🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4284d6e82e7835c97733e215acccacde7d71abfc0c8d25d8a316669782443742. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PhantomStealer


Vendor detections: 16


Intelligence 16 IOCs YARA 5 File information Comments

SHA256 hash: 4284d6e82e7835c97733e215acccacde7d71abfc0c8d25d8a316669782443742
SHA3-384 hash: 3b75021d0ff20f3bbd1ebd2824d56c1eec51fb3f107620b4db5496ef816ba98c209c1bda13c4de6ea9183cc7ad04b5b7
SHA1 hash: ce2575c6f0b05e95580c3ad231cce919b0ab178d
MD5 hash: 19542860d1dd91dc0abf361d0a519c6b
humanhash: gee-october-coffee-winter
File name:PO 9379374863 -R0-S - 030293764.exe
Download: download sample
Signature PhantomStealer
File size:1'703'424 bytes
First seen:2026-05-20 11:19:57 UTC
Last seen:2026-05-25 06:38:18 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'234 x AgentTesla, 20'488 x Formbook, 12'372 x SnakeKeylogger)
ssdeep 24576:u0aCzZ5cvcLfMfpGYuyUm9HglvHAoBPH3B2fwXFNQo6Xh+ow7varIedoeTK:JaCV5ZLUfk/m9cHXB8KNWx+N8IET
Threatray 482 similar samples on MalwareBazaar
TLSH T1747501D43A2AE71ACD924A349A34DEB11AF41DACF401BAE38BDD7F5B74AD1105D0CB81
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
dhash icon d3c825a327a48882 (7 x Formbook, 7 x PhantomStealer, 6 x AgentTesla)
Reporter adrian__luca
Tags:exe PhantomStealer

Intelligence


File Origin
# of uploads :
2
# of downloads :
137
Origin country :
HU HU
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
4284d6e82e7835c97733e215acccacde7d71abfc0c8d25d8a316669782443742
Verdict:
Malicious activity
Analysis date:
2026-05-06 11:04:46 UTC
Tags:
stealer phantom evasion

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.1%
Tags:
keylog micro msil
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Sending a custom TCP request
Creating a process with a hidden window
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Creating a file in the %temp% directory
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Сreating synchronization primitives
Using the Windows Management Instrumentation requests
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Adding an exclusion to Microsoft Defender
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 packed phishing vbnet
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-05-06T03:40:00Z UTC
Last seen:
2026-05-18T00:56:00Z UTC
Hits:
~100
Detections:
PDM:Trojan.Win32.Generic HEUR:Trojan.MSIL.Injector.gen Trojan.Win32.Agent.sb Trojan.MSIL.Inject.sb HEUR:Trojan-PSW.MSIL.Agensla.gen
Result
Threat name:
KeyLogger, Phantom stealer
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
Adds a directory exclusion to Windows Defender
AI detected malicious Powershell script
Allocates memory in foreign processes
Antivirus / Scanner detection for submitted sample
Browser instances using unsafe startup parameters
Bypasses PowerShell execution policy
Creates a thread in another existing process (thread injection)
Creates an autostart registry key pointing to binary in C:\Windows
Creates autostart registry keys with suspicious values (likely registry only malware)
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Injects a PE file into a foreign processes
Installs a global keyboard hook
Loading BitLocker PowerShell Module
Monitors registry run keys for changes
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Sigma detected: New RUN Key Pointing to Suspicious Folder
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Script Execution From Temp Folder
Suricata IDS alerts for network traffic
Suspicious powershell command line found
Switches to a custom stack to bypass stack traces
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses the Windows Restart Manager Abuse for Browser Credential File unlocking
Writes to foreign memory regions
Yara detected AntiVM3
Yara detected Costura Assembly Loader
Yara detected Keylogger Generic
Yara detected Phantom stealer
Yara detected UAC Bypass using CMSTP
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1909295 Sample: CdnXoTjLxC Startdate: 06/05/2026 Architecture: WINDOWS Score: 100 95 Suricata IDS alerts for network traffic 2->95 97 Found malware configuration 2->97 99 Antivirus / Scanner detection for submitted sample 2->99 101 14 other signatures 2->101 8 CdnXoTjLxC.exe 1 7 2->8         started        12 firefox.exe 2->12         started        14 powershell.exe 2->14         started        16 2 other processes 2->16 process3 dnsIp4 67 C:\Users\user\AppData\...\KhbsvdOWlA.exe, PE32 8->67 dropped 69 C:\Users\...\KhbsvdOWlA.exe:Zone.Identifier, ASCII 8->69 dropped 71 C:\Users\user\AppData\...\fgdmd01udq5.ps1, ASCII 8->71 dropped 73 C:\Users\user\AppData\...\CdnXoTjLxC.exe.log, ASCII 8->73 dropped 121 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 8->121 123 Found many strings related to Crypto-Wallets (likely being stolen) 8->123 125 Creates autostart registry keys with suspicious values (likely registry only malware) 8->125 127 5 other signatures 8->127 19 CdnXoTjLxC.exe 25 186 8->19         started        24 powershell.exe 23 8->24         started        26 firefox.exe 12->26         started        28 KhbsvdOWlA.exe 14->28         started        30 conhost.exe 14->30         started        75 192.168.2.4, 443, 49619, 49708 unknown unknown 16->75 77 192.168.2.5 unknown unknown 16->77 79 239.255.255.250 unknown Reserved 16->79 32 KhbsvdOWlA.exe 16->32         started        34 msedge.exe 16->34         started        36 setup.exe 16->36         started        38 6 other processes 16->38 file5 signatures6 process7 dnsIp8 89 2 other IPs or domains 19->89 61 C:\Users\user\AppData\...\Log_Summaries.txt, Unicode 19->61 dropped 103 Tries to steal Mail credentials (via file / registry access) 19->103 105 Tries to harvest and steal browser information (history, passwords, etc) 19->105 107 Writes to foreign memory regions 19->107 115 4 other signatures 19->115 40 msedge.exe 19->40         started        43 chrome.exe 19->43         started        53 4 other processes 19->53 109 Loading BitLocker PowerShell Module 24->109 45 conhost.exe 24->45         started        47 WmiPrvSE.exe 24->47         started        81 151.101.1.91 FASTLYUS United States 26->81 83 34.107.221.82 GOOGLEUS United States 26->83 91 6 other IPs or domains 26->91 63 C:\Users\user\AppData\...\gmpopenh264.dll.tmp, PE32+ 26->63 dropped 65 C:\Users\user\...\gmpopenh264.dll (copy), PE32+ 26->65 dropped 55 2 other processes 26->55 111 Multi AV Scanner detection for dropped file 28->111 113 Injects a PE file into a foreign processes 28->113 49 KhbsvdOWlA.exe 28->49         started        57 2 other processes 32->57 85 sb.scorecardresearch.com 18.65.238.16, 443, 49748 MIT-GATEWAYSUS United States 34->85 87 13.107.213.70 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 34->87 93 37 other IPs or domains 34->93 51 setup.exe 36->51         started        file9 signatures10 process11 signatures12 117 Monitors registry run keys for changes 40->117 119 Installs a global keyboard hook 40->119 59 msedge.exe 40->59         started        process13
Gathering data
Threat name:
ByteCode-MSIL.Trojan.XWorm
Status:
Malicious
First seen:
2026-05-06 08:09:19 UTC
File Type:
PE (.Net Exe)
Extracted files:
18
AV detection:
19 of 24 (79.17%)
Threat level:
  5/5
Result
Malware family:
phantom_stealer
Score:
  10/10
Tags:
family:phantom_stealer collection discovery execution persistence spyware stealer
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
outlook_office_path
outlook_win_path
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Time Discovery
Drops file in Program Files directory
Drops file in Windows directory
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Adds Run key to start application
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Reads user/profile data of web browsers
Command and Scripting Interpreter: PowerShell
Detects PhantomStealer written in C#
Family: PhantomStealer
Unpacked files
SH256 hash:
4284d6e82e7835c97733e215acccacde7d71abfc0c8d25d8a316669782443742
MD5 hash:
19542860d1dd91dc0abf361d0a519c6b
SHA1 hash:
ce2575c6f0b05e95580c3ad231cce919b0ab178d
SH256 hash:
1c31b58acd5a98622560fae51efe8a16887534314a3363ffa8f737ad3d1b9e16
MD5 hash:
6dd4ea47294a267bef3ede84f92c2e24
SHA1 hash:
6c9f78d7a74f13e8507bacb94d727572d76574e5
SH256 hash:
d3a79c0061518b77a3dc73fc7e3932a1c73b9cf547a99a37d42ca497f4781f0d
MD5 hash:
10d7ba918b93f4cac164e5ea9d7ba14a
SHA1 hash:
a4d5da62942ab9b0f65b4fba35bdaedd2427cfd8
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

PhantomStealer

Executable exe 4284d6e82e7835c97733e215acccacde7d71abfc0c8d25d8a316669782443742

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments