JOCR.exe

JOCR

HOME

Publisher:
HOME

Product:
JOCR

Version:
1.00

MD5:
f2d82ab4690eca72c75f46fa049c187a

SHA-1:
867753fba41ec17fc14c6d4bbdeee088095de796

SHA-256:
3a5fdeb871f770f1214ab6909894ada41cecb9169ab77d579472347899b04dbc

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 3:20:32 AM UTC  (today)

File size:
84 KB (86,016 bytes)

Product version:
1.00

Original file name:
JOCR.exe

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
3/16/2006 11:01:45 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:b5+fkeFU0oPej/lyQf+fPKbxjNLTtrVcKRZfZ5:b5zQlT3LZTT5

Entry address:
0x1848

Entry point:
68, 48, 2B, 40, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 38, 00, 00, 00, 00, 00, 00, 00, 99, E0, 11, 1E, 97, B3, 1A, 4E, 90, 52, D5, 23, 3F, F4, 33, EB, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 4A, 4F, 43, 52, 00, 00, 00, 00, 00, 00, 00, 00, FF, CC, 31, 00, 0C, 23, 68, C4, D0, 78, 8F, B8, 4C, 9E, 4C, 1D, 91, 3B, 33, C5, 61, 43, 95, E5, 76, 6C, 57, 54, 44, BD, 39, 90, 4D, C1, EA, 01, BF, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00, AA, 00, 60, D3, 93, 00, 00, 00...
 
[+]

Entropy:
5.1754

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
68 KB (69,632 bytes)

The file JOCR.exe has been seen being distributed by the following 10 URLs.

http://dw.br.uptodown.com/dl/1444829499/.../jocr.exe

https://sg2000.webmail.hinet.net/.../sendAttach.do?&msg=D2658F95C7D748DBCFC2FB1C64081D87&pid=0

https://jocr.en.softonic.com/download-tracker?th=1/.../32Jwpk0dNzLy5EcZMZ vs1MwdGIENFrJgIOCBbYFlVJpeTXV0IJUkn2mLRq9cgr6PdC0YmA7HFjIRNQzhW0=

http://asp.fhjh.ntpc.edu.tw/download/.../JOCR.exe

http://gsf-cf.softonic.com/867/753/.../file?SD_used=0&channel=WEB&fdh=no&id_file=50485&instance=softonic_br&type=PROGRAM&Expires=1478706597&Signature=StzAeNoVFhOfgyssb4iaPHWnHNjKqEaqalsDtgaHZAVpY7A~0MtcTwGeInmteCs1tvVnfFgG5TmnMpAMdJSWvoerIcNgtQh9-MsS1gNPklmijyoAXfMKoMGam8czVMqjxCxgkLhtqrmSUGOvhqpBqXe3f5RnIqs3FgfB-s8jbFU_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=JOCR.exe

Scan JOCR.exe - Powered by Reason Core Security