Evidence & reproducibility
Integrity 83% · 5/6 evidence signalsGOODVERIFIED
The published claims are tied to captured sample hashes, static-analysis evidence, file offsets, data-flow tracing, and reproducible repository artifacts; unavailable third-stage behavior is explicitly excluded from the conclusions.Machine-readable checks- ✓ Captured samples identified by SHA-256
- ✓ Unsigned remote payload execution path documented
- ✓ Controller-to-injection data flow documented
- ◇ Unavailable third-stage behavior independently verified
Evidence- Outer loader downloads and manually maps an unsigned PE/DLL before invoking JNI_OnLoad.
- Controller requests a server-selected third-stage PE and feeds it into a remote manual-mapping path.
- IOC, YARA, integrity-manifest, and evidence-ledger artifacts are published without redistributing the suspicious binaries.
Environment- target
- Prestige Client loader and captured controller DLL
- method
- Static PE analysis, call/data-flow tracing, IOC extraction
- safety
- Suspicious binaries excluded; analysis artifacts only
Artifacts- Publishable investigation report
sha256:02298265da8f… - Claim-by-claim evidence ledger
sha256:bab1afc89562… - Detection rule
sha256:e1274d624d77…
ReproductionReview the pinned report, evidence ledger, static-analysis notes, IOC set, YARA rule, and SHA256SUMS manifest without executing the captured binaries.