File verdict·Decided by the MT AI Engine
Our call

Unknown

Our AI analyst is temporarily unavailable, so we've applied a conservative fallback: all 72 antivirus engines that scanned this file report it as clean.

Trust score50Caution
MT AI confidence · 30%
jilloff.exe
14.0 MB
62c5a559f0ea7a5938ddd2a7c8cc
Antivirus engines
0 of 76 flagged
Code signing
Unsigned
Age
First seen 15y ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

30%Confidence
Exploratory
Reasoning

Our AI analyst is temporarily unavailable, so we've applied a conservative fallback: all 72 antivirus engines that scanned this file report it as clean. With that much coverage, the file looks safe — but re-scan in a few minutes to get the full AI assessment.

Key signals · 3

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. AI arbiter unavailable (reason: grok_http_403:{"code":"The caller does not have permission to execute the specified operation","error":"Your team 9dd48cd8-6db1-4c4c-88ed-8651d1e175c4 has either used all ava)

  2. engines.tier1Malicious=0

  3. engines.reporting=72

Points in its favour
  • 72 antivirus engines all report this file as clean.
What to do

The file appears safe based on antivirus coverage. Re-scan for the full AI assessment.

Sources disagree

1 contradiction resolved by the scoring engine

MT AI Engine read "safe", displayed verdict is "unknown"
A ground-truth gate (admin override, MalwareBazaar, empty-file) or the low-confidence display rule shifted the final call.
Displayed verdict tracks the harder evidence.
Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
17

Adversary techniques mapped to the MITRE ATT&CK framework.

T1010T1012T1027T1027.005T1056.001T1059T1071T1082T1083T1113T1115T1129T1497.001T1564.003T1574.002T1614T1614.001
Spawned processes
5
$(unnamed)
"C:\Users\<USER>\AppData\Local\Temp\software.exe"
$(unnamed)
%SAMPLEPATH%\file.exe
$(unnamed)
C:\Windows\System32\wuapihost.exe
$(unnamed)
%SAMPLEPATH%\62c5a559f0ea7a5938ccd0396c754cebcf5a1e9e9983a62ab5c94fddd2a7c8cc.exe
$(unnamed)
C:\Users\user\Desktop\file.exe
Network activity
15
IP addresses15
  • 204.79.197.203
  • 20.99.186.246
  • 192.229.211.108
  • 104.96.203.51
  • 20.99.184.37
  • 20.99.185.48
  • 20.99.133.109
  • 23.216.81.152
  • 131.253.33.203
  • 192.168.0.6
+5 more
Filesystem & mutexes
25
Files written6
  • C:\Documents and Settings\Administrator\Local Settings\Temp\gm_ttt_28564\D3DX8.dll
  • C:\Users\<USER>\AppData\Local\Temp\gm_ttt_55444\D3DX8.dll
  • C:\Users\<USER>\AppData\Local\Temp\gm_ttt_55444\a26369.mp3
  • C:\Users\<USER>\AppData\Local\Temp\gm_ttt_55444\a1996.mp3
  • C:\Users\user\AppData\Local\Temp\gm_ttt_85096
+1 more
Files deleted9
  • C:\Windows\System32\spp\store\2.0\cache\cache.dat
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER602C.tmp.WERInternalMetadata.xml
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER6107.tmp.csv
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER6136.tmp.txt
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER65BB.tmp.WERInternalMetadata.xml
+4 more
Mutexes created10
  • DDrawWindowListMutex
  • __DDrawExclMode__
  • __DDrawCheckExclMode__
  • DDrawDriverObjectListMutex
  • CTF.LBES.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
+5 more
Dropped payload

Files this sample writes at runtime

This file drops 3 children at runtime. None are currently flagged malicious in our cache.

3 unseen
  • edfc5f86be36c2c509e42b076aNever scanned
    never seen before
  • 8109b7c55610d98365147766bdNever scanned
    never seen before
  • 7ecaa4e8095301c5357eda239eNever scanned
    never seen before
No researcher-database hits
External threat-intel sources were not collected for this scan.
Signature matches

YARA + heuristic rules that fired

One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.

1 synthesis
MITRE ATT&CK profile
C2× 1
MalwareTips synthesis rules
Our heuristics on VT data + sandbox behaviour
  • DirectIpC2medium

    Sample contacted 13 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    204.79.197.203 · 20.99.186.246 · 192.229.211.108
Antivirus engine breakdown

0 detections across 76 engines

0 malicious0 suspicious76 clean
Tier-118 engines
0flag
Top commercial AVs (low FP rate)
Tier-237 engines
0flag
Mainstream engines with mixed FP rates
Low-trust21 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 76 engines report this file as clean.
Hash 62c5a559f0ea… cross-referenced against 76 AV engines via our AV network.
PE forensics

Section entropy & packers

Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.

ent 8.00Unpacked
Section entropy8 sections
CODE
6.62
DATA
4.26
BSS
0.00
.idata
4.88
.tls
0.00
.rdata
0.19
.reloc
6.74
.rsrc
4.96
0.0Packed threshold 7.28.0
Prevalence

How often this file shows up in the wild

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
33
Moderate upload volume.
Total submissions
33
Includes repeat uploads by the same source.
First seen by VT
15y ago
Dec 26, 2010
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
12/26/2010, 11:46:41 AM
First seen (MalwareBazaar)
Last analysis (VT)
12/2/2024, 6:09:11 PM
Scanned here
5/28/2026, 3:56:00 AM
File name
jilloff.exe
Size
13.96 MB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
62c5a559f0ea7a5938ccd0396c754cebcf5a1e9e9983a62ab5c94fddd2a7c8cc
MD5
361ef67aa047cc20cfe16eeea2a6b25d
SHA-1
7ef390ab6cb722025a76c18507ae914565ad4dc1
PE imphash
faaa682bc37e74582e30337c8af101cd
First seen (VT)
12/26/2010, 11:46:41 AM
Last analysis (VT)
12/2/2024, 6:09:11 PM
First scan (MalwareTips)
5/28/2026, 3:56:00 AM
Last scan (MalwareTips)
5/28/2026, 3:56:00 AM
Behavior tags
overlaypeexe
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.