Suspicious
Suspect

69ca07d354c419e152a858cf3a98ee54

PE Executable
MD5: 69ca07d354c419e152a858cf3a98ee54
Size: 417.28 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 69ca07d354c419e152a858cf3a98ee54
Sha1 ad30231e8b41fb61757b361e333dd6f2b32a17cc
Sha256 f46ce77474c6e0dd72f59b4d8b784b85dab6d9765bc3705f466491c74cacebe1
Sha384 199b0818d3984b44c09505266ec276be7e9139f7e290e68a66b892ebdcf441c9fe876753859b4f1bedd74827d384d3de
Sha512 ebc5104ce47b8eaf5b949e2950d47e2f08666395b24bc8a31505830383c1042e512d1f175d181a1e72ba947f3f0d291dd97847a203fa88c67b13169c367e2300
SSDeep 6144:ZTJ9f7/yGi5aeXZMUDg440NbnbSOklUHAdcz:ZTJ9zaGnCvDhN3k
TLSH 7794E52873F88A09F2FF6FB5A8B049118A32F84B9D35D74E1988509D0DB2B91DD50B77
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Phantom_ab43ba850b7b.exe
Full Name
Phantom_ab43ba850b7b.exe
EntryPoint
System.Void PhantomStealer4.Programs::<Main>(System.String[])
Scope Name
Phantom_ab43ba850b7b.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Phantom_ab43ba850b7b
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
4245
Main Method
System.Void PhantomStealer4.Programs::<Main>(System.String[])
Main IL Instruction Count
7
Main IL
ldarg.0 <null>
call System.Threading.Tasks.Task PhantomStealer4.Programs::Main(System.String[])
callvirt System.Runtime.CompilerServices.TaskAwaiter System.Threading.Tasks.Task::GetAwaiter()
stloc.0 <null>
ldloca.s V_0
call System.Void System.Runtime.CompilerServices.TaskAwaiter::GetResult()
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙