ocr.exe

Binary Valley, Inc.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘OCR’.
Publisher:
Binary Valley, Inc.  (signed and verified)

MD5:
a1c74064a8332fe5e24980e226c57a80

SHA-1:
b53b9533b843a1c9584368e5bbbe4aaaa51f0591

SHA-256:
99e20089fad63400edc1fe184951514649e76e0699c2a8f5e3a5e89dd890f462

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/6/2024 4:59:47 PM UTC  (today)

File size:
606.5 KB (621,096 bytes)

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
COMODO CA Limited

Valid from:
9/12/2016 5:00:00 AM

Valid to:
3/29/2018 4:59:59 AM

Subject:
CN="Binary Valley, Inc.", O="Binary Valley, Inc.", STREET=901 N. Pitt St Suite 325, L=Alexandria, S=Virginia, PostalCode=22314, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F9848C90DA431709130E98F24F1F4654

File PE Metadata
Compilation timestamp:
9/5/2016 9:53:20 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:x2geB6mI1dVwQU2moqm+Xz5PLkgF6i7jVJ+DJtRFox:DF8HlogF6AJ+DLRy

Entry address:
0x373D9

Entry point:
E8, 44, 1F, 01, 00, E9, 89, FE, FF, FF, 6A, 08, 68, 90, 9F, 46, 00, E8, 91, 00, 00, 00, E8, C0, 16, 00, 00, 8B, 40, 78, 85, C0, 74, 16, 83, 65, FC, 00, FF, D0, EB, 07, 33, C0, 40, C3, 8B, 65, E8, C7, 45, FC, FE, FF, FF, FF, E8, BC, 7A, 00, 00, E8, AA, 00, 00, 00, C3, E8, 93, 16, 00, 00, 8B, 40, 7C, 85, C0, 74, 02, FF, D0, E9, B4, FF, FF, FF, 6A, 08, 68, B0, 9F, 46, 00, E8, 45, 00, 00, 00, FF, 35, DC, FB, 46, 00, FF, 15, A0, D1, 45, 00, 85, C0, 74, 16, 83, 65, FC, 00, FF, D0, EB, 07, 33, C0, 40, C3, 8B, 65...
 
[+]

Entropy:
6.2731

Code size:
367.5 KB (376,320 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
OCR

Command:
C:\new folder\ocr.exe


Scan ocr.exe - Powered by Reason Core Security