iiwuvhe3zbsyun_bb.exe

Clara

CLARALABSOFTWARE

The application iiwuvhe3zbsyun_bb.exe by CLARALABSOFTWARE has been detected as a potentially unwanted program by 3 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.2ndrequest.me and multiple other hosts.
Publisher:
ClaraLabs  (signed by CLARALABSOFTWARE)

Product:
Clara

Description:
ClaraSetup

Version:
1.45.1.1

MD5:
841485156e7ed942f7fb9498b438108c

SHA-1:
f87bade036f5273ac4f869946aeb47335eac11b1

SHA-256:
53c4c191a7f75b8edfd8d2d40d18df7c8db91859249ef0e67b7cdc9cb15c3844

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 12:49:37 PM UTC  (today)

Scan engine
Detection
Engine version

Malwarebytes
PUP.Optional.Clara.A
v2014.11.17.04

Reason Heuristics
PUP.Installer.CLARALABSOFTWARE.R
14.11.21.23

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

File size:
820.6 KB (840,312 bytes)

Product version:
1.45.1.1

Copyright:
(c) Clara Labs. All rights reserved.

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\iiwuvhe3zbsyun_bb.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
7/29/2014 5:13:08 AM

Valid to:
7/30/2015 5:13:08 AM

Subject:
CN=CLARALABSOFTWARE, O=CLARALABSOFTWARE, L=Paris, C=FR

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121E6E5C72C946A5248674AB7B56E24B246

File PE Metadata
Compilation timestamp:
11/3/2014 4:55:14 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:I8k7rwlAxilkyufeKeNoUsy5su63Bslt/JYX:I8knjxilZ5oUsy5s9slt/JYX

Entry address:
0x19DC1

Entry point:
E8, 93, DB, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 7F, 0F, B6, 44, 24, 08, 0F, BA, 25, 84, 72, 44, 00, 01, 73, 0D, 8B, 4C, 24, 0C, 57, 8B, 7C, 24, 08, F3, AA, EB, 5D, 8B, 54, 24, 0C, 81, FA, 80, 00, 00, 00, 7C, 0E, 0F, BA, 25, 04, 56, 44, 00, 01, 0F, 82, 70, DC, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83, E2, 03, C1...
 
[+]

Code size:
207.5 KB (212,480 bytes)

The file iiwuvhe3zbsyun_bb.exe has been seen being distributed by the following 2 URLs.

Remove iiwuvhe3zbsyun_bb.exe - Powered by Reason Core Security