🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 33d46e4a54c81e5083b2ae4af136a9250c244d0897685526b6669a2ffef3e3d9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SilentNet


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments 1

SHA256 hash: 33d46e4a54c81e5083b2ae4af136a9250c244d0897685526b6669a2ffef3e3d9
SHA3-384 hash: 3aebd8c4f289c674468969f07b16dcd76779dc05592248410fc23652822346a8f83e5171e0a94e154d9ccf64b25d566e
SHA1 hash: 34cf3afd8b3532ab424c2fed434186b8243f69f0
MD5 hash: 2eb5cd7340061b5cf6dbcb6731b0ba10
humanhash: bakerloo-north-triple-gee
File name:198macros.org--198-Macros-Cracked-26.2.jar.jar
Download: download sample
Signature SilentNet
File size:1'577'575 bytes
First seen:2026-09-16 03:08:16 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 24576:FmljIGDeAQ3oAFRkcaK5gYQLRtrf8UjKc1bvw0Toh3G+dRsZAPz3P9r3Jz+a2fJz:YEGKAQ3oeRDWnf5jK8o0UhjdGmLZ31e
TLSH T1A37533035A68B813FCB342B5478DA3FBCAC570170D84967B4EB956218D5FF980E385BA
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika jar
Reporter GhostTypes
Tags:EtherHiding jar SilentNet stealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
FR FR
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
jar
Verdict:
No threats detected
Analysis date:
2026-09-16 03:11:12 UTC
Tags:
arch-exec

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Threat name:
Binary.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-14 03:31:25 UTC
File Type:
Binary (Archive)
Extracted files:
44
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments



Avatar
commented on 2026-09-16 19:34:50 UTC

Distribution site: 198macros.org (https://198macros.org/198-Macros-Cracked-26.2.jar). SilentNet gen-4 github-mixin-loader fleet; nested loader built 2026-09-12 21:50-52 UTC. Smart-contract dead-drop ETH 0x9044f5762e43b23ba91d124b51a045f1b51da652 (text(), deployer 0x34d7fb0cdd43f39ddbdbe85cd6e0688b7596e665) resolves to live C2 windowsdiagnostics.st; stage-2 served at https://windowsdiagnostics.st/api/static/loading. Detected by static analysis (bbmmd donki-vm).