Suspicious
Suspect

8075db3747de48b073caf66e04a8f7c8

PE Executable
MD5: 8075db3747de48b073caf66e04a8f7c8
Size: 29.7 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 8075db3747de48b073caf66e04a8f7c8
Sha1 7d3a91eb2fa14437dc3efbde248abda65691a4fa
Sha256 3ab441bc455c6259e23fad27e1bc5c311bb1daf8a5e6a394ae456e6a860da83c
Sha384 388a97868c865c5931240f319ec017905c8a001aecfbe1946955e4cd2aab507a7da676f90f3d5c29af81ff0ac02db4f7
Sha512 b18a75a252eea99148d93df6704ac6a2d2c044c76e916dcf6def11689baaba972bc123ce3ec678cbec27fe19d974e80bca3219947137da82e4644fd93706952e
SSDeep 768:6M5UQvACt07uYsxhs/10b4JkY5DeBTb1Kaxu87:6UvZYH90sJzi1b1Kao87
TLSH 41D2168977FC8219F2BF8F7999B5A0500770F46A2822E74E19CA509D0C73B509E94FB3
PeID
Microsoft Visual C++ DLLMicrosoft Visual C++ v6.0
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Name Value
Module Name
telegram stealer.dll
Full Name
telegram stealer.dll
EntryPoint
System.Void SystemUpdater.Program::<Main>(System.String[])
Scope Name
telegram stealer.dll
Scope Type
ModuleDef
Kind
Console
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
telegram stealer
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETCoreApp,Version=v10.0
Total Strings
193
Main Method
System.Void SystemUpdater.Program::<Main>(System.String[])
Main IL Instruction Count
7
Main IL
ldarg.0 <null>
call System.Threading.Tasks.Task SystemUpdater.Program::Main(System.String[])
callvirt System.Runtime.CompilerServices.TaskAwaiter System.Threading.Tasks.Task::GetAwaiter()
stloc.0 <null>
ldloca.s V_0
call System.Void System.Runtime.CompilerServices.TaskAwaiter::GetResult()
ret <null>
Info
PE Detect: PeReader OK (file layout)
Info
PDB Path: /home/fl1xx00/Desktop/telegram stealer/obj/Release/net10.0/win-x64/telegram stealer.pdb
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rsrc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙