MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0fa1dc1bdf2d7ad71a1d2ba696f6906186f3a3d7e808db6565354be50c22f004. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PhantomStealer


Vendor detections: 14


Intelligence 14 IOCs YARA 1 File information Comments

SHA256 hash: 0fa1dc1bdf2d7ad71a1d2ba696f6906186f3a3d7e808db6565354be50c22f004
SHA3-384 hash: 55b02e31fd3836706a8cc54af5bd451e8490ae22c4ce4e4c2df177108ef66282b48f40e2cbb55a79e92f4101f29c09ab
SHA1 hash: f54bd6833cf55634faa90c131c90783294f842d3
MD5 hash: a7d2e1d0c7420a0c1fb78d6b87976c11
humanhash: early-bulldog-hotel-ceiling
File name:Filigran197.js
Download: download sample
Signature PhantomStealer
File size:619'850 bytes
First seen:2026-06-17 15:43:58 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 6144:LhUCrhUCzLJhUCehUC/hUC7hEh4hUjhUCxhUClhUEhghUQhUCO4hUC1hUCkhUClC:bi
TLSH T17FD45D10DE34026A4F8B17B9FCE54B56CABC8618562680F5FADE074D61024FCE3BF669
Magika javascript
Reporter threatcat_ch
Tags:js PhantomStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
164
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
81.4%
Tags:
obfuscated infosteal stration spawn
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
cmd lolbin repaired
Verdict:
Malicious
File Type:
text
First seen:
2026-06-17T09:22:00Z UTC
Last seen:
2026-06-19T13:38:00Z UTC
Hits:
~1000
Detections:
HEUR:Trojan.Multi.Powecod.gen Trojan.PowerShell.Strion.sb PDM:Trojan.Win32.Generic HEUR:Trojan.Script.SAgent.gen HEUR:Trojan.Script.Generic Trojan.VBS.SAgent.sb
Result
Threat name:
GuLoader
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Browser instances using unsafe startup parameters
Creates a thread in another existing process (thread injection)
Found suspicious powershell code related to unpacking or dynamic code loading
Injects a PE file into a foreign processes
Injects code into the Windows Explorer (explorer.exe)
JavaScript file contains suspicious strings
JavaScript source code contains functionality to generate code involving a shell, file or stream
JScript performs obfuscated calls to suspicious functions
Malicious sample detected (through community Yara rule)
Monitors registry run keys for changes
Multi AV Scanner detection for submitted file
Obfuscated command line found
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious powershell command line found
Switches to a custom stack to bypass stack traces
Unusual module load detection (module proxying)
Uses the Telegram API (likely for C&C communication)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
WScript reads language and country specific registry keys (likely country aware script)
Yara detected Costura Assembly Loader
Yara detected GuLoader
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1929506 Sample: Filigran197.js Startdate: 17/06/2026 Architecture: WINDOWS Score: 100 89 api.telegram.org 2->89 91 icanhazip.com 2->91 109 Suricata IDS alerts for network traffic 2->109 111 Malicious sample detected (through community Yara rule) 2->111 113 Multi AV Scanner detection for submitted file 2->113 117 8 other signatures 2->117 10 powershell.exe 18 2->10         started        13 wscript.exe 1 3 2->13         started        15 explorer.exe 2->15         started        17 2 other processes 2->17 signatures3 115 Uses the Telegram API (likely for C&C communication) 89->115 process4 signatures5 135 Obfuscated command line found 10->135 137 Writes to foreign memory regions 10->137 139 Found suspicious powershell code related to unpacking or dynamic code loading 10->139 141 Switches to a custom stack to bypass stack traces 10->141 19 backgroundTaskHost.exe 2 13 10->19         started        22 backgroundTaskHost.exe 10->22         started        24 conhost.exe 10->24         started        143 JScript performs obfuscated calls to suspicious functions 13->143 145 Injects code into the Windows Explorer (explorer.exe) 13->145 147 Windows Scripting host queries suspicious COM object (likely to drop second stage) 13->147 149 WScript reads language and country specific registry keys (likely country aware script) 13->149 26 explorer.exe 1 13->26         started        28 cmd.exe 1 15->28         started        30 powershell.exe 17->30         started        32 powershell.exe 17->32         started        34 conhost.exe 17->34         started        36 conhost.exe 17->36         started        process6 signatures7 119 Writes to foreign memory regions 19->119 121 Creates a thread in another existing process (thread injection) 19->121 123 Injects a PE file into a foreign processes 19->123 38 msedge.exe 19->38         started        42 firefox.exe 2 19->42         started        44 cmd.exe 1 19->44         started        55 6 other processes 19->55 125 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 22->125 127 Browser instances using unsafe startup parameters 22->127 129 Unusual module load detection (module proxying) 22->129 131 Switches to a custom stack to bypass stack traces 22->131 133 Obfuscated command line found 28->133 46 powershell.exe 14 20 28->46         started        49 conhost.exe 1 28->49         started        51 backgroundTaskHost.exe 30->51         started        53 backgroundTaskHost.exe 30->53         started        57 2 other processes 32->57 process8 dnsIp9 93 192.168.2.4, 138, 443, 49172 unknown unknown 38->93 95 239.255.255.250 unknown ZZ 38->95 83 C:\...\the-real-index~RF497e7.TMP (copy), COM 38->83 dropped 85 C:\Users\user\...\the-real-index (copy), COM 38->85 dropped 87 C:\Users\user\AppData\Local\...\temp-index, COM 38->87 dropped 59 msedge.exe 38->59         started        62 setup.exe 38->62         started        64 msedge.exe 38->64         started        77 3 other processes 38->77 66 firefox.exe 3 41 42->66         started        69 conhost.exe 44->69         started        71 reg.exe 1 1 44->71         started        97 192.3.136.217, 49690, 49692, 49746 AS-COLOCROSSING-HostPapaUS United States 46->97 151 Found suspicious powershell code related to unpacking or dynamic code loading 46->151 73 conhost.exe 46->73         started        153 Obfuscated command line found 49->153 75 backgroundTaskHost.exe 51->75         started        file10 signatures11 process12 dnsIp13 99 150.171.109.145, 443, 49742, 49743 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS South Africa 59->99 101 150.171.110.195, 443, 49725 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 59->101 105 27 other IPs or domains 59->105 79 setup.exe 62->79         started        103 127.0.0.1 unknown unknown 66->103 107 Monitors registry run keys for changes 66->107 81 firefox.exe 66->81         started        signatures14 process15
Gathering data
Threat name:
Script-JS.Trojan.Heuristic
Status:
Malicious
First seen:
2026-06-17 15:44:49 UTC
File Type:
Text
AV detection:
5 of 38 (13.16%)
Threat level:
  2/5
Result
Malware family:
phantom_stealer
Score:
  10/10
Tags:
family:phantom_stealer collection discovery execution persistence stealer
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
outlook_office_path
outlook_win_path
Command and Scripting Interpreter: JavaScript
Command and Scripting Interpreter: PowerShell
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Time Discovery
Drops file in Program Files directory
Drops file in Windows directory
Drops file in System32 directory
Suspicious use of NtCreateThreadExHideFromDebugger
Suspicious use of NtSetInformationThreadHideFromDebugger
Accesses Microsoft Outlook profiles
Adds Run key to start application
Looks up external IP address via web service
Checks computer location settings
Badlisted process makes network request
Detects PhantomStealer written in C#
Family: PhantomStealer
Malware Config
C2 Extraction:
https://api.telegram.org/bot8522027086:AAHvUXtSZ7mvLQo8hbezWGN9KPHpgv_6mKY/sendMessage?chat_id=7676646854
Malware family:
PhantomStealer
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

PhantomStealer

Java Script (JS) js 0fa1dc1bdf2d7ad71a1d2ba696f6906186f3a3d7e808db6565354be50c22f004

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments