clic.exe

The application clic.exe has been detected as a potentially unwanted program by 34 anti-malware scanners. The file has been seen being downloaded from docteurjp.free.fr.
MD5:
bb14f7571c5c91e3b172f5d0cebf3d4e

SHA-1:
2618027fe1d21d28393ba20c6ba054b60008e21a

SHA-256:
6b66ffed89e1c5c0c15fb2e9fc2650e803a9162fb1dacddab275397de528191c

Scanner detections:
34 / 68

Status:
Potentially unwanted

Analysis date:
4/20/2024 2:00:55 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Joke.Melter.A
1150

Agnitum Outpost
Trojan.Agent
7.1.1

AhnLab V3 Security
Trojan/Win32.Starter
2013.12.28

Avira AntiVirus
JOKE/Melter
7.11.122.108

avast!
Win32:Malware-gen
2014.9-130829

Baidu Antivirus
Trojan.Win32.BadJoke
4.0.3.131127

Bitdefender
Joke.Melter.A
1.0.20.1205

Bkav FE
W32.Clod536.Trojan
1.3.0.4613

Clam AntiVirus
Joke.Melter.B
0.98/18155

Comodo Security
ApplicUnsaf.Win32.Hoax.BadJoke.Melter
17507

Dr.Web
Joke.Finger.5
9.0.1.0241

Emsisoft Anti-Malware
Joke.Melter
8.13.08.29.06

Fortinet FortiGate
Riskware/Melter
8/29/2013

F-Prot
W32/Joke.BY
v6.4.7.1.166

F-Secure
Joke.Melter.A
11.2013-29-08_5

G Data
Joke.Melter
13.8.22

IKARUS anti.virus
not-a-virus:BadJoke.Win32.Melter
t3scan.2.2.29

K7 AntiVirus
Backdoor
13.174.10656

Kaspersky
Hoax.Win32.BadJoke.Melter
14.0.0.3810

Malwarebytes
Joke.Melter
v2013.08.29.06

McAfee
Joke-Melter
5600.7181

Microsoft Security Essentials
Joke:Win32/Melter
1.165.247.01

MicroWorld eScan
Joke.Melter.A
14.0.0.723

NANO AntiVirus
Riskware.Win32.Melter.opmt
0.28.0.57029

Norman
Suspicious_Gen2.UGYRV
11.20130829

nProtect
Joke/W32.BadJoke.24576.F
13.12.27.01

Panda Antivirus
Joke/Melter
13.08.29.06

Quick Heal
Hoax.BadJoke.Melter.n3 (Not a Virus)
8.13.12.00

Reason Heuristics
Unnamed.Threat.64
14.3.1.0

Rising Antivirus
PE:Trojan.Win32.Generic.122D17DC!304945116
23.00.65.13827

Sophos
Joke/Melter-A
4.96

Trend Micro House Call
JOKE_MELTER.A
7.2.241

Trend Micro
JOKE_MELTER.A
10.465.29

VIPRE Antivirus
Trojan.Win32.Generic
24806

File size:
24 KB (24,576 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\clic.exe

File PE Metadata
Compilation timestamp:
1/14/2002 7:12:45 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
192:zhEhAAT/HqAlCIF/Sx5CIWfFdurQXdcPN0tXzwmZBdZD9qB3y2JEPGHrcXq1Lyy3:MVl0uM9NUXcml3gC2Pyy4aFrh6oZ

Entry address:
0x110E

Entry point:
55, 8B, EC, 6A, FF, 68, B8, 40, 40, 00, 68, 44, 1C, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, 28, 40, 40, 00, 33, D2, 8A, D4, 89, 15, B4, 54, 40, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, B0, 54, 40, 00, C1, E1, 08, 03, CA, 89, 0D, AC, 54, 40, 00, C1, E8, 10, A3, A8, 54, 40, 00, 33, F6, 56, E8, A1, 09, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, B0, 00, 00, 00, 59, 89, 75, FC, E8, E1, 07, 00, 00, FF, 15, 24, 40, 40, 00, A3, B8, 59, 40, 00, E8...
 
[+]

Entropy:
4.2885

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
12 KB (12,288 bytes)

The file clic.exe has been seen being distributed by the following URL.

Remove clic.exe - Powered by Reason Core Security