Suspicious
Suspect

0d8c2d896f3a6bc8c9de054d0d9fe998

PE Executable
MD5: 0d8c2d896f3a6bc8c9de054d0d9fe998
Size: 764.42 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 0d8c2d896f3a6bc8c9de054d0d9fe998
Sha1 82e531868171dc4834ed68d547732b9c9586fa27
Sha256 68df7b6f9d19fa367adc824210afb8a8272deda7fe4e79657cb12723d20298ef
Sha384 d74979764cdca68979acde1c4005afa2cac6961c46c0f349ebdd291b9720fa5363745dbe49278ffd215f596a6e66b008
Sha512 fa8d3cb93a9da7a1d0f2e7e8552e0f824b57d48371d268ac7b305d9a9a94e09649f4fab02ea439fc195538904b0f2eae45faa1e2408db2509ec94792838e5d09
SSDeep 12288:p9CTvBAyx0Mpky3OzQdyBxjbCFroh3l+C6E0+:p9CrOMky3OzQdyXbCFQl+CN0+
TLSH 30F47C24B3F409A4F1FF9B75D4B18522CA71B84B9A34CB8F1598829E0E337919D74B63
PeID
Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
.Net Resources
PhantomStealer4.Resources.DumpBrowserSecrets.exe
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
DLLFILE
ID:0065
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.reloc
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:exe>pe:rsrc>pe:dll
Shape pe:exe>pe:exe>pe:rsrc>pe:dll
4 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Phantom_c709c4c8e788.exe
Full Name
Phantom_c709c4c8e788.exe
EntryPoint
System.Void PhantomStealer4.Programs::<Main>()
Scope Name
Phantom_c709c4c8e788.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Phantom_c709c4c8e788
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
3847
Main Method
System.Void PhantomStealer4.Programs::<Main>()
Main IL Instruction Count
6
Main IL
call System.Threading.Tasks.Task PhantomStealer4.Programs::Main()
callvirt System.Runtime.CompilerServices.TaskAwaiter System.Threading.Tasks.Task::GetAwaiter()
stloc.0 <null>
ldloca.s V_0
call System.Void System.Runtime.CompilerServices.TaskAwaiter::GetResult()
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
.Net Resources
PhantomStealer4.Resources.DumpBrowserSecrets.exe
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
DLLFILE
ID:0065
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.reloc
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙