ocam.exe

Mediawave Corporation

Publisher:
oh!soft ( Partner: MediaWave )  (signed by Mediawave Corporation)

Description:
oCam - Screen Recorder

Version:
170.0.0.0

MD5:
9dbb43f660becbc369e4ef9275b8f06e

SHA-1:
8633d0552aeb3775a37016761f68b4352e2ed2e7

SHA-256:
2c1f95367840c22174b0defde22ef7e776ebae75a3bc626a69009ebbf22fa558

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
11/5/2024 2:48:06 AM UTC  (today)

Scan engine
Detection
Engine version

Rising Antivirus
PE:Malware.Generic(Thunder)!1.A1C4 [F]
23.00.65.16812

File size:
4.9 MB (5,182,664 bytes)

Product version:
170.0

Copyright:
oh!soft

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ocam.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
10/5/2015 8:00:00 AM

Valid to:
11/4/2016 7:59:59 AM

Subject:
CN=Mediawave Corporation, O=Mediawave Corporation, L=Seongnam-si, S=Gyeonggi-do, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
185D7D55F5ABFCD613846B5542E58611

File PE Metadata
Compilation timestamp:
12/11/2015 6:35:12 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:BftI6i/U0nSstrtl/ygZHAlsSsiRRRRRRRX5sAxSQqjeI6HyyQdaksZsSsuc:4BRlF+lsSsiRRRRRRRX5sAxSQqjeI6Hk

Entry address:
0x3A8A18

Entry point:
55, 8B, EC, 83, C4, F0, B8, 80, 69, 79, 00, E8, FC, 33, C6, FF, 68, 14, 8B, 7A, 00, 6A, FF, 6A, 00, E8, 86, 6D, C6, FF, A3, CC, 65, 87, 00, 83, 3D, CC, 65, 87, 00, 00, 0F, 84, C4, 00, 00, 00, E8, 77, 6E, C6, FF, 85, C0, 0F, 85, B7, 00, 00, 00, A1, 9C, 97, 7B, 00, 8B, 00, E8, 9B, 3E, E3, FF, E8, 76, DD, FE, FF, A1, 9C, 97, 7B, 00, 8B, 00, C6, 40, 6F, 01, A1, 9C, 97, 7B, 00, 8B, 00, 33, D2, E8, A1, 5A, E3, FF, B9, 70, 8B, 7A, 00, 8B, 15, 54, CC, 7B, 00, A1, 84, 5C, 58, 00, E8, 6C, 4C, DF, FF, 8B, D0, A1, 84...
 
[+]

Entropy:
6.5457

Developed / compiled with:
Microsoft Visual C++

Code size:
3.7 MB (3,830,272 bytes)

Scan ocam.exe - Powered by Reason Core Security