f93373c2f73dbb074a66584d184de84a
SHA1
b08b3daebf0a111e4645354580b09904176144ae
SHA256
5bbc5598b2d79f2c69e0fdd4ba72a3cb07e786d3a57951e3343eb34bf419204f
SHA512
bbf794aa20d0c16cce7e31459f08d30afc321f0762ccde93722f9ffa19199dcc1ab417bc4331c81d528bebb8ed1ea522070e299806ab53e87db0170959fdd32b
ImpHash
2b8eba2cd1a25d418431dffd9683aa80

Security Engines with Detections (11 of 64)

Bkav
W32.AIDetectMalware Malicious
K7AntiVirus
Adware ( 0057021e1 ) Malicious
K7GW
Adware ( 0057021e1 ) Malicious
Ikarus
PUA.Yandex Malicious
Webroot
W32.Adware.Gen Malicious
Antiy-AVL
GrayWare/Win32.Yandex Malicious
Gridinsoft
PUP.Win32.BundleInstaller.oa!s1 Malicious
Malwarebytes
PUP.Optional.BundleInstaller Malicious
Fortinet
Riskware/Yandex Malicious
DeepInstinct
MALICIOUS Malicious
CrowdStrike
win/grayware_confidence_70% (D) Malicious
53 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 392ef86c821c190403abcba071d4d503
Fuzzy: 7084d568ef659e35f736e2ccc91a8711
dHash: 4d6d6545e1e14565
Image Base 0x00400000
Entry Point 0x0041b377
Compilation Time 2024-06-04 13:13:46
Checksum 0x000b751e (Actual: 0x000c32fb)
OS Version 5.1
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
PDB Path C:\BuildAgent\work\4a73c29f3c4e6ac\downloader\Release\downloader.pdb
Digital Signature OK
Imports 13 libraries
Exports 0 functions
Resources 35 Resources
Sections 7 Sections

Version Information

FileDescription Setup Downloader
FileVersion 0.1.0.6
InternalName download
LegalCopyright Copyright (C) 2021 Yandex LLC
OriginalFilename downloader.exe
ProductName Setup Downloader
ProductVersion 0.1.0.6
Translation 0x0419 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 254,124 bytes 254,464 bytes 6.64 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ AD714ABD6D9A7C55727FF0780B5E0A1A
.rdata 0x00040000 87,396 bytes 87,552 bytes 5.27 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ B98CBBC1625156746282C3F955C5404A
.data 0x00056000 12,408 bytes 6,144 bytes 3.89 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BD49BB51E09B144FC458E63C212F4BF9
.gfids 0x0005a000 652 bytes 1,024 bytes 2.73 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 053202AE059A410899F78FA63C4B66B8
.tls 0x0005b000 9 bytes 512 bytes 0.02 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 1F354D76203061BFDD5A53DAE48D5435
.rsrc 0x0005c000 366,648 bytes 367,104 bytes 5.87 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ DEBCA5FC79B4169CFA01A6E25E03FB34
.reloc 0x000b6000 14,556 bytes 14,848 bytes 6.57 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 4E08B4063FBD6AACDD6A31B7F01DC0C7
Entropy Analysis Alert

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 35 (364,617 bytes)
Resource Type Count Total Size Percentage
RT_ICON 5 24,082 bytes
6.6%
RT_DIALOG 1 266 bytes
0.1%
RT_FONTDIR 1 332 bytes
0.1%
RT_FONT 2 325,684 bytes
89.3%
RT_RCDATA 23 12,261 bytes
3.4%
RT_GROUP_ICON 1 76 bytes
0%
RT_VERSION 1 684 bytes
0.2%
RT_MANIFEST 1 1,232 bytes
0.3%

Certificate Chain Analysis

Certificate Information
Product Setup Downloader
Description Setup Downloader
File Version 0.1.0.6
Original Name downloader.exe
Internal Name download
Copyright Copyright (C) 2021 Yandex LLC
Certificate Chain Summary
YANDEX LLC #1 Primary
Validity Period: 2024-03-20 14:23:35 → 2026-03-21 14:23:35
Signature Algorithm: sha256RSA
Serial Number: 6F 12 6C 9C C2 87 DE 45 8C E8 90 F6
GlobalSign GCC R45 EV CodeSigning CA 2020 #2 Chain
Validity Period: 2020-07-28 00:00:00 → 2030-07-28 00:00:00
Signature Algorithm: sha256RSA
Serial Number: 77 BD 0E 05 B7 59 0B B6 1D 47 61 53 1E 3F 75 ED
GlobalSign Code Signing Root R45 #3 Chain
Validity Period: 2020-03-18 00:00:00 → 2045-03-18 00:00:00
Signature Algorithm: sha384RSA
Serial Number: 76 53 FE AC 75 46 48 93 F5 E5 D7 4A 48 3A 4E F8
Sectigo RSA Time Stamping Signer #4 #4 Chain
Validity Period: 2023-05-03 00:00:00 → 2034-08-02 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 39 4C 25 E1 7C A0 6D 27 A8 65 E2 3B D9 1D 22 D4
Sectigo RSA Time Stamping CA #5 Chain
Validity Period: 2019-05-02 00:00:00 → 2038-01-18 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 30 0F 6F AC DD 66 98 74 7C A9 46 36 A7 78 2D B9

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
11 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware