Suspicious
Suspect

4605c0b216ee284bc683aa3cae99cf65

PE Executable
MD5: 4605c0b216ee284bc683aa3cae99cf65
Size: 399.36 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 4605c0b216ee284bc683aa3cae99cf65
Sha1 9e922e8074f3f3193261ef55d75fa6e412cf28b3
Sha256 2b07d9485d644e740ebcf55a5f2a9768b98cb97e3238977e16ed3c77a55ca2ba
Sha384 7c52365f7f1a70bc29426627a37089d162592a39ff9148bd6a1c79c13e97d01c4824d2ebe7b937b40ea2ffd29a7257bd
Sha512 f7ba79312b510d103d54536fa464d264780e093ef52781722c15bc45ba8e99ecdff0261162cad1a6fb2224152a10b649ce9af28663635f71cac411bc5d1eba38
SSDeep 6144:IP4yOcYaCgSXJPudvCSlmcZAabGZgvkwUzzAdPz:IP4yOc3CgSJudvZ+Akz
TLSH BB8407A433F44615F2FF6F75E8B045118A32F88BEA39D75E0AC8449E0E71B50AE50B67
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Phantom_635b81c8a617.exe
Full Name
Phantom_635b81c8a617.exe
EntryPoint
System.Void PhantomStealer4.Programs::<Main>(System.String[])
Scope Name
Phantom_635b81c8a617.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Phantom_635b81c8a617
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
4010
Main Method
System.Void PhantomStealer4.Programs::<Main>(System.String[])
Main IL Instruction Count
7
Main IL
ldarg.0 <null>
call System.Threading.Tasks.Task PhantomStealer4.Programs::Main(System.String[])
callvirt System.Runtime.CompilerServices.TaskAwaiter System.Threading.Tasks.Task::GetAwaiter()
stloc.0 <null>
ldloca.s V_0
call System.Void System.Runtime.CompilerServices.TaskAwaiter::GetResult()
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙