PUP.Ypack.G

Analysis Report

General information

Family Name: PUP.Ypack.G
Signature status: Root Not Trusted

Known Samples

MD5: a60fdf3e7f210df8bcf88ada72ea4d37
SHA1: 6ee3a987da24315e7c55c9ff553dfcccd4b30dde
SHA256: 7A0E69DFAFF537A07A35DC175BFB97E7C1CE6821FBF9F60425F17128E7DCE5EA
File Size: 1.67 MB, 1669272 bytes
MD5: e5bd37f0959c7dafcef38b3c6008426c
SHA1: 25967bf79c0d97b71e3574507585366cbe45e6d1
SHA256: 0DACE7DB029DAD76F265330BB7FB761495380A05A5251C48FF67B92967AE5824
File Size: 1.53 MB, 1527600 bytes
MD5: 6a52a1209ea9d89fd06ebb5d8e32a4f3
SHA1: 301ed962cdc0312fd27d862762de31adf415671b
SHA256: 3C2E345182EEDBA58A95DCA6C98F86FC87A760A9BD6C9E5F85659618966420A7
File Size: 1.53 MB, 1532080 bytes
MD5: 3f02d4ebe6f56417745fe92ab4573c3e
SHA1: f3ef218c6f167e35d7e10f5ab522935cc3dd65ec
SHA256: 7B31E908A3CE2FAC394BC1F42B92304A6622A06600A015014E20C69D780345BE
File Size: 1.53 MB, 1528496 bytes
MD5: a0f5c561bf1352a746f344b0afc0c928
SHA1: e3149d5a68fb50e6ee6ebf3e7d30286284243927
SHA256: 76776C2B3F883EA7DB831173D39278E3EF50882BBC2D54F75B3C724CC632B1FB
File Size: 4.02 MB, 4021912 bytes
Show More
MD5: d49437077108b9913656b1245a9ea0c1
SHA1: e5138c14ac71593b73c883cb26c8ec3eddcd6266
SHA256: 00F39BF6E50A1ECC3453BCE0C5A2ABA3C4FB6CD0E8F55BAAC6B07BA255E2D020
File Size: 4.06 MB, 4056240 bytes
MD5: e10a54618e55f01a41d7a92082cd23e9
SHA1: 56b0306b67f5265536dfdc7db0a582c24aa7fe47
SHA256: 64608681CEA537A4189B89FE6F0B9E5068D6D3F70C0DB3102829E0DE171E8253
File Size: 1.61 MB, 1609904 bytes
MD5: a798d32210517deba0f1fb20133e09bd
SHA1: 716844ed935658ad0d2d7bde2e6e8876b5d18525
SHA256: 1B7ADB7780330A885EFD753D24BA370B51CF0DB9E147850B6D4426C72EC45E58
File Size: 3.34 MB, 3340464 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name YANDEX LLC
Company Short Name YANDEX LLC
File Description
  • @PRODUCT_FILE_DESCRIPTION@
  • Yandex
File Version
  • 25.2.4.954
  • 24.12.3.780
  • 24.10.4.850
  • 24.7.2.1100
  • 24.6.1.768
  • 23.11.0.2472
  • 23.5.3.918
Internal Name
  • @INTERNAL_NAME@
  • notification_helper_exe
  • setup
Last Change
  • 9b32803ea2d305cd87dd8af7b47fa56e870c767e
  • 500ec94cb1e04153e64f10d9eebb4e28fe70fd79
  • 701f3abe30bd0dd4f8e0c921c03d41893ea3f6dd
  • 663571e13fadae5ce98627cd88eef0240de7052d
  • 06675302fd9ccd703b40fe9fd3a7732e9a898559
  • a041fd2d75d29596caf491d9372182e5e185d7c6
  • ff102d7073a0b4af5e2b046265a6da8ef562a423
Legal Copyright
  • Copyright (c) 2012-2023 YANDEX LLC. All Rights Reserved.
  • Copyright (c) 2012-2024 YANDEX LLC. All Rights Reserved.
  • Copyright (c) 2012-2025 YANDEX LLC. All Rights Reserved.
Official Build 1
Original Filename notification_helper.exe
Product Chromium Version
  • 130.0.6723.170
  • 128.0.6613.186
  • 126.0.6478.234
  • 124.0.6367.243
  • 118.0.5993.144
  • 112.0.5615.204
Product Name Yandex
Product Short Name Yandex
Product Version
  • 25.2.4.954
  • 24.12.3.780
  • 24.10.4.850
  • 24.7.2.1100
  • 24.6.1.768
  • 23.11.0.2472
  • 23.5.3.918
Product Yandex Version
  • 25.2.4.954
  • 24.12.3.780
  • 24.10.4.850
  • 24.7.2.1100
  • 24.6.1.768
  • 23.11.0.2472
  • 23.5.3.918

Digital Signatures

Signer Root Status
YANDEX LLC GlobalSign Code Signing Root R45 Root Not Trusted
YANDEX LLC GlobalSign GCC R45 EV CodeSigning CA 2020 Self Signed

File Traits

  • 2+ executable sections
  • HighEntropy
  • Installer Version
  • ntdll
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 9,830
Potentially Malicious Blocks: 103
Whitelisted Blocks: 7,365
Unknown Blocks: 2,362

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? ? 0 0 0 0 0 ? ? ? 0 0 0 0 ? 0 ? 0 0 ? 0 0 ? 0 0 ? 0 ? 0 ? ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 ? 0 x 0 ? 0 0 0 0 ? ? ? 0 ? 0 0 0 0 ? 0 0 0 0 ? 0 ? 0 ? ? 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 1 0 0 0 0 ? 0 0 0 0 0 ? ? 0 0 0 ? 0 0 ? 0 ? 0 0 0 ? ? 0 ? ? ? ? ? 0 ? ? x ? 0 ? ? ? ? ? 0 0 x ? ? ? ? ? ? ? ? ? x 0 ? ? ? ? x ? 0 ? 0 ? ? ? 1 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 ? 0 0 1 0 ? ? 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 ? ? 1 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? ? ? 0 0 0 ? ? 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 ? ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 ? 0 0 0 0 0 0 ? 1 ? ? 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 ? ? 0 0 ? ? 0 0 0 0 0 0 0 x x 0 ? 0 0 0 0 ? 0 0 ? 1 0 0 0 ? ? 0 0 ? 0 ? 0 ? 0 0 0 0 0 ? ? 0 0 ? ? 0 0 ? ? 0 0 ? 0 ? ? 0 0 0 0 ? 0 ? 0 ? 0 ? 0 ? ? 0 ? 0 x ? ? 0 0 0 0 0 0 0 ? ? ? ? 0 ? 0 0 0 ? 0 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 x 0 ? 0 0 0 0 ? 0 ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? 0 0 ? 0 ? 0 ? ? ? 0 0 0 ? ? 0 ? ? 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? 1 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? 0 ? ? 0 ? ? ? ? 0 0 0 0 0 0 0 ? ? ? x ? 0 0 0 0 ? 0 ? ? 0 0 x 0 x 0 ? 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? 0 ? 0 ? 0 0 0 0 ? ? 0 0 0 ? 0 ? 0 ? 0 ? 0 0 0 0 ? ? ? ? x ? 0 0 0 0 0 0 0 ? ? 0 0 ? ? ? ? 0 0 0 0 ? ? ? 0 ? x 0 0 0 0 0 0 0 0 0 0 x x 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 ? 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 x 0 0 ? ? x 0 0 0 0 0 ? 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 ? ? ? 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? 0 0 0 ? ? 0 0 0 0 ? ? 0 ? ? ? ? ? 0 0 0 ? ? 0 0 ? ? 0 ? ? ? ? 0 ? ? 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? 1 0 0 0 0 1 0 0 0 x 0 0 ? 0 ? ? 0 ? 0 0 ? 0 ? 0 0 0 0 0 ? 0 0 x x ? 0 ? ? 0 0 0 0 ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 1 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? ? 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 ? 0 0 ? ? ? ? ? ? 0 ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 ? 0 ? 0 ? ? ? ? 0 0 0 ? 0 x ? 0 0 ? 0 0 0 ? 0 0 ? ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 ? ? 0 0 0 0 0 ? ? ? 0 0 0 0 0 ? ? 0 ? 0 0 ? ? ? 0 ? 0 ? 0 ? ? 0 0 ? 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 ? 0 0 0 0 ? ? 0 0 0 0 ? 0 0 0 ? ? ? ? 0 0 0 ? ? ? 0 0 ? 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 ? 0 ? 0 ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 ? ? ? 0 ? 0 0 ? ? ? 0 ? 0 ? ? ? 0 0 ? ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 ? ? ? 0 x 0 x ? ? 0 0 0 ? 0 0 0 0 0 ? ? 0 0 ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? ? 0 ? 0 0 ? ? ? ? ? ? ? 0 0 ? ? 0 0 ? 0 0 ? ? ? 0 0 0 0 0 ? ? 0 0 ? 0 0 ? 0 ? 0 ? ? 0 ? ? 0 ? 0 ? 0 0 ? ? 0 ? ? 0 0 ? ? 0 0 0 0 0 ? ? ? ? 0 x ? 0 0 0 0 x 0 0 0 ? 0 0 ? 0 0 ? 0 ? 0 0 ?
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\program files (x86) Read Attributes,Synchronize,Write Data
c:\programdata\yandex\yandexbrowser\service_update.log Read Attributes,Synchronize,Append data
c:\users\user\appdata\local\temp\yandex_browser_installer.log Read Attributes,Synchronize,Append data
c:\windows\systemtemp Read Attributes,Synchronize,Write Data

Registry Modifications

Key::Value Data API Name
HKCU\software\yandex\yandexbrowser::ap RegNtPreCreateKey

Trending

Most Viewed

Loading...