🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2f63edf9c20d73454e0afbb04392c969e4b3e5c7bc227f80306b403758cd40cf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SilentNet


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments 1

SHA256 hash: 2f63edf9c20d73454e0afbb04392c969e4b3e5c7bc227f80306b403758cd40cf
SHA3-384 hash: 70d0a525df1f45b5b97ae21ae5d0cd1b67202a11a33826593356b14f3065516bd26bcbd79593555cbbe0c2fa73e72375
SHA1 hash: 5ec4d25a44d6cc7e70433d98c1f93599e65a417f
MD5 hash: ab35e7837ddad9b5090ae085cfadeb8b
humanhash: october-low-berlin-early
File name:prestige-client.org--PrestigeLoader-26.2.jar.jar
Download: download sample
Signature SilentNet
File size:1'577'446 bytes
First seen:2026-09-16 03:10:28 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 24576:QT0ZjG6D0wQNQyFtoga+5IQ2L1tr18IjOcVpvs+5iHJG6dFe3YfzFP9j39v+0uN6:BS6gwQNQEtPQ711jOqk+IHxdEINp3nt
TLSH T19B7533079A5CA413FCF34274874DA3FAC9C5701A0D849A7B1EF996218D5FED80E389B6
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika jar
Reporter GhostTypes
Tags:EtherHiding jar SilentNet stealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
FR FR
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
jar
Verdict:
No threats detected
Analysis date:
2026-09-16 03:37:45 UTC
Tags:
arch-exec

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Threat name:
Binary.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-13 19:09:41 UTC
File Type:
Binary (Archive)
Extracted files:
44
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

SilentNet

Java file jar 2f63edf9c20d73454e0afbb04392c969e4b3e5c7bc227f80306b403758cd40cf

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
commented on 2026-09-16 19:38:36 UTC

Distribution site: prestige-client.org (https://prestige-client.org/PrestigeLoader-1.21.11-v1.5.5.jar). SilentNet gen-4 github-mixin-loader fleet; nested loader built 2026-09-12 21:50-52 UTC. Smart-contract dead-drop ETH 0x9044f5762e43b23ba91d124b51a045f1b51da652 (text(), deployer 0x34d7fb0cdd43f39ddbdbe85cd6e0688b7596e665) resolves to live C2 windowsdiagnostics.st; stage-2 served at https://windowsdiagnostics.st/api/static/loading. Detected by static analysis (bbmmd donki-vm).