🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3ad70d2ec5439d26164ae414cbf8e463e3b129dd80f8dbbbf89084c89565e111. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments 1

SHA256 hash: 3ad70d2ec5439d26164ae414cbf8e463e3b129dd80f8dbbbf89084c89565e111
SHA3-384 hash: 4538587d137d02adeedde55f5dc816415a24ccd71d76704773747f92317b2c58f77607d4bb692a9953ce51cc4ec2206f
SHA1 hash: 306470a0b7664fcb533a0477748d7e777d62964f
MD5 hash: 3f4b997e2c44220b57efe86ae2962ab6
humanhash: whiskey-blue-sad-ceiling
File name:familyaddons.org--FamilyAddons-26.2.jar.jar
Download: download sample
File size:1'577'469 bytes
First seen:2026-09-16 03:08:49 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 24576:khUvjwGDo0QrKYF1EYaa5CKqvJtrB8cjkc3FN2KVMFdG+dxWD+3zdP9x3Dd+me98:r8GU0QrKG1X87BNjkMQKeFRdQydH3/L
TLSH T1B1753302951CB813FCB34274874DA3FADAC9B01B0DC495BB5DB69321CD5FE984A385BA
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika jar
Reporter GhostTypes
Tags:EtherHiding jar SilentNet stealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
FR FR
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
jar
Verdict:
No threats detected
Analysis date:
2026-09-16 04:02:46 UTC
Tags:
arch-exec

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments



Avatar
commented on 2026-09-16 19:36:06 UTC

Distribution site: familyaddons.org (https://familyaddons.org/FamilyAddons-1.21.11-v3.7.4.jar). SilentNet gen-4 github-mixin-loader fleet; nested loader built 2026-09-12 21:50-52 UTC. Smart-contract dead-drop ETH 0x9044f5762e43b23ba91d124b51a045f1b51da652 (text(), deployer 0x34d7fb0cdd43f39ddbdbe85cd6e0688b7596e665) resolves to live C2 windowsdiagnostics.st; stage-2 served at https://windowsdiagnostics.st/api/static/loading. Detected by static analysis (bbmmd donki-vm).