APTMembers
APT

Shared Imphash Ties Four 'Different' Stealers to One Builder Stub

Four Windows executables labeled by antivirus vendors as AgentTesla, Bobik, Reline, and an unnamed loader all share the same import-table imphash and packer signature, revealing one commodity builder pipeline behind supposedly separate malware families. Sandbox verdicts add RedlineStealer and Fabookie to the mix, underscoring how downstream AV labels obscure a single build lineage.

Jun 28, 2026, 01:25 (UTC+9)Last seenJul 2, 2026Severity77ByCTX TeamActorLazarus GroupHastati GroupIOC44RegionsFR

Four Windows executables carrying four unrelated antivirus labels — AgentTesla, Bobik, "Reline," and an unnamed loader named pctool.exe — turn out to share the same import-table fingerprint, imphash f34d5f2d4577ed6d9ceec516c1f5a744, and the same PEiD packer signature. That single build lineage is the most durable and reproducible signal in an 18-file, 6-domain cluster CTX Team has been tracking: a commodity builder-and-stub layer that antivirus vendors are classifying as though it produced four…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence