🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ebe55ff8fe1a36f2101dcf651a5941432575ca645200768288f30dafe0f2c57f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PhantomStealer


Vendor detections: 11


Intelligence 11 IOCs YARA 4 File information Comments

SHA256 hash: ebe55ff8fe1a36f2101dcf651a5941432575ca645200768288f30dafe0f2c57f
SHA3-384 hash: c5d9a84a0bed1804712bdb9706b7dd54bba3dc724cba59122c49203ef9e45938b942e941ffdbaceca80a2c964a31cd51
SHA1 hash: 7150f5d94f99d031463287bdcd79de53fd635aa6
MD5 hash: cb6b306445a523130dde73a5c33cf7fc
humanhash: michigan-undress-hamper-kilo
File name:RFQ-20172512-gpi_waleedece - Copy.js
Download: download sample
Signature PhantomStealer
File size:850'210 bytes
First seen:2026-08-27 13:47:32 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 24576:pTwhVOMQJneDP63jffLO9wcZItM7B80pwJn:pYZJ0t481x
TLSH T13605011C1F062DFA5AEAC20A9A3344FD1DE7D6C3C09EE5CB920AB4617B1931365DAD0D
Magika txt
Reporter threatcat_ch
Tags:js PhantomStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
148
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd evasive lolbin obfuscated powershell repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-08-24T22:05:00Z UTC
Last seen:
2026-08-29T10:50:00Z UTC
Hits:
~100
Result
Threat name:
KeyLogger, MicroClip, Phantom stealer, T
Detection:
malicious
Classification:
rans.troj.spyw.expl.evad
Score:
100 / 100
Signature
.NET source code contains process injector
.NET source code references suspicious native API functions
Contains functionality to log keystrokes (.Net Source)
Creates a thread in another existing process (thread injection)
Creates an autostart registry key pointing to binary in C:\Windows
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Found stalling execution ending in API Sleep call
Found suspicious powershell code related to unpacking or dynamic code loading
Hijacks the control flow in another process
Injects a PE file into a foreign processes
Installs a global keyboard hook
Joe Sandbox ML detected suspicious sample
JScript performs obfuscated calls to suspicious functions
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Multi AV Scanner detection for submitted file
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Sigma detected: Dot net compiler compiles file from suspicious location
Sigma detected: Register Wscript In Run Key
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Unusual module load detection (module proxying)
Uses attrib.exe to hide files
Uses cmd line tools excessively to alter registry or file data
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript called in batch mode (surpress errors)
WScript reads language and country specific registry keys (likely country aware script)
Wscript starts Powershell (via cmd or directly)
Yara detected AntiVM3
Yara detected Keylogger Generic
Yara detected MicroClip
Yara detected Phantom stealer
Yara detected Telegram RAT
Yara detected TrojanRansom
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1964787 Sample: RFQ-20172512-gpi_waleedece ... Startdate: 27/08/2026 Architecture: WINDOWS Score: 100 101 mail.gpi.com.eg 2->101 103 gpi.com.eg 2->103 105 2 other IPs or domains 2->105 113 Sigma detected: Register Wscript In Run Key 2->113 115 Found malware configuration 2->115 117 Malicious sample detected (through community Yara rule) 2->117 119 15 other signatures 2->119 11 wscript.exe 1 1 2->11         started        14 wscript.exe 2->14         started        16 wscript.exe 2->16         started        signatures3 process4 signatures5 155 JScript performs obfuscated calls to suspicious functions 11->155 157 Wscript starts Powershell (via cmd or directly) 11->157 159 Windows Scripting host queries suspicious COM object (likely to drop second stage) 11->159 161 Suspicious execution chain found 11->161 18 cmd.exe 4 11->18         started        22 powershell.exe 8 11->22         started        163 WScript reads language and country specific registry keys (likely country aware script) 14->163 24 cmd.exe 14->24         started        process6 file7 83 C:\Users\user\...\print_spool_m_ZOBFDGUZ.cmd, DOS 18->83 dropped 85 C:\Users\user\AppData\...\print_spool_m.dat, DOS 18->85 dropped 121 Wscript starts Powershell (via cmd or directly) 18->121 123 Uses cmd line tools excessively to alter registry or file data 18->123 125 Uses attrib.exe to hide files 18->125 26 powershell.exe 18->26         started        28 conhost.exe 18->28         started        31 reg.exe 1 1 18->31         started        41 11 other processes 18->41 87 C:\Users\user\...\20267271787839424570.cmd, DOS 22->87 dropped 127 Found many strings related to Crypto-Wallets (likely being stolen) 22->127 129 Found suspicious powershell code related to unpacking or dynamic code loading 22->129 33 conhost.exe 22->33         started        35 powershell.exe 24->35         started        37 conhost.exe 24->37         started        39 attrib.exe 24->39         started        43 2 other processes 24->43 signatures8 process9 signatures10 45 powershell.exe 1 33 26->45         started        165 Installs a global keyboard hook 28->165 167 Creates an autostart registry key pointing to binary in C:\Windows 31->167 49 powershell.exe 35->49         started        process11 file12 97 C:\Users\user\AppData\...\pbg52qh0.cmdline, Unicode 45->97 dropped 99 C:\Users\user\...\print_spool_m_ZHLBZDCS.vbs, ASCII 45->99 dropped 169 Writes to foreign memory regions 45->169 171 Maps a DLL or memory area into another process 45->171 173 Creates a thread in another existing process (thread injection) 45->173 175 Loading BitLocker PowerShell Module 45->175 51 msiexec.exe 2 45->51         started        54 conhost.exe 45->54         started        56 csc.exe 3 45->56         started        65 2 other processes 45->65 59 msiexec.exe 49->59         started        61 conhost.exe 49->61         started        63 csc.exe 49->63         started        67 2 other processes 49->67 signatures13 process14 file15 131 Hijacks the control flow in another process 51->131 133 Found many strings related to Crypto-Wallets (likely being stolen) 51->133 135 Writes to foreign memory regions 51->135 69 prevhost.exe 51->69         started        137 Installs a global keyboard hook 54->137 89 C:\Users\user\AppData\Local\...\pbg52qh0.dll, PE32 56->89 dropped 73 cvtres.exe 1 56->73         started        139 Creates a thread in another existing process (thread injection) 59->139 141 Injects a PE file into a foreign processes 59->141 75 prevhost.exe 59->75         started        91 C:\Users\user\AppData\Local\...\1msmeyqa.dll, PE32 63->91 dropped 77 cvtres.exe 63->77         started        93 C:\Users\user\AppData\Local\...\emh2vo4d.dll, PE32 65->93 dropped 79 cvtres.exe 1 65->79         started        95 C:\Users\user\AppData\Local\...\ds0e40xo.dll, PE32 67->95 dropped 81 cvtres.exe 67->81         started        signatures16 process17 dnsIp18 107 gpi.com.eg 37.48.99.77, 49756, 49758, 49762 LEASEWEB-NL-AMS-01NetherlandsNL Netherlands 69->107 109 github.com 140.82.113.4, 443, 49755, 49757 GITHUB-GitHubIncUS United States 69->109 143 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 69->143 145 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 69->145 147 Tries to steal Mail credentials (via file / registry access) 69->147 153 2 other signatures 69->153 111 icanhazip.com 104.16.184.241, 49761, 80 CLOUDFLARENET-CloudflareIncUS Canada 75->111 149 Tries to harvest and steal browser information (history, passwords, etc) 75->149 151 Installs a global keyboard hook 75->151 signatures19
Verdict:
inconclusive
YARA:
1 match(es)
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-08-25 04:26:01 UTC
File Type:
Text (Batch)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
PhantomStealer
Result
Malware family:
phantom_stealer
Score:
  10/10
Tags:
family:phantom_stealer collection defense_evasion discovery execution persistence stealer
Behaviour
Checks processor information in registry
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Views/modifies file attributes
outlook_office_path
Command and Scripting Interpreter: JavaScript
Command and Scripting Interpreter: PowerShell
Enumerates physical storage devices
Hide Artifacts: Hidden Files and Directories
Accesses Microsoft Outlook profiles
Adds Run key to start application
Looks up external IP address via web service
Checks computer location settings
Family: PhantomStealer
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:telebot_framework
Author:vietdx.mb
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

PhantomStealer

Java Script (JS) js ebe55ff8fe1a36f2101dcf651a5941432575ca645200768288f30dafe0f2c57f

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments