The CLIPStudioPaint.exe (CLIP STUDIO PAINT) File Analysis
Technical Analysis
| File Name | CLIPStudioPaint.exe |
| File Type |
Win32 EXE
|
| Magic Bytes | PE32+ executable (GUI) x86-64, for MS Windows |
| SSDEEP Hash |
786432:ijHjEKol/aVag+g3XUZu5lJ6781M5q4jX:MDE/8aTgTXbM5q4jX
|
| Scanner Version | 1.0.209.174 |
| Database Version | 2025-02-23 09:00:29 UTC |
Suspicious File Detected
Detected by 11 security engines - requires caution
Scan Another File
File Identification
| Hash Type | Value | Action |
|---|---|---|
| MD5 |
e1c717cbef97475b3e5411299fccc0bd
|
|
| SHA1 |
907050e7df4b5e064097648b269669c05bcb6ae5
|
|
| SHA256 |
f5896480e58a6992eb94e1daecce4e4436b6efcf943adc71e08543765bff4ca9
|
|
| SHA512 |
f12898846ee28895e53bbf6fb9d62975bcd96c3d41db799f692d693391e29cf603d11e92331be21549f0f0ae1ac032de37a16598b1eb7dcd5f083d01a05f25ab
|
|
| ImpHash |
20480cbb59054161fec3685fca6411a5
|
Security Engines with Detections (11 of 71)
PE Analysis
Basic Information
▼| Icon |
Hash: 863f61d6f2716c147763aa8c36936bf8
Fuzzy: c023a2e141a89059191f38edc486950d dHash: c88e236d330ccec8 |
| Image Base | 0x140000000 |
| Entry Point | 0x146772fe0 |
| Compilation Time | 2024-07-24 08:58:41 |
| Checksum | 0x04f91c44 (Actual: 0x0223ed89) |
| OS Version | 6.0 |
| PEiD Signatures |
PE32+ executable (GUI) x86-64, for MS Windows
|
| Digital Signature | No valid SignedData structure was found. |
| Imports | 66 libraries |
| Exports | 2 functions |
| Resources | 86 Resources |
| Sections | 10 Sections |
Version Information
▼| CompanyName | CELSYS,Inc. |
| FileDescription | CLIP STUDIO PAINT |
| FileVersion | 3.1.0.0 |
| InternalName | CLIP STUDIO PAINT |
| LegalCopyright | (C) CELSYS,Inc. All Rights Reserved. |
| OriginalFilename | CLIPStudioPaint.exe |
| ProductName | CLIP STUDIO PAINT |
| ProductVersion | 3.1.0 |
| Translation | 0x0409 0x04b0 |
PE Sections
▼| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
|---|---|---|---|---|---|---|
|
0x00001000 |
62,578,688 bytes | 20,178,944 bytes | 8.00 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
1A82DC8488F6278E9123B201B580D414 |
|
0x03baf000 |
12,726,272 bytes | 4,784,640 bytes | 8.00 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
AB24263F52BC6F6BC1D05FA1EF1F934C |
|
0x047d2000 |
4,644,864 bytes | 209,920 bytes | 8.00 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
EA5D8BCB27F34D216323EDBCEE785D09 |
|
0x04c40000 |
1,978,368 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
|
0x04e23000 |
12,288 bytes | 3,072 bytes | 7.82 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D715ECA6FBF90880A21D49696ABC4B38 |
|
0x04e26000 |
3,633,152 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
|
0x0519d000 |
434,176 bytes | 43,520 bytes | 7.99 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
A8D60BE206E53E1487BDB3EB2B7F992B |
.rsrc |
0x05207000 |
3,633,152 bytes | 3,632,640 bytes | 4.87 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
67FE09374418D645A99F420B17126ABF |
|
0x0557e000 |
13,479,936 bytes | 1,624,064 bytes | 8.00 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
1ADC4101B1F15FF5AB6579DA6F8410A6 |
|
0x06259000 |
5,369,856 bytes | 5,369,344 bytes | 7.79 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
E13C27533E347195F44F23AF8526EAD6 |
Entropy Analysis Alert
7 section(s) with high entropy (≥7.5) detected - possible packing/encryption
Resource Analysis
▼| Resource Type | Count | Total Size | Percentage |
|---|---|---|---|
| RT_ICON | 72 | 3,625,122 bytes | |
| RT_GROUP_ICON | 12 | 1,080 bytes | |
| RT_VERSION | 1 | 776 bytes | |
| RT_MANIFEST | 1 | 1,021 bytes |
Certificate Chain Analysis
▼Certificate Information
| Product | CLIP STUDIO PAINT |
| Description | CLIP STUDIO PAINT |
| File Version | 3.1.0.0 |
| Original Name | CLIPStudioPaint.exe |
| Internal Name | CLIP STUDIO PAINT |
| Copyright | (C) CELSYS,Inc. All Rights Reserved. |
Certificate Chain Summary
4C 92 18 96 8B 96 0B C3 97 05 82 A5 FA 03 50 A6 4A 08 28 7D2C ED 5C 2C 5D B4 B7 06 CF DF 0F 49 77 45 62 80 4F DC 00 C778 03 18 42 45 70 8A 41 CF 6F 01 B8 EE B4 A9 5477 BD 0E 05 B7 59 0B B6 1D 47 61 53 1E 3F 75 ED08 38 7A 7D 1C 01 4C 74 D7 FA 1A DE01 19 75 74 71 C9 92 D7 44 DF A5 96 EB B9 70 1501 EC 1C 92 40 DE FD 2E 40 5D 7C 47 7445 E6 BB 03 83 33 C3 85 65 48 E6 FF 45 51✓ This file has been digitally signed and the certificate chain has been verified
- The signature ensures file integrity and authenticity from the publisher
- Timestamping proves when the signature was applied
Certificate Verification Status
No valid SignedData structure was found.
Recommendation: Verify the file source and ensure it comes from a trusted publisher.
Remember: This is Result of Online Virus Scanner
Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:
Download Anti-Malware
Keep Your System Protected
This file appears clean, but regular security maintenance is important
-
1
Weekly Quick Scans: Set a reminder to run a scan every Sunday. Most infections are caught within the first week, so regular checks give you peace of mind.
-
2
Update Everything: Those annoying update popups exist for a reason — they patch security holes. Windows, browsers, Adobe, Java — keep them all current.
-
3
Download Smart: Stick to official websites and app stores. If a "free" version of paid software sounds too good to be true, it probably comes with unwanted extras.
-
4
Think Before You Click: Malware loves email attachments and "urgent" links. Even if an email looks like it's from your bank or a friend, verify suspicious requests through a different channel.
Leave a Comment
Gridinsoft Anti-Malware
Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware
Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!