Malicious
998657bed1b4eed2f0b5ae70c7e8e3e8
PE Executable
MD5: 998657bed1b4eed2f0b5ae70c7e8e3e8
Size: 1.83 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Medium
| MD5 | 998657bed1b4eed2f0b5ae70c7e8e3e8 |
| Sha1 | 8969742783ca90205507746179f617522b4bf59a |
| Sha256 | 9c2b14d26cea958757168f181d94098bcbeb6eb263b6bc9f93288e93a8b3029a |
| Sha384 | d521f5064153144fc0330e875c2922dfbae9a32a22f3eecbc7b2ef614fcb8c4c74332e932ac1a8686ae98a5e48db2ff6 |
| Sha512 | 0ab2fe2c2fa990dd548605f54b5f6b6ffcb6a61d766ccc435a984aff3491ac692097855882065d0f33632b3707bd2393e1a9bbb42f42b19c9eb988c43c56de7b |
| SSDeep | 49152:ZhgVsbrKDuTkcE4NSlw9Q132QRleyUpkvPP7vMrTGM:ZKVs67cvO2Qm6XPTY |
| TLSH | 6D8512642B27E403C66123354AE2D5B403B85F9AF823E3575EE97DDBB66AF164C81303 |
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
5 / 5
Path
pe:exe>img>img
Shape
pe:exe>img>img
malicious
3 nodes
Path
pe:exe>pe:rsrc>img
Shape
pe:exe>pe:rsrc>img
malicious
3 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Info | PDB Path: jCLg.pdb |
| Module Name | jCLg.exe |
| Full Name | jCLg.exe |
| EntryPoint | System.Void BDg.sDI::pDW() |
| Scope Name | jCLg.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | jCLg |
| Assembly Version | 5.3.7.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | .NETFramework,Version=v4.8 |
| Total Strings | 434 |
| Main Method | System.Void BDg.sDI::pDW() |
| Main IL Instruction Count | 12 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.