TcNcI.exe

Beckhoff GmbH TcNcI

Beckhoff Automation GmbH

It runs as a separate (within the context of its own process) windows Service named “TwinCAT Nc Interpreter”.
Publisher:
Beckhoff Automation GmbH  (signed and verified)

Product:
Beckhoff GmbH TcNcI

Description:
TcNcI

Version:
2, 11, 0, 3017

MD5:
037c714ab8b4652ab4a09a6188500d35

SHA-1:
bac50a24d1c5917c77e6c741bbd02dc8fb5f6c87

SHA-256:
27eed4e093159569b40bd51c97910852f23d070d60d5983e0b5d4187016fac5f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 6:24:18 AM UTC  (today)

File size:
532 KB (544,816 bytes)

Product version:
2,11,2241,0

Copyright:
Copyright © 1998 - 2014

Original file name:
TcNcI.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/19/2013 10:14:35 AM

Valid to:
3/19/2017 10:14:35 AM

Subject:
E=info@beckhoff.com, CN=Beckhoff Automation GmbH, O=Beckhoff Automation GmbH, L=Verl, S=NRW, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121BBC574B28F2A871F0F8F4B9FB21DA509

File PE Metadata
Compilation timestamp:
3/7/2014 5:03:36 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
12288:ui+ZHfjLawgv1vQyN8KXycbxus+2dN98mXAqhlySsJ44+oSqMIMgI99jtAXNzriE:udqhLs+4+oSqlZem9a2b

Entry address:
0x60600

Entry point:
E8, 19, 05, 00, 00, E9, 40, FD, FF, FF, FF, 25, F0, A1, 46, 00, FF, 25, F4, A1, 46, 00, FF, 25, F8, A1, 46, 00, FF, 25, FC, A1, 46, 00, FF, 25, B8, A1, 46, 00, FF, 25, D0, A0, 46, 00, FF, 25, D4, A0, 46, 00, FF, 25, D8, A0, 46, 00, FF, 25, DC, A0, 46, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 98, 5C, 48, 00, 89, 0D, 94, 5C, 48, 00, 89, 15, 90, 5C, 48, 00, 89, 1D, 8C, 5C, 48, 00, 89, 35, 88, 5C, 48, 00, 89, 3D, 84, 5C, 48, 00, 66, 8C, 15, B0, 5C, 48, 00, 66, 8C, 0D, A4, 5C, 48, 00, 66, 8C, 1D, 80...
 
[+]

Entropy:
6.4408

Code size:
417 KB (427,008 bytes)

Service
Display name:
TwinCAT Nc Interpreter

Service name:
TcNcI

Type:
Win32OwnProcess

Group:
Base


Scan TcNcI.exe - Powered by Reason Core Security