gcl-install-silent-v5.3-ref19.exe

Get a Clip

The application gcl-install-silent-v5.3-ref19.exe by Get a Clip has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Get a Clip  (signed and verified)

MD5:
22040b0aa2e6288e42bf9833c3232743

SHA-1:
37ff950c9e5adbdc9e192aaaf13f87f091ff1dac

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/6/2024 4:29:03 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.GetaClip (L)
16.11.12.11

File size:
18.1 MB (18,998,748 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\gcl-install-silent-v5.3-ref19.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/6/2016 5:09:05 PM

Valid to:
3/23/2017 7:37:13 AM

Subject:
E=info@get-a-clip.com, CN=Get a Clip, O=Get a Clip, L=Garden Grove, S=California, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11214F73BF2EACA0C2BCE07BD34BC3F2079D

File PE Metadata
Compilation timestamp:
10/6/2014 9:40:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:3HKEOTNzzIICbhu2biwCHSwInbITBSnDhFBErW:3HKnVb2hvbiwCHeEFgDGrW

Entry address:
0x2E000

Entry point:
68, B8, 79, 48, 01, 59, 90, 90, 68, 22, E0, 42, 00, 5E, 90, BA, 98, 05, 00, 00, 90, 90, FF, 34, 32, 31, 0C, 24, 8F, 04, 32, 83, EA, 03, 4A, 75, F1, 90, 50, 04, 49, 01, B8, 79, 48, 01, B8, 79, 08, 01, AF, 4B, 48, 01, F8, 57, 57, 00, 64, 4C, 57, 00, B8, C9, 4A, 01, B9, 79, 48, 01, D8, 09, 08, 01, 8E, 00, 08, 01, 1E, 01, 08, 01, 00, 1D, 48, 01, 8C, 00, 48, 01, 1C, 01, 48, 01, D8, 19, 48, 01, 8C, 00, 48, 01, 1C, 01, 48, 01, B8, 79, 48, 01, B8, 79, 48, 01, B8, 79, 48, 01, B8, 79, 48, 01, 30, 09, 08, 01, B8, 79...
 
[+]

Entropy:
7.9999  (probably packed)

Code size:
23 KB (23,552 bytes)

Remove gcl-install-silent-v5.3-ref19.exe - Powered by Reason Core Security