• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Phantom Stealer IOC Hunt - C2 IPs and Known File Hashes

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Arnold Chan@slaz
    •updated 24 days ago•1•0•0

    This rule monitors for network connections to known command-and-control (C2) IP addresses and the execution or presence of files matching known hashes associated with the 'PhantomC2' threat group or malware family. It correlates data from DeviceNetworkEvents, DeviceFileEvents, and DeviceProcessEvents to identify potential compromise.

    Microsoft Sentinel (KQL)

    Tags

    T1071 - Application Layer ProtocolT1105 - Ingress Tool TransferNetwork Connection OutboundFile Executable DetectedProcess CreationMalware DetectedWindowsWindows Defender Atpkql

    Found in

    • Phantom Stealer Malware-as-a-Service Infostealer AnalysisLast updated 24 days ago
    • Phantom Stealer Malware-as-a-Service Infostealer AnalysisLast updated 24 days ago
    • Phantom Stealer Malware-as-a-Service Infostealer AnalysisLast updated 24 days ago
    • Phantom Stealer Malware-as-a-Service Infostealer AnalysisLast updated 24 days ago
    • Phantom Stealer Malware-as-a-Service Infostealer AnalysisLast updated 24 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?