OlacaritaUpdate.exe

Olacarita Update

Olacatala OU

The application OlacaritaUpdate.exe by Olacatala OU has been detected as adware by 4 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler named OlacaritaUpdateTaskMachineCore triggered to execute each time a user logs in. While running, it connects to the Internet address 10-3798 on port 443.
Publisher:
The Olacarita Group  (signed by Olacatala OU)

Product:
Olacarita Update

Version:
1.3.25.0

MD5:
ce5349c111baec576ce0cba318fece20

SHA-1:
6615cccaab47e39c919927fc412b977d759f6e4e

SHA-256:
8cdecc9406bd806a35a731f6f026341c30de29608ecc1faca23ebbd1a17c8804

Scanner detections:
4 / 68

Status:
Adware

Analysis date:
1/12/2025 10:14:30 AM UTC  (today)

Scan engine
Detection
Engine version

G Data
Win32.Trojan-Dropper.BoxoreInject
15.3.24

Malwarebytes
PUP.Optional.Boxore.A
v2015.03.24.02

Reason Heuristics
PUP.Task.OlacatalaOU.P
14.12.16.10

VIPRE Antivirus
Boxore
34283

File size:
116.4 KB (119,200 bytes)

Product version:
1.3.25.0

Copyright:
Copyright 2007-2010 Google Inc.

Original file name:
OlacaritaUpdate.exe

File type:
Executable application (Win32 EXE)

Language:
Spanish

Common path:
C:\Program Files\olacarita\update\olacaritaupdate.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
5/30/2014 2:00:00 AM

Valid to:
6/7/2017 2:00:00 PM

Subject:
CN=Olacatala OU, O=Olacatala OU, L=Tallinn, S=Tallinn, C=EE

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0205682CD1297B1EC23B7DC2FE37FA0C

File PE Metadata
Compilation timestamp:
7/9/2014 3:52:55 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:eV3Bpju4ev0TI+Mk0Z2uTBHB0e94eVfpZm5z9jG+HiDxWjKMksEA/XmRhC9w6JOA:URdf9I+T

Entry address:
0x3F00

Entry point:
E8, B9, 1C, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, 3C, A6, 40, 00, FF, 15, 6C, B0, 40, 00, 85, C0, 75, 18, 56, E8, 8B, 03, 00, 00, 8B, F0, FF, 15, 34, B0, 40, 00, 50, E8, 3B, 03, 00, 00, 59, 89, 06, 5E, 5D, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 68, B0, 3F, 40, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 80, 91, 40, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45...
 
[+]

Code size:
29 KB (29,696 bytes)

Scheduled Task
Task name:
OlacaritaUpdateTaskMachineCore

Trigger:
Logon (Runs on logon)

Action:
olacaritaupdate.exe \c

Description:
Keeps your Olacarita software up to date. If this task is disabled or stopped, your Olacarita software will not be kept up to date, meaning security v


The executing file has been seen to make the following network communication in live environments.

TCP (HTTP SSL):
Connects to 10-3798  (194.150.236.159:443)

Remove OlacaritaUpdate.exe - Powered by Reason Core Security