Suspicious
Suspect

dd335229ce9cfabb228576f4eb90bbba

Share on LinkedIn
Print
PE Executable
MD5: dd335229ce9cfabb228576f4eb90bbba
Size: 764.42 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 dd335229ce9cfabb228576f4eb90bbba
Sha1 f9b20507daca9ab8c4f4006fcbae77251ab97deb
Sha256 0593b9a2c09ed235e48ceb2b86b64feb9de1eaa58893af1dce532da959f27c69
Sha384 617f38eb470e086a407ce8741cdcd7d4595d733552b8f59eb68bbe9a9fdca95f1b3a670e7d5e7930b11a2fd123142aa9
Sha512 43477a8a0937834b1ac4aa249f59f64f17d9b11afbca0be89303fa787b0f66ebc26e3f2ae9aaa4a34c1bd979af2410f8997bc21f2e1f2c9a09b3ee1bc534e514
SSDeep 12288:r9C924e4koL3MpKy3OzQdyBxjbCFroh3l+C6E0+:r9CQ4FMKy3OzQdyXbCFQl+CN0+
TLSH 00F47C24B3F409A4F1FF9B75D4B18522CA71B84B9A34CB8F159885AE0E337919D34B63
PeID
Microsoft Visual C++ v6.0 DLL
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
.Net Resources
PhantomStealer4.Resources.DumpBrowserSecrets.exe
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.fptable
.rsrc
.reloc
Resources
DLLFILE
ID:0065
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.reloc
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe>pe:exe>pe:rsrc>pe:dll
Shape pe:exe>pe:exe>pe:rsrc>pe:dll
4 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Phantom_c88553b9a36b.exe
Full Name
Phantom_c88553b9a36b.exe
EntryPoint
System.Void PhantomStealer4.Programs::<Main>()
Scope Name
Phantom_c88553b9a36b.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Phantom_c88553b9a36b
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
3847
Main Method
System.Void PhantomStealer4.Programs::<Main>()
Main IL Instruction Count
6
Main IL
call System.Threading.Tasks.Task PhantomStealer4.Programs::Main()
callvirt System.Runtime.CompilerServices.TaskAwaiter System.Threading.Tasks.Task::GetAwaiter()
stloc.0 <null>
ldloca.s V_0
call System.Void System.Runtime.CompilerServices.TaskAwaiter::GetResult()
ret <null>
An error has occurred. This application may no longer respond until reloaded. Reload 🗙