Suspicious
Suspect

6a24eb3239d3dde1dceb58352b69f3f5

PE Executable
MD5: 6a24eb3239d3dde1dceb58352b69f3f5
Size: 422.4 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 6a24eb3239d3dde1dceb58352b69f3f5
Sha1 03ee984eff59d8d9d1a579642481c00948dfc1fa
Sha256 8f6f78a3e78c282fa75cc96b5ad6b2c5083ca05bdde8ebe8b4f32bce6f64adf4
Sha384 1e3e197a612a1b2c54d6492642198203849a8f3a9eb44f58ba9827de39b0ee9cdc4ec67e53fabf867ff708acc654ae46
Sha512 607115901663983b45402755e4e894bd257850b8a89982baa351f112af244140b22813a9117e27763e437964bb839c14e2a570e688cf154e48c5c8e8fbcf28db
SSDeep 6144:BTJAKXh0CBHGz0KXXUJKYOh0NbWbSOklUyS3Adcz:BTJAKXbHTacKBD3kZ
TLSH 8F94F62863F88A09F2FF6FB5A8B049118B32F84B9D39D74E1988509D0D72B91DD50B77
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Phantom_1dc5439b66a4.exe
Full Name
Phantom_1dc5439b66a4.exe
EntryPoint
System.Void PhantomStealer4.Programs::<Main>(System.String[])
Scope Name
Phantom_1dc5439b66a4.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Phantom_1dc5439b66a4
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
4257
Main Method
System.Void PhantomStealer4.Programs::<Main>(System.String[])
Main IL Instruction Count
7
Main IL
ldarg.0 <null>
call System.Threading.Tasks.Task PhantomStealer4.Programs::Main(System.String[])
callvirt System.Runtime.CompilerServices.TaskAwaiter System.Threading.Tasks.Task::GetAwaiter()
stloc.0 <null>
ldloca.s V_0
call System.Void System.Runtime.CompilerServices.TaskAwaiter::GetResult()
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙