TouchCopy16.exe

TouchCopy 16

Wide Angle Software Ltd

The application TouchCopy16.exe, “This installer database contains the logic and data required to install TouchCopy 16.” by Wide Angle Software has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from www.wideanglesoftware.com.
Publisher:
Wide Angle Software  (signed by Wide Angle Software Ltd)

Product:
TouchCopy 16

Description:
This installer database contains the logic and data required to install TouchCopy 16.

Version:
16.12

MD5:
3e4072fcc80c15654e7c4e1c80779dea

SHA-1:
c1d5b1a8d7c43d6c878c1cdc031e80abd7b288dc

SHA-256:
b6774120c19e51bf8d80c03b1928c5a291b467db9274c4c78d40bfc0f575ec4d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 8:18:00 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Microleaves
17.2.9.14

File size:
35.8 MB (37,514,072 bytes)

Product version:
16.12

Copyright:
Copyright (C) 2017 Wide Angle Software

Original file name:
TouchCopy16.exe

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\users\{user}\downloads\touchcopy16.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
3/4/2015 7:00:00 PM

Valid to:
3/19/2017 7:59:59 PM

Subject:
CN=Wide Angle Software Ltd, O=Wide Angle Software Ltd, L=Stafford, S=Stafford, C=GB, SERIALNUMBER=05671223, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=GB

Issuer:
CN=Symantec Class 3 Extended Validation Code Signing CA - G2, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
3B644EE550F19B61E16A55B9D77667FF

File PE Metadata
Compilation timestamp:
12/14/2016 6:25:37 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0x268E0

Entry point:
E8, 38, 05, 00, 00, E9, 8E, FE, FF, FF, 6A, 10, 68, A0, EC, 44, 00, E8, 2A, 04, 00, 00, 33, DB, 89, 5D, E0, 88, 5D, E7, 89, 5D, FC, 3B, 5D, 10, 74, 1A, 8B, 4D, 14, E8, 45, 00, 00, 00, 8B, 4D, 08, FF, 55, 14, 8B, 45, 0C, 01, 45, 08, 43, 89, 5D, E0, EB, E1, B0, 01, 88, 45, E7, C7, 45, FC, FE, FF, FF, FF, E8, 0E, 00, 00, 00, E8, 30, 04, 00, 00, C2, 14, 00, 8B, 5D, E0, 8A, 45, E7, 84, C0, 75, 0F, FF, 75, 18, 53, FF, 75, 0C, FF, 75, 08, E8, FB, FC, FF, FF, C3, FF, 25, 44, F2, 43, 00, CC, CC, CC, CC, CC, CC, CC...
 
[+]

Entropy:
7.9859  (probably packed)

Code size:
246.5 KB (252,416 bytes)

The file TouchCopy16.exe has been seen being distributed by the following URL.

https://www.wideanglesoftware.com/.../TouchCopy16.exe

Remove TouchCopy16.exe - Powered by Reason Core Security