🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2599c5a6191bc208c4f0f1fcafba81b0f8d4099de6dc8d64ee7aec0b5289833e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments 1

SHA256 hash: 2599c5a6191bc208c4f0f1fcafba81b0f8d4099de6dc8d64ee7aec0b5289833e
SHA3-384 hash: 1a5607c17e4ef2fe0f85bc75fd9a36b48db8f00f970c1ecde9b4126c5e2c984191c212bcaa174a9362cb9a3c3fcc14bc
SHA1 hash: e6cf86ee39d64364964eda3adc761bc3388467ca
MD5 hash: 2c0747da107021dd2995640eef8afd37
humanhash: blossom-butter-johnny-beryllium
File name:github-mixin-loader-2.5.2-obfuscated.jar
Download: download sample
File size:1'552'190 bytes
First seen:2026-09-16 03:08:16 UTC
Last seen:Never
File type:Java file jar
MIME type:application/java-archive
ssdeep 24576:I+sIXjOYDICQTq2Fl2Eae5GGiVztrZ8Mj0cb3JmYNWfRGwdJAj+/zfP993hb+MWp:IoCY0CQTqolfiTZPj0iMYEfNd2qr73c
TLSH T178753307696CF813FCF30275474DB2AAD9C5B0160DC09A6B5E7A8251CE5FF844E28AED
TrID 57.8% (.JAR) Minecraft Fabric Mod (24020/2/4)
32.5% (.JAR) Java Archive (13500/1/2)
9.6% (.ZIP) ZIP compressed archive (4000/1)
Magika jar
Reporter GhostTypes
Tags:EtherHiding jar SilentNet stealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
FR FR
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
jar
Verdict:
No threats detected
Analysis date:
2026-09-16 03:11:13 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments



Avatar
commented on 2026-09-16 19:40:34 UTC

Nested loader jar (github-mixin-loader-2.5.2-obfuscated, fabric.mod.json spoofed as Mixin Loader by Fabric Team) extracted from the 22qq-client.com site jar. Same contract 0x9044f5762e43b23ba91d124b51a045f1b51da652 -> windowsdiagnostics.st. bbmmd markers donki-vm:vm-image / donki-vm:loader-jar.