MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dbb9231ff1fb45b101eeb44d6d2157863035dbc364ce8f726560ef0f833fbfdd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PhantomStealer


Vendor detections: 10


Intelligence 10 IOCs YARA 1 File information Comments

SHA256 hash: dbb9231ff1fb45b101eeb44d6d2157863035dbc364ce8f726560ef0f833fbfdd
SHA3-384 hash: 24f76d0c7ba8219dd3d738e96422bcf45f596f2c9122a877cb4a08c336a739b46662fc2ffee0c10c1364b5772b5f480d
SHA1 hash: 09833ffa84ba4f1f504a095213792a367960aabc
MD5 hash: 41bd5e2d5541f706767cd981ef00e12c
humanhash: nuts-minnesota-florida-eight
File name:Payment-receipt-ref8062547pdf.js
Download: download sample
Signature PhantomStealer
File size:78'461 bytes
First seen:2026-08-06 08:34:47 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 768:gposePX5kDay2YnWyVzuin/NvR86ZWvguEJon/D0Cyjam8k5yCIIAw49kw0gp8qA:WUs4LtDmxw9YVeJJN+cFMsXd7sx1TqO
TLSH T1FF730F55099678806337A7BFA32BA8E5F7764A6701802817B87C7450DFF2D09CEE0EB5
Magika javascript
Reporter abuse_ch
Tags:js PhantomStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
145
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader encrypted evasive masquerade obfuscated opendir repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-08-05T23:18:00Z UTC
Last seen:
2026-08-08T06:22:00Z UTC
Hits:
~100
Result
Threat name:
KeyLogger, Phantom stealer
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
AI detected malicious Powershell script
Allocates memory in foreign processes
Antivirus detection for URL or domain
Browser instances using unsafe startup parameters
Bypasses PowerShell execution policy
Creates a thread in another existing process (thread injection)
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Injects a PE file into a foreign processes
JavaScript source code contains functionality to generate code involving a shell, file or stream
JavaScript source code contains functionality to generate code involving HTTP requests or file downloads
Joe Sandbox ML detected suspicious sample
JScript performs obfuscated calls to suspicious functions
Malicious sample detected (through community Yara rule)
Monitors registry run keys for changes
Multi AV Scanner detection for submitted file
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample has a suspicious name (potential lure to open the executable)
Sample uses string decryption to hide its real strings
Sigma detected: Script Initiated Connection to Non-Local Network
Sigma detected: Suspicious PowerShell Parameter Substring
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Switches to a custom stack to bypass stack traces
System process connects to network (likely due to code injection or exploit)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
WScript reads language and country specific registry keys (likely country aware script)
Wscript starts Powershell (via cmd or directly)
Yara detected Costura Assembly Loader
Yara detected Keylogger Generic
Yara detected Phantom stealer
Yara detected Powershell decode and execute
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1953193 Sample: Payment-receipt-ref8062547pdf.js Startdate: 06/08/2026 Architecture: WINDOWS Score: 100 63 orienttaxtile.com 2->63 65 mail.polizas.gr 2->65 67 2 other IPs or domains 2->67 93 Found malware configuration 2->93 95 Malicious sample detected (through community Yara rule) 2->95 97 Antivirus detection for URL or domain 2->97 99 14 other signatures 2->99 11 wscript.exe 21 2->11         started        signatures3 process4 dnsIp5 83 orienttaxtile.com 13.140.159.163, 443, 49719 VEESP-LV-ASLV Germany 11->83 55 C:\Temp\PEA39ZPJ.ps1, ASCII 11->55 dropped 115 System process connects to network (likely due to code injection or exploit) 11->115 117 JScript performs obfuscated calls to suspicious functions 11->117 119 Wscript starts Powershell (via cmd or directly) 11->119 121 4 other signatures 11->121 16 powershell.exe 16 11->16         started        file6 signatures7 process8 signatures9 89 Writes to foreign memory regions 16->89 91 Injects a PE file into a foreign processes 16->91 19 aspnet_compiler.exe 15 12 16->19         started        23 aspnet_compiler.exe 16->23         started        25 conhost.exe 16->25         started        27 4 other processes 16->27 process10 dnsIp11 69 mail.polizas.gr 185.25.23.20, 49781, 587 POINTERGR Greece 19->69 71 icanhazip.com 104.16.185.241, 49780, 80 CLOUDFLARENET-CloudflareIncUS Canada 19->71 101 Tries to steal Mail credentials (via file / registry access) 19->101 103 Found many strings related to Crypto-Wallets (likely being stolen) 19->103 105 Tries to harvest and steal browser information (history, passwords, etc) 19->105 113 4 other signatures 19->113 29 msedge.exe 50 875 19->29         started        33 firefox.exe 2 19->33         started        35 chrome.exe 19->35 injected 37 6 other processes 19->37 107 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 23->107 109 Browser instances using unsafe startup parameters 23->109 111 Switches to a custom stack to bypass stack traces 23->111 signatures12 process13 dnsIp14 85 192.168.2.11, 138, 443, 49606 unknown unknown 29->85 87 239.255.255.250 unknown ZZ 29->87 57 C:\...\the-real-index~RF3833b.TMP (copy), COM 29->57 dropped 59 C:\Users\user\...\the-real-index (copy), COM 29->59 dropped 61 C:\Users\user\AppData\Local\...\temp-index, COM 29->61 dropped 39 msedge.exe 29->39         started        42 setup.exe 29->42         started        44 msedge.exe 29->44         started        49 2 other processes 29->49 46 firefox.exe 3 44 33->46         started        file15 process16 dnsIp17 73 104.208.16.94, 443, 49758 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 39->73 75 mr-b01.tm-azurefd.net 150.171.110.193, 443, 49744 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 39->75 81 33 other IPs or domains 39->81 51 setup.exe 42->51         started        77 mozilla.map.fastly.net 151.101.1.91, 443, 49725 FASTLY-FastlyIncUS Canada 46->77 79 127.0.0.1 unknown unknown 46->79 123 Monitors registry run keys for changes 46->123 53 firefox.exe 1 46->53         started        signatures18 process19
Gathering data
Threat name:
Script-JS.Trojan.Heuristic
Status:
Malicious
First seen:
2026-08-06 09:11:36 UTC
File Type:
Text (JavaScript)
AV detection:
10 of 38 (26.32%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
execution
Behaviour
Command and Scripting Interpreter: JavaScript
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments