Suspicious
Suspect

e97475cc33df65c170676a4ca5dbea83

PE Executable
MD5: e97475cc33df65c170676a4ca5dbea83
Size: 417.28 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 e97475cc33df65c170676a4ca5dbea83
Sha1 862b3c603089a46cd40d22bce0db05fd2840fc8d
Sha256 6a341b3e9c265e672ac0bb8c72a7fb2b72f8872a1a12b5d1fa48b868ca43f8b4
Sha384 fee31736e697d23003e981d296bd7b2090d4b34115297e8540d46031625b3290171d90c1a2ee4c7b238a5f64dc613f1d
Sha512 04b0ad0ab66f65e4584dcf0bc9af84c4bee2130be61afa6b43250db3c91f1c8101207403360ad63e33ce13517a54a5eb61a6f9890de2aa4660ac784b035a58dd
SSDeep 6144:0TJdf7/yGi5aezpi86ehn0NbAbSOklUVAdcz:0TJdzaGnep6in3k
TLSH 2994E52973F88A09F2FF6FB5A8B049118A32F84B9D35D74E1988409D0DB2B91DD50B77
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
Phantom_aa73e201233d.exe
Full Name
Phantom_aa73e201233d.exe
EntryPoint
System.Void PhantomStealer4.Programs::<Main>(System.String[])
Scope Name
Phantom_aa73e201233d.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
Phantom_aa73e201233d
Assembly Version
0.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
<null>
Total Strings
4245
Main Method
System.Void PhantomStealer4.Programs::<Main>(System.String[])
Main IL Instruction Count
7
Main IL
ldarg.0 <null>
call System.Threading.Tasks.Task PhantomStealer4.Programs::Main(System.String[])
callvirt System.Runtime.CompilerServices.TaskAwaiter System.Threading.Tasks.Task::GetAwaiter()
stloc.0 <null>
ldloca.s V_0
call System.Void System.Runtime.CompilerServices.TaskAwaiter::GetResult()
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.reloc
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙