🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3b54c796eef85bde16c8f7f4f9d00946358f919084f4652239adc894fef09cd4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PhantomStealer


Vendor detections: 11


Intelligence 11 IOCs YARA 1 File information Comments

SHA256 hash: 3b54c796eef85bde16c8f7f4f9d00946358f919084f4652239adc894fef09cd4
SHA3-384 hash: 978e3c15c281677d1a160b175b8e141db8bedde899773d296eafd9b5049b5d9740ca46238eaee6318bfdb7036ca5dbb6
SHA1 hash: e01c152cc6ac47f649eaad239217fe78e066f076
MD5 hash: d7052ed3e3800840f721258e37300972
humanhash: pasta-robin-mirror-missouri
File name:TransferCopy.vbs
Download: download sample
Signature PhantomStealer
File size:2'776'591 bytes
First seen:2026-04-20 15:09:19 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/csv
ssdeep 192:c0d0d0d0d0d0d0d0d0d0d0d0d0d0d0d0d0d0d0d0d0d0d0d0d0d0d0d0d0d0d0d0:Yg0aCcuiG
Threatray 83 similar samples on MalwareBazaar
TLSH T1A1D52D10D63CE3C0143B54E6D80D2EADD4A293678DB09751AB2DA6CCD0B6C62F5B5ECB
Magika txt
Reporter abuse_ch
Tags:PhantomStealer vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
File Type:
text.utf8
First seen:
2026-04-20T03:14:00Z UTC
Last seen:
2026-04-20T04:12:00Z UTC
Hits:
~10
Detections:
Trojan.VBS.SAgent.sb Trojan.JS.SAgent.sb HEUR:Trojan.Script.Generic HEUR:Trojan-Downloader.Script.Generic
Result
Threat name:
KeyLogger, Phantom stealer, Strela Steal
Detection:
malicious
Classification:
spre.troj.spyw.expl.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Antivirus detection for URL or domain
Browser instances using unsafe startup parameters
Bypasses PowerShell execution policy
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Creates a thread in another existing process (thread injection)
Creates processes via WMI
Detected large data written to user environment variables, potentially indicating payload staging for fileless execution
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Injects a PE file into a foreign processes
Installs a global keyboard hook
Malicious sample detected (through community Yara rule)
Monitors registry run keys for changes
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Sigma detected: Capture Wi-Fi password
Sigma detected: MSBuild connects to smtp port
Sigma detected: Rare Remote Thread Creation By Uncommon Source Image
Sigma detected: Silenttrinity Stager Msbuild Activity
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Switches to a custom stack to bypass stack traces
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal WLAN passwords
Tries to steal Mail credentials (via file / registry access)
Uses netsh to modify the Windows network and firewall settings
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Yara detected AntiVM3
Yara detected Costura Assembly Loader
Yara detected Keylogger Generic
Yara detected Phantom stealer
Yara detected Strela Stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1901277 Sample: TransferCopy.vbs Startdate: 20/04/2026 Architecture: WINDOWS Score: 100 84 shed.dual-low.part-0012.t-0009.t-msedge.net 2->84 86 shed.dual-low.part-0010.t-0009.t-msedge.net 2->86 88 13 other IPs or domains 2->88 104 Found malware configuration 2->104 106 Malicious sample detected (through community Yara rule) 2->106 108 Antivirus detection for URL or domain 2->108 110 11 other signatures 2->110 11 wscript.exe 1 2->11         started        14 MSBuild.exe 2 2->14         started        16 svchost.exe 1 1 2->16         started        19 MSBuild.exe 2->19         started        signatures3 process4 dnsIp5 124 Suspicious powershell command line found 11->124 126 Wscript starts Powershell (via cmd or directly) 11->126 128 Bypasses PowerShell execution policy 11->128 130 4 other signatures 11->130 21 powershell.exe 14 16 11->21         started        25 conhost.exe 14->25         started        74 127.0.0.1 unknown unknown 16->74 27 conhost.exe 19->27         started        signatures6 process7 dnsIp8 90 phantom22.secure-efficient2.su 45.156.23.38, 443, 49692 CLOUDBACKBONERU Russian Federation 21->90 112 Found many strings related to Crypto-Wallets (likely being stolen) 21->112 114 Writes to foreign memory regions 21->114 116 Injects a PE file into a foreign processes 21->116 118 Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent) 21->118 29 MSBuild.exe 16 17 21->29         started        34 MSBuild.exe 21->34         started        36 conhost.exe 21->36         started        signatures9 process10 dnsIp11 92 mail.privateemail.com 198.54.122.135, 49775, 587 NAMECHEAP-NETUS United States 29->92 94 icanhazip.com 104.16.185.241, 49774, 80 CLOUDFLARENETUS United States 29->94 72 C:\Users\user\AppData\Roaming\MSBuild.exe, PE32 29->72 dropped 132 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 29->132 134 Tries to steal Mail credentials (via file / registry access) 29->134 136 Tries to harvest and steal browser information (history, passwords, etc) 29->136 146 5 other signatures 29->146 38 firefox.exe 2 29->38         started        40 cmd.exe 29->40         started        43 cmd.exe 29->43         started        45 11 other processes 29->45 138 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 34->138 140 Tries to harvest and steal WLAN passwords 34->140 142 Browser instances using unsafe startup parameters 34->142 144 Switches to a custom stack to bypass stack traces 34->144 file12 signatures13 process14 dnsIp15 48 firefox.exe 3 43 38->48         started        120 Uses netsh to modify the Windows network and firewall settings 40->120 122 Tries to harvest and steal WLAN passwords 40->122 52 conhost.exe 40->52         started        54 chcp.com 40->54         started        56 netsh.exe 40->56         started        66 4 other processes 43->66 96 192.168.2.8, 138, 443, 49673 unknown unknown 45->96 98 239.255.255.250 unknown Reserved 45->98 58 msedge.exe 45->58         started        60 setup.exe 45->60         started        62 msedge.exe 45->62         started        64 msedge.exe 45->64         started        signatures16 process17 dnsIp18 76 mozilla.map.fastly.net 151.101.129.91, 443, 49708 FASTLYUS United States 48->76 100 Monitors registry run keys for changes 48->100 102 Installs a global keyboard hook 48->102 68 firefox.exe 48->68         started        78 a1666.dscr.akamai.net 23.62.47.164, 443, 49716, 49717 TelefonicadelPeruSAAPE United States 58->78 80 sb.scorecardresearch.com 18.173.219.111, 443, 49733 MIT-GATEWAYSUS United States 58->80 82 37 other IPs or domains 58->82 70 setup.exe 60->70         started        signatures19 process20
Gathering data
Threat name:
Win32.Trojan.Yomal
Status:
Malicious
First seen:
2026-04-20 13:02:23 UTC
File Type:
Binary
AV detection:
7 of 38 (18.42%)
Threat level:
  5/5
Result
Malware family:
phantom_stealer
Score:
  10/10
Tags:
family:phantom_stealer collection discovery execution persistence privilege_escalation stealer
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
outlook_office_path
outlook_win_path
Event Triggered Execution: Netsh Helper DLL
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Wi-Fi Discovery
System Time Discovery
Drops file in Program Files directory
Drops file in Windows directory
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Adds Run key to start application
Looks up external IP address via web service
Executes dropped EXE
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Detects PhantomStealer written in C#
Family: PhantomStealer
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_tiny_vbs
Author:daniyyell
Description:Detects tiny VBS delivery technique

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments