URLhaus Database

URLhaus tries to identify the malware associated with the payload served by a certain malware URL. In case URLhaus is able to identify the associated malware family, the payload will be tagged accordingly (field signature). The page below gives you an overview on payloads that URLhaus has identified as PhantomStealer.

Database Entry


Signature:PhantomStealer
Firstseen:2025-04-02 07:51:04 UTC
Lastseen:2025-11-20 08:09:09 UTC
Unique Payloads:20
URLs:28

Payload


The table below shows all payloads that have been identified as PhantomStealer.

Firstseen (UTC)SHA256File TypeFile sizeVT
2025-11-20 08:09:09b79d958cdf29416de5a7f1bea0de9a8010a0ae3136f00cf078de06e4c301e8883'330'440n/a
2025-11-08 17:02:08d9c88c1a21fc918ce8082e3c71e47e8b7e694b6b1fab0d94693bba1ddc13e693999'424Virustotal results 15 / 62 (24.19)
2025-11-08 16:52:09d9c88c1a21fc918ce8082e3c71e47e8b7e694b6b1fab0d94693bba1ddc13e693999'424Virustotal results 15 / 62 (24.19)
2025-11-08 08:03:07d9c88c1a21fc918ce8082e3c71e47e8b7e694b6b1fab0d94693bba1ddc13e693999'424Virustotal results 15 / 62 (24.19)
2025-11-04 08:36:09d9c88c1a21fc918ce8082e3c71e47e8b7e694b6b1fab0d94693bba1ddc13e693999'424Virustotal results 15 / 62 (24.19)
2025-11-04 08:35:12d9c88c1a21fc918ce8082e3c71e47e8b7e694b6b1fab0d94693bba1ddc13e693999'424Virustotal results 15 / 62 (24.19)
2025-11-04 08:35:11d9c88c1a21fc918ce8082e3c71e47e8b7e694b6b1fab0d94693bba1ddc13e693999'424Virustotal results 15 / 62 (24.19)
2025-10-29 16:09:12841af82ce668c0593a6b304a3505e7f2c33c7420c7de0a0745f9be16310696653'345'060Virustotal results 4 / 63 (6.35)
2025-10-29 16:09:09cfd8024adf35c0e3ce5fc2628b65f50213035fe77992234368e7bd0ee3f072813'345'060Virustotal results 9 / 61 (14.75)
2025-10-29 16:09:085f45e4e68f2b089b372cf1ef9b6db1a1e61f4b7889b73706bb1caa0d98ef58f737'028Virustotal results 7 / 60 (11.67)
2025-10-29 16:09:069c1d33c887c2488fab4eca5dd5c09bcb173c9d09d162442a329f09031051033f35'306Virustotal results 5 / 62 (8.06)
2025-10-29 15:58:10d9c88c1a21fc918ce8082e3c71e47e8b7e694b6b1fab0d94693bba1ddc13e693999'424Virustotal results 4 / 60 (6.67)
2025-10-29 15:58:07d9c88c1a21fc918ce8082e3c71e47e8b7e694b6b1fab0d94693bba1ddc13e693999'424Virustotal results 4 / 60 (6.67)
2025-10-29 07:29:06a05790987759904eaacf9334088c089bc2bab90c7223d6e72d3014043a3b72bc79'326n/a
2025-10-23 08:25:09d9c88c1a21fc918ce8082e3c71e47e8b7e694b6b1fab0d94693bba1ddc13e693999'424n/a
2025-09-12 07:37:014bd04debc182c6d62ead8d7682150188f1a483a90439dde4d4b17f70b0d9a2c03'933Virustotal results 1 / 57 (1.75)
2025-08-01 06:34:07b55e5f2eea6a4424153cfb2b0c655e899e569635fcfd908f3282b658e0032b8e492'328n/a
2025-04-29 12:00:0829213c5efb63d948ad4dc9c3fed382ee9159de8721cfd98c9f67ed6563e92d37Executable exe72'704Virustotal results 24 / 72 (33.33)
2025-04-29 05:51:1112e35465ce2fdaad24558f41692cb9a81274f8ecc37cd15ad4d572ed5f1178552'271Virustotal results 23 / 63 (36.51)
2025-04-02 07:51:044e28f186f3855291ec84b24da61938ab604d90d3121e1667f50bda632a5a3dd8177'364n/a

Number of entries displayed: 20 (max: 1'000)