Malicious
Malicious

998657bed1b4eed2f0b5ae70c7e8e3e8

PE Executable
MD5: 998657bed1b4eed2f0b5ae70c7e8e3e8
Size: 1.83 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 998657bed1b4eed2f0b5ae70c7e8e3e8
Sha1 8969742783ca90205507746179f617522b4bf59a
Sha256 9c2b14d26cea958757168f181d94098bcbeb6eb263b6bc9f93288e93a8b3029a
Sha384 d521f5064153144fc0330e875c2922dfbae9a32a22f3eecbc7b2ef614fcb8c4c74332e932ac1a8686ae98a5e48db2ff6
Sha512 0ab2fe2c2fa990dd548605f54b5f6b6ffcb6a61d766ccc435a984aff3491ac692097855882065d0f33632b3707bd2393e1a9bbb42f42b19c9eb988c43c56de7b
SSDeep 49152:ZhgVsbrKDuTkcE4NSlw9Q132QRleyUpkvPP7vMrTGM:ZKVs67cvO2Qm6XPTY
TLSH 6D8512642B27E403C66123354AE2D5B403B85F9AF823E3575EE97DDBB66AF164C81303
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Bn.se.resources
$this.Icon
[NBF]root.IconData
gxj.qxM.resources
NJ
[NBF]root.Data
yJa.oJn.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
QQC.Properties.Resources.resources
h17 (5)
[NBF]root.Data
[NBF]root.Data-preview.png
h17 (4)
[NBF]root.Data
[NBF]root.Data-preview.png
a4
[NBF]root.Data
[NBF]root.Data-preview.png
h21
[NBF]root.Data
[NBF]root.Data-preview.png
a9 (7)
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
a9 (2)
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
NvHX
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
5 / 5
Path pe:exe>img>img
Shape pe:exe>img>img
malicious 3 nodes
Path pe:exe>pe:rsrc>img
Shape pe:exe>pe:rsrc>img
malicious 3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: jCLg.pdb
Module Name
jCLg.exe
Full Name
jCLg.exe
EntryPoint
System.Void BDg.sDI::pDW()
Scope Name
jCLg.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
jCLg
Assembly Version
5.3.7.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
434
Main Method
System.Void BDg.sDI::pDW()
Main IL Instruction Count
12
Main IL
br IL_0010: call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_002A: call System.Void gUs.tUr::CXp()
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0005: ldc.i4.0
ret <null>
newobj System.Void gxj.qxM::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_001A: ret
call System.Void gUs.tUr::CXp()
br IL_001B: newobj System.Void gxj.qxM::.ctor()
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Bn.se.resources
$this.Icon
[NBF]root.IconData
gxj.qxM.resources
NJ
[NBF]root.Data
yJa.oJn.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
QQC.Properties.Resources.resources
h17 (5)
[NBF]root.Data
[NBF]root.Data-preview.png
h17 (4)
[NBF]root.Data
[NBF]root.Data-preview.png
a4
[NBF]root.Data
[NBF]root.Data-preview.png
h21
[NBF]root.Data
[NBF]root.Data-preview.png
a9 (7)
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
a9 (2)
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
NvHX
[NBF]root.Data
[NBF]root.Data-preview.png
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙