
Shared Imphash Ties Four 'Different' Stealers to One Builder Stub
Four Windows executables labeled by antivirus vendors as AgentTesla, Bobik, Reline, and an unnamed loader all share the same import-table imphash and packer signature, revealing one commodity builder pipeline behind supposedly separate malware families. Sandbox verdicts add RedlineStealer and Fabookie to the mix, underscoring how downstream AV labels obscure a single build lineage.
Four Windows executables carrying four unrelated antivirus labels — AgentTesla, Bobik, "Reline," and an unnamed loader named pctool.exe — turn out to share the same import-table fingerprint, imphash f34d5f2d4577ed6d9ceec516c1f5a744, and the same PEiD packer signature. That single build lineage is the most durable and reproducible signal in an 18-file, 6-domain cluster CTX Team has been tracking: a commodity builder-and-stub layer that antivirus vendors are classifying as though it produced four…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read