PUP.Ypack.G

Analysis Report

General information

Family Name: PUP.Ypack.G
Signature status: Root Not Trusted

Known Samples

MD5: a60fdf3e7f210df8bcf88ada72ea4d37
SHA1: 6ee3a987da24315e7c55c9ff553dfcccd4b30dde
SHA256: 7A0E69DFAFF537A07A35DC175BFB97E7C1CE6821FBF9F60425F17128E7DCE5EA
File Size: 1.67 MB, 1669272 bytes
MD5: e5bd37f0959c7dafcef38b3c6008426c
SHA1: 25967bf79c0d97b71e3574507585366cbe45e6d1
SHA256: 0DACE7DB029DAD76F265330BB7FB761495380A05A5251C48FF67B92967AE5824
File Size: 1.53 MB, 1527600 bytes
MD5: 6a52a1209ea9d89fd06ebb5d8e32a4f3
SHA1: 301ed962cdc0312fd27d862762de31adf415671b
SHA256: 3C2E345182EEDBA58A95DCA6C98F86FC87A760A9BD6C9E5F85659618966420A7
File Size: 1.53 MB, 1532080 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name YANDEX LLC
Company Short Name YANDEX LLC
File Description @PRODUCT_FILE_DESCRIPTION@
File Version
  • 24.10.4.850
  • 24.6.1.768
  • 23.11.0.2472
Internal Name notification_helper_exe
Last Change
  • 701f3abe30bd0dd4f8e0c921c03d41893ea3f6dd
  • 06675302fd9ccd703b40fe9fd3a7732e9a898559
  • a041fd2d75d29596caf491d9372182e5e185d7c6
Legal Copyright
  • Copyright (c) 2012-2023 YANDEX LLC. All Rights Reserved.
  • Copyright (c) 2012-2024 YANDEX LLC. All Rights Reserved.
Official Build 1
Original Filename notification_helper.exe
Product Chromium Version
  • 128.0.6613.186
  • 124.0.6367.243
  • 118.0.5993.144
Product Name Yandex
Product Short Name Yandex
Product Version
  • 24.10.4.850
  • 24.6.1.768
  • 23.11.0.2472
Product Yandex Version
  • 24.10.4.850
  • 24.6.1.768
  • 23.11.0.2472

Digital Signatures

Signer Root Status
YANDEX LLC GlobalSign Code Signing Root R45 Root Not Trusted
YANDEX LLC GlobalSign GCC R45 EV CodeSigning CA 2020 Self Signed

File Traits

  • 2+ executable sections
  • ntdll
  • x86

Block Information

Total Blocks: 4,329
Potentially Malicious Blocks: 19
Whitelisted Blocks: 3,738
Unknown Blocks: 572

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 ? 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 0 0 ? ? ? 0 0 0 0 ? 0 ? 1 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 ? ? ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 2 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? ? 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? 0 0 ? 0 0 ? ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 ? 0 0 ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 2 ? ? 0 0 0 0 0 0 0 ? ? 0 0 ? ? ? 0 0 0 0 0 ? 0 ? 0 0 0 1 0 0 0 0 0 ? 0 ? ? 0 0 0 ? ? 0 ? 0 0 ? 0 0 0 0 ? ? ? ? 0 0 0 0 ? 0 ? ? ? ? ? 0 0 0 ? 0 0 ? 0 ? 0 ? ? 0 ? ? ? ? 0 0 0 0 ? 0 0 ? 0 0 0 ? ? ? 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 ? 0 ? ? ? ? 0 ? 0 0 0 x 0 ? 0 0 0 0 ? 0 0 ? 0 0 0 ? 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 ? 0 0 x 0 x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 ? 0 0 ? 0 ? 0 ? 0 0 ? 0 0 ? 0 0 0 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 ? 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 ? 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 x x 0 ? ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 2 0 0 ? 0 ? 0 0 0 ? 0 ? 0 ? ? 0 ? 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 ? 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? 0 0 ? ? ? ? ? ? 0 ? ? 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 ? ? ? ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 ? ? ? 0 0 ? 0 0 ? 0 0 0 0 0 0 0 2 0 1 ? 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 ? ? ? ? 0 0 ? ? 0 ? 0 ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 0 ? 0 0 0 ? 0 ? 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 0 0 0 ? ? ? 0 ? ? 0 0 0 ? ? ? 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 ? 0 0 ? 0 0 0 0 ? 0 0 0 0 0 ? ? ? ? 0 0 ? 0 ? 0 0 0 0 ? 0 0 ? ? ? 0 0 ? 0 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 ? 0 ? 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 ? ? 0 ? 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? 0 ? ? x x ? 0 0 ? ? ? ? ? 0 0 0 ? ? ? ? 0 0 ? ? 0 ? ? 0 0 0 0 ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 0 0 0 ? 0 ? 0 ? 0 ? 0 ? ? 0 0 0 0 0 ? ? 0 ? ? 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? x ? 0 0 0 0 0 0 ? 0 0 0 ? 0 x 0 0 ? ? ? ? ? ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 1 0 0 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 ? 0 0 ? ? 0 0 0 ? 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 0 0 ? 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Trending

Most Viewed

Loading...