Malicious
Malicious

998657bed1b4eed2f0b5ae70c7e8e3e8

Share on LinkedIn
Print
PE Executable
MD5: 998657bed1b4eed2f0b5ae70c7e8e3e8
Size: 1.83 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Medium
MD5 998657bed1b4eed2f0b5ae70c7e8e3e8
Sha1 8969742783ca90205507746179f617522b4bf59a
Sha256 9c2b14d26cea958757168f181d94098bcbeb6eb263b6bc9f93288e93a8b3029a
Sha384 d521f5064153144fc0330e875c2922dfbae9a32a22f3eecbc7b2ef614fcb8c4c74332e932ac1a8686ae98a5e48db2ff6
Sha512 0ab2fe2c2fa990dd548605f54b5f6b6ffcb6a61d766ccc435a984aff3491ac692097855882065d0f33632b3707bd2393e1a9bbb42f42b19c9eb988c43c56de7b
SSDeep 49152:ZhgVsbrKDuTkcE4NSlw9Q132QRleyUpkvPP7vMrTGM:ZKVs67cvO2Qm6XPTY
TLSH 6D8512642B27E403C66123354AE2D5B403B85F9AF823E3575EE97DDBB66AF164C81303
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_ICON
ID:0001
ID:0
ID:0-preview.png
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
.Net Resources
Bn.se.resources
$this.Icon
[NBF]root.IconData
gxj.qxM.resources
NJ
[NBF]root.Data
yJa.oJn.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
$this.Icon
[NBF]root.IconData
progressBar1.Modifiers
$this.Language
$this.GridSize
QQC.Properties.Resources.resources
h17 (5)
[NBF]root.Data
[NBF]root.Data-preview.png
h17 (4)
[NBF]root.Data
[NBF]root.Data-preview.png
a4
[NBF]root.Data
[NBF]root.Data-preview.png
h21
[NBF]root.Data
[NBF]root.Data-preview.png
a9 (7)
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
a9 (2)
[NBF]root.Data
[NBF]root.Data.exif
[NBF]root.Data-preview.png
NvHX
[NBF]root.Data
[NBF]root.Data-preview.png
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
5 / 5
Path pe:exe>img>img
Shape pe:exe>img>img
malicious 3 nodes
Path pe:exe>pe:rsrc>img
Shape pe:exe>pe:rsrc>img
malicious 3 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: jCLg.pdb
Module Name
jCLg.exe
Full Name
jCLg.exe
EntryPoint
System.Void BDg.sDI::pDW()
Scope Name
jCLg.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
jCLg
Assembly Version
5.3.7.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
434
Main Method
System.Void BDg.sDI::pDW()
Main IL Instruction Count
12
Main IL
br IL_0010: call System.Void System.Windows.Forms.Application::EnableVisualStyles()
ldc.i4.0 <null>
call System.Void System.Windows.Forms.Application::SetCompatibleTextRenderingDefault(System.Boolean)
br IL_002A: call System.Void gUs.tUr::CXp()
call System.Void System.Windows.Forms.Application::EnableVisualStyles()
br IL_0005: ldc.i4.0
ret <null>
newobj System.Void gxj.qxM::.ctor()
call System.Void System.Windows.Forms.Application::Run(System.Windows.Forms.Form)
br IL_001A: ret
call System.Void gUs.tUr::CXp()
br IL_001B: newobj System.Void gxj.qxM::.ctor()
An error has occurred. This application may no longer respond until reloaded. Reload 🗙