🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2f1f3032cbdf2c854e3e9f135fa4dc417ea5b3f81a4d1af058142ed20f83962e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PhantomStealer


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 2f1f3032cbdf2c854e3e9f135fa4dc417ea5b3f81a4d1af058142ed20f83962e
SHA3-384 hash: dc961e199f37e9e183c24fe611fcea0f21c9da2a29d5ac4fc053b6fed46d1da2e641abcfaa056c8635c6d810a9960597
SHA1 hash: 2270ba5701f6a00a56a206ec14c1f6fbc63eecb8
MD5 hash: 26a1199087d38d15c26d4b34d7ab3c5a
humanhash: mobile-nevada-crazy-mars
File name:6RFQ000919.JS
Download: download sample
Signature PhantomStealer
File size:12'611'377 bytes
First seen:2026-09-09 09:11:44 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 393216:FUqpnQQs6BJvc0F9Hv0OeaUmY6X43gmJsLm:F5pnQQf9F9Hv0OeZmY6X4QgsC
TLSH T179C6F7891354E133B36157DC6235ED35A60A921716CADB1A727CD318BB3CE07A36CAE3
Magika txt
Reporter lowmal3
Tags:js PhantomStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
91
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
obfuscated repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-09-08T18:59:00Z UTC
Last seen:
2026-09-09T06:11:00Z UTC
Hits:
~1000
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Multi AV Scanner detection for submitted file
Sigma detected: WScript or CScript Dropper
Behaviour
Behavior Graph:
Gathering data
Result
Malware family:
phantom_stealer
Score:
  10/10
Tags:
family:phantom_stealer collection discovery execution spyware stealer
Behaviour
Checks processor information in registry
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
outlook_office_path
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Accesses Microsoft Outlook profiles
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Reads user/profile data of web browsers
Family: PhantomStealer
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments