MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b702cd9138799be52084b2ad29adcc10d5499eb5702183137dc0b7845f7acb9a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PhantomStealer


Vendor detections: 13


Intelligence 13 IOCs YARA 4 File information Comments

SHA256 hash: b702cd9138799be52084b2ad29adcc10d5499eb5702183137dc0b7845f7acb9a
SHA3-384 hash: fb0097ee461966702b77df5aac9602bd1080daa35b095a900761d6aeec9486c074ef69bf284ba565585db1db7054d907
SHA1 hash: fe046bde16c5dd6e93e3b9055f3df9bfb4cf74a7
MD5 hash: ac79676bd3711405b5a2a29d13755120
humanhash: summer-twenty-lamp-wyoming
File name:b702cd9138799be52084b2ad29adcc10d5499eb5702183137dc0b7845f7acb9a
Download: download sample
Signature PhantomStealer
File size:1'593'344 bytes
First seen:2026-08-10 13:30:18 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'190 x AgentTesla, 20'337 x Formbook, 12'364 x SnakeKeylogger)
ssdeep 24576:uqGRvQVLrD/LvCqO41KUuMHcooEayNR07FSwG7EydYJ8QQUG4sENIUm:uhRK/LaqOBrMHczE10Alu8LUG4s8m
TLSH T11A7512C43729A705DEB86A349135EEB813B62E28B420F9E76EDD3B97756C3015D18F02
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter adrian__luca
Tags:exe PhantomStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
HU HU
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Creating a process with a hidden window
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Using the Windows Management Instrumentation requests
Creating a file in the %temp% directory
Creating a process from a recently created file
Reading critical registry keys
Deleting a recently created file
Launching a process
Loading a suspicious library
Stealing user critical data
Unauthorized injection to a recently created process by asynchronous procedure call
Adding an exclusion to Microsoft Defender
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
blustealer krypt packed
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-06-30T04:55:00Z UTC
Last seen:
2026-08-10T01:43:00Z UTC
Hits:
~1000
Gathering data
Threat name:
Win32.Backdoor.FormBook
Status:
Malicious
First seen:
2026-06-30 10:49:43 UTC
File Type:
PE (.Net Exe)
Extracted files:
7
AV detection:
26 of 36 (72.22%)
Threat level:
  5/5
Result
Malware family:
phantom_stealer
Score:
  10/10
Tags:
family:phantom_stealer collection credential_access discovery execution spyware stealer
Behaviour
Checks processor information in registry
Enumerates system info in registry
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
outlook_office_path
Browser Information Discovery
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Time Discovery
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Command and Scripting Interpreter: PowerShell
Uses browser remote debugging
Family: PhantomStealer
Unpacked files
SH256 hash:
b702cd9138799be52084b2ad29adcc10d5499eb5702183137dc0b7845f7acb9a
MD5 hash:
ac79676bd3711405b5a2a29d13755120
SHA1 hash:
fe046bde16c5dd6e93e3b9055f3df9bfb4cf74a7
SH256 hash:
c934a2db58a1a64ee245a7627843508c6c517fcb06ea6855d26a72b41ae6753b
MD5 hash:
0e51138ef195ac755f052babb761a1e7
SHA1 hash:
3c7bbeabc56110d3463e6002cd0ff5c9a168d64b
SH256 hash:
b0935270bc8ed6d31c5352c49a8f5d7cbe62457133fe1cf7effeeeb1440e9ce0
MD5 hash:
f8c81aac564cf5834e602553a19c17a0
SHA1 hash:
bee29ea3fe90c45bab11b2bf941fbbcbc6acbbf9
SH256 hash:
26d85383838c6cd5af824f133eb5f608d70f54866aad8d4a6e313877589b4053
MD5 hash:
59c5210cea105567f210fd438a45b2c7
SHA1 hash:
076873d622151a38c7c1f5d1c7dc80036434c4f0
SH256 hash:
53efb491a5c48fc7f7de4e00a3bd1e4f76be85182424a5fc89ca8e7f68e4ba66
MD5 hash:
a6f61e1ca598be03a97258ae9f22873f
SHA1 hash:
85befc03f55eeccb434b28634879fba3c1b3535c
SH256 hash:
124ca72d44f94fba05f88e3e3b69c098f4e87682c0baec1deda3acb71bfd09da
MD5 hash:
271360416282d78b990bd3a539960fbb
SHA1 hash:
d4182e352b2d62118d8152701833ed99843ee229
Detections:
triage_net_infostealer_wsh triage_vidar_infostealer
Malware family:
PhantomStealer
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments