MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eddb2dceefe6b8eadc8556697efefb528965da714d1a09e356d7deb788e19e8f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PhantomStealer


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: eddb2dceefe6b8eadc8556697efefb528965da714d1a09e356d7deb788e19e8f
SHA3-384 hash: d48d312f227d191e60a6f46b225ede20a66a68ef15ae39e26391daf56e5817e5355158129b126bb9bf15f8e21ada251e
SHA1 hash: aee47aa72f4eb157a219327e52751dc909fb5985
MD5 hash: a6fcfa65f7cb6c76c21adf39abe32759
humanhash: missouri-freddie-wyoming-mockingbird
File name:852000031.img
Download: download sample
Signature PhantomStealer
File size:1'245'184 bytes
First seen:2026-07-21 05:52:43 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 192:hqJ2BgDLB3FxAyZgD/glv5IDH5XNS6IydK/H5Ee3PrhY3P5d4P+CX1VMPuy:T81FM8bIDH59RIydYH5p3DhIxiFV+
TLSH T18C45743AE65CEFF4C72D11F141873D021168AB56713A89ADB4CDC158BF2A7508FA68EC
TrID 47.7% (.ISO/UDF) UDF disc image (2114500/1/6)
46.2% (.NULL) null bytes (2048000/1)
5.7% (.HTP) HomeLab/BraiLab Tape image (256000/1)
0.1% (.ATN) Photoshop Action (5007/6/1)
0.0% (.ISO) ISO 9660 CD image (2545/36/1)
Magika iso
Reporter JAMESWT_WT
Tags:FAMILY-TRIP-BOOKING img PhantomStealer Spam-ITA tourtrade-shop xambby--tourtrade-shop

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
IT IT
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:Boot-NoEmul.img
File size:2'048 bytes
SHA256 hash: fc3d39b29d7c628ab9d3b01b096a2bd5e711d42f0ba2a42df0bd500773c92f91
MD5 hash: ce05c025433085b7e856e7214f7ce8b1
MIME type:application/octet-stream
Signature PhantomStealer
File name:85200003.VBS
File size:15'772 bytes
SHA256 hash: 2cd6897845961d94d058970266728a7abb4d6fdaff48bb295acdb912dfac9f89
MD5 hash: a3acfb33bc369fa29fb5a191ee8ca09c
MIME type:text/plain
Signature PhantomStealer
Vendor Threat Intelligence
Verdict:
Malicious
Score:
81.4%
Tags:
uloader virus
Verdict:
Malicious
File Type:
iso
First seen:
2026-07-21T03:58:00Z UTC
Last seen:
2026-07-21T10:55:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan.Script.Generic HEUR:Trojan-Downloader.Script.Generic
Threat name:
Script-WScript.Trojan.GuLoader
Status:
Malicious
First seen:
2026-07-21 00:00:56 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments