Claro_1.exe

Claro

The application Claro_1.exe has been detected as a potentially unwanted program by 5 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from cdn.guttastatdk.us.
Publisher:
Claro

Product:
Claro

Description:
claro-search

Version:
3.0

MD5:
00c4c00a0792020838f6f07166939cb9

SHA-1:
1d961b163e1bd9e6dec3376b3c723a88e4d7a65e

SHA-256:
817a89683683bab32bb76b53772feb5788f1ca482e8cf8b51069d34bc1080caa

Scanner detections:
5 / 68

Status:
Potentially unwanted

Explanation:
The installer may include an offer for the Babylon Toolbar (a homepage/search hijacker), which is potentially installed with minimal user consent.

Analysis date:
1/12/2025 4:58:38 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.Babylon
2013.12.05

AVG
Toolbar.Babylon
2014.0.3542

Baidu Antivirus
Trojan.Win32.Agent
4.0.3.131211

Dr.Web
Trojan.DownLoader7.58867
9.0.1.0240

ESET NOD32
Win32/DownWare
7.9130

File size:
916.8 KB (938,795 bytes)

Copyright:
© claro-search

Trademarks:
claro-search

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\claro_1.exe

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:HB20zuaMhhVE9AiE8fD/gTvQEGFRe1AdXTN/6bgiz:k0HMzVEnEG4EJ61Az6/z

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9584

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file Claro_1.exe has been seen being distributed by the following URL.

Remove Claro_1.exe - Powered by Reason Core Security