MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 420eaeab7871c7c8f6dffaa6ad95ea564b44952b1edfec858d69b53fbda4ec89. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
PhantomStealer
Vendor detections: 14
| SHA256 hash: | 420eaeab7871c7c8f6dffaa6ad95ea564b44952b1edfec858d69b53fbda4ec89 |
|---|---|
| SHA3-384 hash: | a82f5af22cc6523d4dadb61c01d6b3daa80549083d09ad48f76326a8848d1af47eb5460299e2b3113ed5db0b30812bf9 |
| SHA1 hash: | 7adad0266e5301ff6caa2b774d271baf638e77f3 |
| MD5 hash: | 5dde11e44d06131109688e6375be6ba7 |
| humanhash: | freddie-washington-bluebird-batman |
| File name: | 420eaeab7871c7c8f6dffaa6ad95ea564b44952b1edfec858d69b53fbda4ec89 |
| Download: | download sample |
| Signature | PhantomStealer |
| File size: | 1'585'152 bytes |
| First seen: | 2026-06-08 08:49:09 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (49'066 x AgentTesla, 20'011 x Formbook, 12'352 x SnakeKeylogger) |
| ssdeep | 49152:ZZLyYulNFwjhCivtkazKSGUSv3Xhfjmo3FQ:nulIlfvtFeF/xf9FQ |
| Threatray | 270 similar samples on MalwareBazaar |
| TLSH | T14E751245225ADD02D1E60FB459A1E2F027745E88E936D2478FE6BCEBBC7A7406C093C7 |
| TrID | 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 6.6% (.EXE) Win64 Executable (generic) (6522/11/2) 4.5% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| Reporter | |
| Tags: | exe PhantomStealer |
Intelligence
File Origin
HUVendor Threat Intelligence
Details
Result
Behaviour
Result
Behaviour
Unpacked files
c5c29720693314c6492a45268a4852d5c6efb4698d928ac6f68c283ea7c9f785
5d23a0e4656f41bcb064307a614565b32cf6d04d6b38a910f24570907f29b436
db0864b36e22c383e8e59b8d2d4610276ab4bbd97d7b382bdb451fb7ed9a6540
420eaeab7871c7c8f6dffaa6ad95ea564b44952b1edfec858d69b53fbda4ec89
d6168fea1d549e10df9f33d41a6058573f32312eb67b1cc48756dca2558479ca
7c26003b25a03f34ac2ddd11324d2501506ef7fa694cac3ec9d63717d3071783
e7096f11b4ea7f7ba0bcafc509b6642942ab3f8ff46b93bfab2170a516c28425
863e5790dc76c8ef082144e1f7ed91e92cb72960172b56af593737c738cfc8f5
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | MoleBoxv20 |
|---|---|
| Author: | malware-lu |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.