Suspicious
Suspect

6ecfd7c88c153935cadbea2841d113f1

PE Executable
|
MD5: 6ecfd7c88c153935cadbea2841d113f1
|
Size: 130.05 KB
|
application/x-dosexec

Summary by MalvaGPT
Characteristics

Symbol Obfuscation Score

Very low

Hash
Hash Value
MD5
6ecfd7c88c153935cadbea2841d113f1
Sha1
f2448ab7b4b355881a1cb48c5914bbff90c97de1
Sha256
f1faa923f5875168554785449c8af12cd96c402753c5bd0db5eac4ea37f7cace
Sha384
20fead85b67317b8c6e3009f44606e6d7933e56dd7dcf806b8ed03b5fc43cf45b26c34a3b376a978f602048d6b609564
Sha512
7fc26022ed068dbeae33ec7cb2b74704980ada00f97ad162d16c7e8efb80befdca3354975d37dc2c76addff1d17b17fba4bdb0de3838bf702670dda1c6b358f7
SSDeep
1536:xqz8rx/RmUJAD246dQ7mAfM6tdHn6Amf1ev2Bb0Gp8kfbvbGSYIgD1za5LEoW+du:x6xH77fM6kf1OKTxjZJ5LEYdVej
TLSH
43D35C153388EB49EB7D463D54B0132646F0D0972A23EBDA4EC478CD3F26F9296126F6
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Informations
Name
Value
Info

PE Detect: PeReader OK (file layout)

Info

PDB Path: ?

Module Name

Oriflammes.exe

Full Name

Oriflammes.exe

EntryPoint

System.Void Selenium.Program::Main(System.String[])

Scope Name

Oriflammes.exe

Scope Type

ModuleDef

Kind

Windows

Runtime Version

v4.0.30319

Tables Header Version

512

WinMD Version

<null>

Assembly Name

Oriflammes

Assembly Version

0.0.0.0

Assembly Culture

<null>

Has PublicKey

False

PublicKey Token

<null>

Target Framework

.NETFramework,Version=v4.0

Total Strings

221

Main Method

System.Void Selenium.Program::Main(System.String[])

Main IL Instruction Count

24

Main IL

newobj System.Void Selenium.Data.Core.Launchers.Executor::.ctor() stloc.0 <null> newobj System.Void Selenium.Data.Core.AhnLabIdiNaxui::.ctor() stloc.1 <null> ldloc.0 <null> ldloc.1 <null> callvirt Selenium.Models.Core.XmlParser Selenium.Models.Core.XmlParser::Init(Selenium.Models.Core.ICommunicator) newobj System.Void Selenium.Data.Core.LogParsers.Processor::.ctor() callvirt Selenium.Models.Core.XmlParser Selenium.Models.Core.XmlParser::Prepere(Selenium.Data.Core.LogParsers.BaseLogParser) callvirt System.Boolean Selenium.Models.Core.XmlParser::Parse() brfalse.s IL_0026: leave.s IL_0000 leave.s IL_003C: ret leave.s IL_0000: newobj System.Void Selenium.Data.Core.Launchers.Executor::.ctor() ldloc.1 <null> brfalse.s IL_0031: endfinally ldloc.1 <null> callvirt System.Void System.IDisposable::Dispose() endfinally <null> ldloc.0 <null> brfalse.s IL_003B: endfinally ldloc.0 <null> callvirt System.Void System.IDisposable::Dispose() endfinally <null> ret <null>

6ecfd7c88c153935cadbea2841d113f1 (130.05 KB)
File Structure
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙