🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dbb474f236caeda92d5b893ed1d9f9e80858529754756a9ca1d1dc5597421efa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PhantomStealer


Vendor detections: 11


Intelligence 11 IOCs YARA 2 File information Comments

SHA256 hash: dbb474f236caeda92d5b893ed1d9f9e80858529754756a9ca1d1dc5597421efa
SHA3-384 hash: fd2fd84121e6aa527da331616c41281d82c7aa1ade07d6ef9c9d8c54a6e87a06dccfcaff2c4d6d217015c6cc8725fbfd
SHA1 hash: 40d4c721cae141c3f6e52d98c6201c2c4fd1c3fa
MD5 hash: 53c57852dedfcd293ce819e21bf85830
humanhash: fruit-table-fanta-six
File name:Sip. DISAGRUP_FİYAT VE TERMİN TALEBİ.bat
Download: download sample
Signature PhantomStealer
File size:13'671 bytes
First seen:2026-04-13 12:56:00 UTC
Last seen:2026-04-13 12:56:05 UTC
File type:Batch (bat) bat
MIME type:text/x-msdos-batch
ssdeep 384:wsj6PgkAAB7MLv8yp156BJ3KhwVKKRq0XX5ixE/nGgNScXecBu:f3gwLf/8gwsKX+ELxBBu
TLSH T133522E7DC4D4FCC4879B22D178EAFBC2129E87137E5A5B6CF9C800950B94364EBB9188
Magika batch
Reporter abuse_ch
Tags:bat geo PhantomStealer TUR

Intelligence


File Origin
# of uploads :
2
# of downloads :
63
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
Sip.DISAGRUP_FYATVETERMNTALEB.z
Verdict:
Malicious activity
Analysis date:
2026-04-13 12:25:23 UTC
Tags:
arch-exec susp-powershell payload loader reverseloader api-base64 stealer phantom evasion

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
93.3%
Tags:
malware
Result
Verdict:
Clean
Maliciousness:

Behaviour
Launching a process
Creating a process with a hidden window
Creating a file
Сreating synchronization primitives
DNS request
Connection attempt
Sending a custom TCP request
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-04-13T09:17:00Z UTC
Last seen:
2026-04-15T11:38:00Z UTC
Hits:
~1000
Detections:
Trojan-PSW.Win32.Stealer.sb Trojan-PSW.Win32.Coins.sb Trojan-PSW.MSIL.Stealerium.sb PDM:Trojan.Win32.Generic Backdoor.Win32.Androm.sb Trojan.Win32.Vimditator.sb Trojan.Win32.Agent.sb Trojan-PSW.Win32.Disco.sb Trojan-PSW.MSIL.Stealer.sb Trojan-Dropper.Win32.Injector.sb Trojan-Downloader.MSIL.Agent.c HEUR:Trojan.BAT.Alien.gen
Result
Threat name:
KeyLogger, Phantom stealer, Strela Steal
Detection:
malicious
Classification:
spre.troj.spyw.expl.evad
Score:
100 / 100
Signature
.NET source code references suspicious native API functions
Allocates memory in foreign processes
Browser instances using unsafe startup parameters
Creates a thread in another existing process (thread injection)
Creates multiple autostart registry keys
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Found suspicious powershell code related to unpacking or dynamic code loading
Injects a PE file into a foreign processes
Installs a global keyboard hook
Malicious sample detected (through community Yara rule)
Monitors registry run keys for changes
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Sigma detected: Base64 Encoded PowerShell Command Detected
Sigma detected: Net WebClient Casing Anomalies
Sigma detected: PowerShell Base64 Encoded FromBase64String Cmdlet
Sigma detected: Powershell Decrypt And Execute Base64 Data
Sigma detected: Powerup Write Hijack DLL
Sigma detected: RegAsm connects to smtp port
Sigma detected: Suspicious PowerShell IEX Execution Patterns
Suricata IDS alerts for network traffic
Suspicious execution chain found
Suspicious powershell command line found
Switches to a custom stack to bypass stack traces
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses the Windows Restart Manager Abuse for Browser Credential File unlocking
Writes to foreign memory regions
Yara detected AntiVM3
Yara detected Costura Assembly Loader
Yara detected Keylogger Generic
Yara detected Phantom stealer
Yara detected Powershell decode and execute
Yara detected Powershell download and execute
Yara detected Strela Stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1897337 Sample: Sip. DISAGRUP_F#U0130YAT VE... Startdate: 13/04/2026 Architecture: WINDOWS Score: 100 100 mypanel.vip 2->100 102 mail.izlen.net 2->102 104 79 other IPs or domains 2->104 126 Suricata IDS alerts for network traffic 2->126 128 Found malware configuration 2->128 130 Malicious sample detected (through community Yara rule) 2->130 132 16 other signatures 2->132 11 cmd.exe 1 2->11         started        14 cmd.exe 2->14         started        16 cmd.exe 1 2->16         started        18 13 other processes 2->18 signatures3 process4 signatures5 150 Suspicious powershell command line found 11->150 20 powershell.exe 14 11->20         started        24 conhost.exe 11->24         started        26 powershell.exe 14->26         started        28 conhost.exe 14->28         started        30 powershell.exe 16->30         started        32 conhost.exe 16->32         started        34 powershell.exe 18->34         started        36 powershell.exe 18->36         started        38 21 other processes 18->38 process6 dnsIp7 94 C:\ProgramData\URT.bat, DOS 20->94 dropped 134 Suspicious powershell command line found 20->134 136 Found many strings related to Crypto-Wallets (likely being stolen) 20->136 138 Suspicious execution chain found 20->138 140 Found suspicious powershell code related to unpacking or dynamic code loading 20->140 41 powershell.exe 15 17 20->41         started        45 powershell.exe 26->45         started        47 powershell.exe 30->47         started        49 powershell.exe 34->49         started        51 powershell.exe 36->51         started        106 prod.detectportal.prod.cloudops.mozgcp.net 34.107.221.82, 49712, 49724, 49767 GOOGLEUS United States 38->106 108 push.services.mozilla.com 34.107.243.93, 443, 49729, 49734 GOOGLEUS United States 38->108 110 10 other IPs or domains 38->110 96 C:\Users\user\AppData\...\gmpopenh264.dll.tmp, PE32+ 38->96 dropped 98 C:\Users\user\...\gmpopenh264.dll (copy), PE32+ 38->98 dropped 53 powershell.exe 38->53         started        55 powershell.exe 38->55         started        57 powershell.exe 38->57         started        59 7 other processes 38->59 file8 signatures9 process10 dnsIp11 112 hasteb.in 45.33.64.25, 443, 49693, 49707 LINODE-APLinodeLLCUS United States 41->112 114 mypanel.vip 65.21.131.83, 443, 49698, 49709 CP-ASDE United States 41->114 116 pastefy.app 172.67.188.196, 443, 49695, 49708 CLOUDFLARENETUS United States 41->116 142 Found many strings related to Crypto-Wallets (likely being stolen) 41->142 144 Creates multiple autostart registry keys 41->144 146 Writes to foreign memory regions 41->146 61 2 other processes 41->61 148 Injects a PE file into a foreign processes 45->148 65 4 other processes 45->65 67 2 other processes 47->67 69 2 other processes 49->69 71 2 other processes 51->71 73 2 other processes 53->73 75 2 other processes 55->75 77 2 other processes 57->77 79 7 other processes 59->79 signatures12 process13 dnsIp14 118 mail.izlen.net 217.116.195.40, 49711, 587 HOSTHANETR Turkey 61->118 120 icanhazip.com 104.16.185.241, 49710, 80 CLOUDFLARENETUS United States 61->120 152 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 61->152 154 Tries to steal Mail credentials (via file / registry access) 61->154 156 Tries to harvest and steal browser information (history, passwords, etc) 61->156 158 8 other signatures 61->158 81 msedge.exe 61->81         started        84 firefox.exe 2 61->84         started        86 chrome.exe 61->86 injected 90 2 other processes 61->90 88 conhost.exe 65->88         started        signatures15 process16 signatures17 122 Monitors registry run keys for changes 81->122 124 Installs a global keyboard hook 81->124 92 msedge.exe 81->92         started        process18
Threat name:
Win32.Trojan.Qwexlafiba
Status:
Malicious
First seen:
2026-04-13 12:25:59 UTC
File Type:
Text (Batch)
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
phantom_stealer
Score:
  10/10
Tags:
family:phantom_stealer collection discovery execution persistence spyware stealer
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
outlook_office_path
outlook_win_path
System Location Discovery: System Language Discovery
System Time Discovery
Drops file in Windows directory
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Adds Run key to start application
Looks up external IP address via web service
Reads user/profile data of web browsers
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Detects PhantomStealer written in C#
Family: PhantomStealer
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CMD_Ping_Localhost
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments