Suspect
06a2e8ed1093aa0d0e10e68ed870d0b1
PE Executable
MD5: 06a2e8ed1093aa0d0e10e68ed870d0b1
Size: 399.36 KB
application/x-dosexec
Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.
AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score
Low
| MD5 | 06a2e8ed1093aa0d0e10e68ed870d0b1 |
| Sha1 | a15c0dbbf069da7b4d605af46212695f3c60da90 |
| Sha256 | 801906d53d973d68367754281a9aba78bbd0de99b35bfa34f63baafa49eb179a |
| Sha384 | d39a4467ab1e863574282d72852f55a67d44f2094ddfbce8bad21698d2f81c7309b1911423c20107b00bceb89c787d30 |
| Sha512 | a9cf3b18bbab3da22dabeac6d87ecc8e47cb8a8966590bdb71c1453fd6740335a541d3c2123792da81b649fcfc8876d922fd2c5885468555d77226d59ebed6e2 |
| SSDeep | 6144:HP4l5PwaVZrmb9TPFoCH55tFK/KYAabdZgvkwUsAdPz:HP4l5PwWrmbXoCH9s/KqAk |
| TLSH | 7E84186433F44604F2FFAFB5E8B045118A72F88BEA39D75E0AC9449E0D71B50AE50B67 |
STICH
beta
Structural Threat Infection Chain Hash
A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.
STICH Path = the fingerprint (canonical chain with techniques)
STICH Shape = structure only
Only determinant branches produce STICH Paths.
Path
pe:exe
Shape
pe:exe
1 nodes
| Name | Value |
|---|---|
| Info | PE Detect: PeReader OK (file layout) |
| Module Name | Phantom_794e63c0ddbf.exe |
| Full Name | Phantom_794e63c0ddbf.exe |
| EntryPoint | System.Void PhantomStealer4.Programs::<Main>(System.String[]) |
| Scope Name | Phantom_794e63c0ddbf.exe |
| Scope Type | ModuleDef |
| Kind | Windows |
| Runtime Version | v4.0.30319 |
| Tables Header Version | 512 |
| WinMD Version | <null> |
| Assembly Name | Phantom_794e63c0ddbf |
| Assembly Version | 0.0.0.0 |
| Assembly Culture | <null> |
| Has PublicKey | False |
| PublicKey Token | <null> |
| Target Framework | <null> |
| Total Strings | 4010 |
| Main Method | System.Void PhantomStealer4.Programs::<Main>(System.String[]) |
| Main IL Instruction Count | 7 |
| Main IL | |
No malware configuration was found at this point.
You must be signed in to view YARA rules.