claraupdater.exe

ClaraUpdater

ClaraLabSoftware

The application claraupdater.exe by ClaraLabSoftware has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. This is the uninstaller utility registered in the Windows Control Panel for the program BoBrowser by BoBrowser. The file has been seen being downloaded from vzbucket.clara-labs.com.
Publisher:
ClaraLabs  (signed by ClaraLabSoftware)

Product:
ClaraUpdater

Version:
4.6.5.1

MD5:
5b12cdfe264f55035c39487047f0fc33

SHA-1:
8e961183192d06f5ae92fbbe54bae7f545bc2f1c

SHA-256:
0d4f57e1345f8eb450b7261672eec07f05ac7510846720520913e4b01a14a512

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/18/2024 1:31:47 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ClaraLabSoftware (M)
16.2.5.19

File size:
918.7 KB (940,760 bytes)

Product version:
4.6.5.1

Copyright:
Copyright (C) 2014

Original file name:
Updater.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\common files\claraupdater\claraupdater.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
12/31/2015 1:00:00 AM

Valid to:
12/21/2016 12:59:59 AM

Subject:
CN=ClaraLabSoftware, OU=ClaraLabSoftware, O=ClaraLabSoftware, POBox=ClaraLabSoftware, STREET=32 BOULEVARD DE STRASBOURG, L=PARIS, S=FRANCE, PostalCode=75010, C=FR

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
008857DCCA6BEB83363B5B8D19600709FF

File PE Metadata
Compilation timestamp:
2/5/2016 2:36:34 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
24576:zjB7hYH8cXWQV5aVFNkfJMErYb8FOcmHIyrlCPskpCi58:zjl6bsCprnZyrlapCi58

Entry address:
0x857F5

Entry point:
E8, 08, 12, 01, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 83, EC, 18, 8D, 4D, E8, 53, 57, FF, 75, 0C, E8, 59, C3, FF, FF, 8B, 5D, 08, BF, 00, 01, 00, 00, 3B, DF, 73, 60, 8B, 4D, E8, 83, 79, 74, 01, 7E, 14, 8D, 45, E8, 50, 6A, 01, 53, E8, F8, 12, 01, 00, 8B, 4D, E8, 83, C4, 0C, EB, 0D, 8B, 81, 90, 00, 00, 00, 0F, B7, 04, 58, 83, E0, 01, 85, C0, 74, 1E, 80, 7D, F4, 00, 8B, 81, 94, 00, 00, 00, 0F, B6, 0C, 18, 74, 07, 8B, 45, F0, 83, 60, 70, FD, 8B, C1, E9, D2, 00, 00, 00, 80, 7D, F4, 00, 74, 07, 8B, 4D, F0, 83, 61...
 
[+]

Code size:
680.5 KB (696,832 bytes)

Program Uninstaller
Program name:
BoBrowser

Display publisher:
BoBrowser

Display version:
45.0.2454.131

Uninstall string:
C:\Program Files (x86)\Common Files\ClaraUpdater\ClaraUpdater.exe /UNINSTALL=dde5a5b2-e3f2-4725-94b9-0e16aa7fec5d


The file claraupdater.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to ec2-23-23-112-220.compute-1.amazonaws.com  (23.23.112.220:80)

Remove claraupdater.exe - Powered by Reason Core Security