Suspicious
Suspect

06a2e8ed1093aa0d0e10e68ed870d0b1

PE Executable
MD5: 06a2e8ed1093aa0d0e10e68ed870d0b1
Size: 399.36 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 06a2e8ed1093aa0d0e10e68ed870d0b1
Sha1 a15c0dbbf069da7b4d605af46212695f3c60da90
Sha256 801906d53d973d68367754281a9aba78bbd0de99b35bfa34f63baafa49eb179a
Sha384 d39a4467ab1e863574282d72852f55a67d44f2094ddfbce8bad21698d2f81c7309b1911423c20107b00bceb89c787d30
Sha512 a9cf3b18bbab3da22dabeac6d87ecc8e47cb8a8966590bdb71c1453fd6740335a541d3c2123792da81b649fcfc8876d922fd2c5885468555d77226d59ebed6e2
SSDeep 6144:HP4l5PwaVZrmb9TPFoCH55tFK/KYAabdZgvkwUsAdPz:HP4l5PwWrmbXoCH9s/KqAk
TLSH 7E84186433F44604F2FFAFB5E8B045118A72F88BEA39D75E0AC9449E0D71B50AE50B67
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Phantom_794e63c0ddbf.exe
Full Name
Phantom_794e63c0ddbf.exe
EntryPoint
System.Void PhantomStealer4.Programs::<Main>(System.String[])
Scope Name
Phantom_794e63c0ddbf.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Phantom_794e63c0ddbf
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
4010
Main Method
System.Void PhantomStealer4.Programs::<Main>(System.String[])
Main IL Instruction Count
7
Main IL
ldarg.0 <null>
call System.Threading.Tasks.Task PhantomStealer4.Programs::Main(System.String[])
callvirt System.Runtime.CompilerServices.TaskAwaiter System.Threading.Tasks.Task::GetAwaiter()
stloc.0 <null>
ldloca.s V_0
call System.Void System.Runtime.CompilerServices.TaskAwaiter::GetResult()
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙