MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1f79ce70cd5c4f7829c34604c2a62db5d5b2a4d00d5d8b6a8b246e3059e77f17. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SilentNet


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: 1f79ce70cd5c4f7829c34604c2a62db5d5b2a4d00d5d8b6a8b246e3059e77f17
SHA3-384 hash: bb6d0a119b23bf37558f0521c714622cf68d81278de449fcb2e3e5d9aff1147e9ef8dd5d35aade9a4d50c691ffb69eca
SHA1 hash: 6695fcbe90678e915c620aae4ef4dd051f60e67c
MD5 hash: 124dc47fe247ccb6966e3e9a3b92c151
humanhash: low-glucose-ohio-coffee
File name:Matrix duper.jar
Download: download sample
Signature SilentNet
File size:5'134'136 bytes
First seen:2026-07-14 14:34:57 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 98304:Sg+LvwN584qgmw2WbCisrXTsDIynRJzGS5JB9X:ww5cgZ2vrjSIORxGS5JrX
TLSH T133363390C80A9796AE517471B7FF9A79336E58AC7C02B4A7B081FB2CD010F327593567
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika jar
Reporter burger
Tags:jar SilentNet

Intelligence


File Origin
# of uploads :
1
# of downloads :
148
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
jar
First seen:
2026-07-14T11:39:00Z UTC
Last seen:
2026-07-16T08:53:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan.Java.Generic
Result
Threat name:
SilentNet, MicroClip
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
Adds a directory exclusion to Windows Defender
Allocates memory in foreign processes
Creates a thread in another existing process (thread injection)
Exploit detected, runtime environment starts unknown processes
Found many strings related to Crypto-Wallets (likely being stolen)
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Rare Remote Thread Creation By Uncommon Source Image
Suricata IDS alerts for network traffic
Suspicious powershell command line found
Tries to harvest and steal browser information (history, passwords, etc)
Unusual module load detection (module proxying)
Writes to foreign memory regions
Yara detected MicroClip
Yara detected SilentNet
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1942310 Sample: Matrix duper.jar Startdate: 14/07/2026 Architecture: WINDOWS Score: 100 97 thisisafalsepositive.st 2->97 99 pypi.org 2->99 101 3 other IPs or domains 2->101 123 Suricata IDS alerts for network traffic 2->123 125 Yara detected SilentNet 2->125 127 Yara detected MicroClip 2->127 129 5 other signatures 2->129 12 cmd.exe 1 2->12         started        signatures3 process4 process5 14 java.exe 5 12->14         started        17 conhost.exe 12->17         started        signatures6 139 Found many strings related to Crypto-Wallets (likely being stolen) 14->139 19 javaw.exe 884 14->19         started        process7 dnsIp8 103 132.145.155.63, 443, 49701, 49709 ORACLE-BMC-31898-OracleCorporationUS United States 19->103 105 198.178.224.35, 443, 49699, 49707 LATITUDE-SH-LatitudeshUS United States 19->105 107 thisisafalsepositive.st 185.178.208.191, 443, 49703, 49704 DDOS-GUARDRU Russia 19->107 57 C:\Users\user\AppData\Local\...\python.exe, PE32+ 19->57 dropped 59 C:\Users\user\AppData\Local\...\winsound.pyd, PE32+ 19->59 dropped 61 C:\Users\user\AppData\...\vcruntime140_1.dll, PE32+ 19->61 dropped 63 623 other files (none is malicious) 19->63 dropped 23 python.exe 217 19->23         started        file9 process10 dnsIp11 109 dualstack.python.map.fastly.net 151.101.128.223, 443, 49714, 49731 FASTLY-FastlyIncUS Canada 23->109 111 151.101.64.175, 443, 49719 FASTLY-FastlyIncUS Canada 23->111 113 2 other IPs or domains 23->113 73 C:\Users\user\AppData\Local\...\python.exe, PE32+ 23->73 dropped 75 C:\Users\user\AppData\Local\...\main.py, Python 23->75 dropped 77 C:\Users\user\AppData\...\tmph0dmm1gl.tmp, PE32+ 23->77 dropped 79 32 other files (none is malicious) 23->79 dropped 131 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 23->131 133 Found many strings related to Crypto-Wallets (likely being stolen) 23->133 135 Tries to harvest and steal browser information (history, passwords, etc) 23->135 137 3 other signatures 23->137 28 pip.exe 23->28         started        30 python.exe 1088 23->30         started        35 python.exe 23->35         started        37 2 other processes 23->37 file12 signatures13 process14 dnsIp15 39 python.exe 28->39         started        42 conhost.exe 28->42         started        115 pypi.org 151.101.64.223, 443, 49729, 49735 FASTLY-FastlyIncUS Canada 30->115 81 C:\Users\user\AppData\Local\...\pip3.exe, PE32+ 30->81 dropped 83 C:\Users\user\AppData\Local\...\pip3.12.exe, PE32+ 30->83 dropped 85 C:\Users\user\AppData\Local\...\pip.exe, PE32+ 30->85 dropped 93 378 other files (none is malicious) 30->93 dropped 119 Suspicious powershell command line found 30->119 121 Adds a directory exclusion to Windows Defender 30->121 44 conhost.exe 30->44         started        117 150.136.141.142 ORACLE-BMC-31898-OracleCorporationUS United States 35->117 87 C:\Users\user\AppData\Local\...\stdole.py, Python 35->87 dropped 89 _78530B68_61F9_11D...A024580902_0_1_0.py, Python 35->89 dropped 91 _56A868B0_0AD4_11C...20AF0BA770_0_1_0.py, Python 35->91 dropped 95 3 other files (none is malicious) 35->95 dropped 46 powershell.exe 35->46         started        49 conhost.exe 35->49         started        file16 signatures17 process18 file19 65 C:\Users\user\AppData\...\cffi-gen-src.exe, PE32+ 39->65 dropped 67 C:\Users\user\AppData\Local\...\win32wnet.pyd, PE32+ 39->67 dropped 69 C:\Users\user\AppData\Local\...\win32ts.pyd, PE32+ 39->69 dropped 71 560 other files (none is malicious) 39->71 dropped 51 cmd.exe 39->51         started        141 Loading BitLocker PowerShell Module 46->141 53 conhost.exe 46->53         started        55 WmiPrvSE.exe 46->55         started        signatures20 process21
Threat name:
ByteCode-JAVA.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-14 14:35:57 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
silentnet
Score:
  10/10
Tags:
family:silentnet stealer
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:RANSOMWARE
Author:ToroGuitar

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments