File verdict·Decided by the MT AI Engine
Our call

Unknown

Our AI analyst is temporarily unavailable, so we've applied a conservative fallback: all 72 antivirus engines that scanned this file report it as clean.

Trust score50Caution
jilloff.exe
14.0 MB
62c5a559f0ea7a5938ddd2a7c8cc
Antivirus engines
0 of 76 flagged
Code signing
Unsigned
Age
First seen 16y ago
MT AI Engine · Verdict analysis

The reasoning behind this verdict

The MT AI Engine weighs every signal from this scan — antivirus detections, sandbox behaviour, code signing, prevalence and historical matches — to reach a single, evidence-based verdict.

30%Confidence
Exploratory
Reasoning

Our AI analyst is temporarily unavailable, so we've applied a conservative fallback: all 72 antivirus engines that scanned this file report it as clean. With that much coverage, the file looks safe — but re-scan in a few minutes to get the full AI assessment.

Key signals · 3

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. AI arbiter unavailable (reason: grok_http_403:{"code":"The caller does not have permission to execute the specified operation","error":"Your team 9dd48cd8-6db1-4c4c-88ed-8651d1e175c4 has either used all ava)

  2. engines.tier1Malicious=0

  3. engines.reporting=72

Points in its favour
  • 72 antivirus engines all report this file as clean.
Recommended action

The file appears safe based on antivirus coverage. Re-scan for the full AI assessment.

What to do now

There isn't enough information to give this file a clear rating.

  1. Be cautious — an unknown rating is not the same as a clean bill of health.

  2. Only run it if it came directly from the official maker of the software.

  3. When in doubt, don't open it — or scan it again later once it's more widely seen.

Sources disagree

1 contradiction resolved by the scoring engine

MT AI Engine read "safe", displayed verdict is "unknown"
A ground-truth gate (admin override, MalwareBazaar, empty-file) or the low-confidence display rule shifted the final call.
Displayed verdict tracks the harder evidence.
Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
17

Adversary techniques mapped to the MITRE ATT&CK framework.

T1010T1012T1027· Obfuscated codeT1027.005· Obfuscated codeT1056.001· KeyloggingT1059· Runs commandsT1071· Remote server (C2)T1082· System reconT1083· Scans your filesT1113T1115T1129· Loads modulesT1497.001· Sandbox evasionT1564.003· Hides artifactsT1574.002· Execution hijackT1614T1614.001
Spawned processes
5
$(unnamed)
"C:\Users\<USER>\AppData\Local\Temp\software.exe"
$(unnamed)
%SAMPLEPATH%\file.exe
$(unnamed)
C:\Windows\System32\wuapihost.exe
$(unnamed)
%SAMPLEPATH%\62c5a559f0ea7a5938ccd0396c754cebcf5a1e9e9983a62ab5c94fddd2a7c8cc.exe
$(unnamed)
C:\Users\user\Desktop\file.exe
Network activity
15
IP addresses15
  • 204.79.197.203
  • 20.99.186.246
  • 192.229.211.108
  • 104.96.203.51
  • 20.99.184.37
  • 20.99.185.48
  • 20.99.133.109
  • 23.216.81.152
  • 131.253.33.203
  • 192.168.0.6
+5 more
Filesystem & mutexes
25
Files written6
  • C:\Documents and Settings\Administrator\Local Settings\Temp\gm_ttt_28564\D3DX8.dll
  • C:\Users\<USER>\AppData\Local\Temp\gm_ttt_55444\D3DX8.dll
  • C:\Users\<USER>\AppData\Local\Temp\gm_ttt_55444\a26369.mp3
  • C:\Users\<USER>\AppData\Local\Temp\gm_ttt_55444\a1996.mp3
  • C:\Users\user\AppData\Local\Temp\gm_ttt_85096
+1 more
Files deleted9
  • C:\Windows\System32\spp\store\2.0\cache\cache.dat
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER602C.tmp.WERInternalMetadata.xml
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER6107.tmp.csv
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER6136.tmp.txt
  • C:\ProgramData\Microsoft\Windows\WER\Temp\WER65BB.tmp.WERInternalMetadata.xml
+4 more
Mutexes created10
  • DDrawWindowListMutex
  • __DDrawExclMode__
  • __DDrawCheckExclMode__
  • DDrawDriverObjectListMutex
  • CTF.LBES.MutexDefaultS-1-5-21-1482476501-1645522239-1417001333-500
+5 more
Dropped payload

Files this sample writes at runtime

This file drops 3 children at runtime. None are currently flagged malicious in our cache.

3 unseen
  • edfc5f86be36c2c509e42b076aNever scanned
    never seen before
  • 8109b7c55610d98365147766bdNever scanned
    never seen before
  • 7ecaa4e8095301c5357eda239eNever scanned
    never seen before
No researcher-database hits
External threat-intel sources were not collected for this scan.
Signature matches

YARA & heuristic rule matches

One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.

1 synthesis
MITRE ATT&CK profile
C2× 1
MalwareTips synthesis rules
Our own detection rules, applied to the scan data and sandbox behaviour
  • DirectIpC2medium

    Sample contacted 13 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.

    Evidence
    204.79.197.203 · 20.99.186.246 · 192.229.211.108
Antivirus engine breakdown

0 detections across 76 engines

0 malicious0 suspicious76 clean
Tier-118 engines
0flag
Top commercial AVs (low FP rate)
Tier-240 engines
0flag
Mainstream engines with mixed FP rates
Low-trust18 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 76 engines report this file as clean.
Hash 62c5a559f0ea… cross-referenced against 76 AV engines via our AV network.
PE forensics

Section entropy & packers

Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.

ent 8.00Unpacked
Section entropy8 sections
CODE
6.62
DATA
4.26
BSS
0.00
.idata
4.88
.tls
0.00
.rdata
0.19
.reloc
6.74
.rsrc
4.96
0.0Packed threshold 7.28.0
Prevalence

How widely this file has been seen

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
33
Moderate upload volume.
Total submissions
33
Includes repeat uploads by the same source.
First seen
16y ago
Dec 26, 2010
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
12/26/2010, 11:46:41 AM
First seen (MalwareBazaar)
Last analysis (VT)
12/2/2024, 6:09:11 PM
Scanned here
5/28/2026, 3:56:00 AM
File name
jilloff.exe
Size
13.96 MB
MIME type
(unknown)
Detected type
Win32 EXE
SHA-256
62c5a559f0ea7a5938ccd0396c754cebcf5a1e9e9983a62ab5c94fddd2a7c8cc
MD5
361ef67aa047cc20cfe16eeea2a6b25d
SHA-1
7ef390ab6cb722025a76c18507ae914565ad4dc1
PE imphash
faaa682bc37e74582e30337c8af101cd
First seen (VT)
12/26/2010, 11:46:41 AM
Last analysis (VT)
12/2/2024, 6:09:11 PM
First scan (MalwareTips)
5/28/2026, 3:56:00 AM
Last scan (MalwareTips)
5/28/2026, 3:56:00 AM
Behavior tags
overlaypeexe
Frequently asked

Safety FAQ

Common questions about jilloff.exe, answered from the scan data above.

  • We can't give jilloff.exe a confident verdict yet — too few engines have an opinion on this exact file. Uncommon or brand-new files often show little coverage before vendors catch up, so treat it as untrusted: don't run it unless you're certain of the source.
  • jilloff.exe is a Windows executable program, about 14 MB. We identify a file by its cryptographic hash rather than its name, because the same filename can be reused by completely different files — the hash below is the reliable fingerprint.
  • None — all 76 antivirus engines we queried report jilloff.exe as clean. That's reassuring, though brand-new malware can briefly evade detection before vendors add signatures, so we also weigh the file's behaviour and reputation.
  • The SHA-256 hash of jilloff.exe is 62c5a559f0ea7a5938ccd0396c754cebcf5a1e9e9983a62ab5c94fddd2a7c8cc, and its MD5 is 361ef67aa047cc20cfe16eeea2a6b25d. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
  • This report reflects the scan run on May 28, 2026. Because a file's hash never changes, the identity of jilloff.exe is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.