🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 490bd7f74ab85cdbfe757047b013debae8e56cc0d959c6f8bfef4e8bac1ed8f9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 490bd7f74ab85cdbfe757047b013debae8e56cc0d959c6f8bfef4e8bac1ed8f9
SHA3-384 hash: 591ca0caf20a49acbbbbc8e6b6209f6a7e237eaf7253227c1ff2d3f930b1d7bc7efbda7713eb21cc42b466aa0b9f2471
SHA1 hash: 6bf9d9b76ef4e999a722d741216dc74f370aaa25
MD5 hash: 570bfa1680d92dd6daa8792f446155b5
humanhash: blossom-lithium-carbon-apart
File name:22qq-client.com
Download: download sample
File size:1'558'849 bytes
First seen:2026-09-16 03:07:42 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:D9QMhdgMDkKQxqoFvw4aq5i+epjtrn8UhocdblGg7KFtGcdbADeBznP993Lt+IY0:DHuMAKQxq2v7QHnThog4gWFLdsyRr3n
TLSH T17B753306966CE813FCB31375478DA2E9CAC4B0170DC49A7B4DB94661DD1FFC84E289BA
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika zip
Reporter GhostTypes

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
FR FR
File Archive Information

This file archive contains 9 file(s), sorted by their relevance:

File name:MANIFEST.MF
File size:414 bytes
SHA256 hash: f20cbc7766cb9d9b3445c58e8402e9ec6da7454fa0ea62555939b6e56c8c2c0e
MD5 hash: bb6ee1fa6f1321a97516851800129f08
MIME type:text/plain
File name:en_us.json
File size:226 bytes
SHA256 hash: 6691204c334151adc8653b2d91acbf77fe28acc9254acd938bc1ff0872af518b
MD5 hash: 906dd91683991ec5d3870fa012aa5c76
MIME type:application/json
File name:github-mixin-loader-2.5.2-obfuscated.jar
File size:1'552'190 bytes
SHA256 hash: 2599c5a6191bc208c4f0f1fcafba81b0f8d4099de6dc8d64ee7aec0b5289833e
MD5 hash: 2c0747da107021dd2995640eef8afd37
MIME type:application/java-archive
File name:GuiMixin.class
File size:3'323 bytes
SHA256 hash: 4ef2903224d60dd8870fe1cc86d969e88755609ad5302e90c276ab2ca756733a
MD5 hash: ebe2e51be2d02598868e842183850767
MIME type:application/x-java-applet
File name:icon.png
File size:6'312 bytes
SHA256 hash: 429b3cc4b15868de72a3aec6118b8e1a82fe84e56b6735095dc62fad6d5ec3c3
MD5 hash: 3c273febce9d9066b9a6e564ee71bf74
MIME type:image/png
File name:LICENSE_toggle-sprint-display
File size:7'815 bytes
SHA256 hash: f831e7eed577481687a9bc0b48024e5e40b6f655fcde073ede964b50be5d55d9
MD5 hash: cc46e3e9ef97cbdc56318ee7ff23d73e
MIME type:text/plain
File name:toggle-sprint-display.mixins.json
File size:279 bytes
SHA256 hash: 15f47095d52ae6659f685f26a8636942ce6b7c974359b81bf37b03c002e2f2b7
MD5 hash: baebace0977c87e578a3c457eb1985ba
MIME type:text/plain
File name:fabric.mod.json
File size:599 bytes
SHA256 hash: 6c2c6b86ebac984dc2699ed0c0cf654349cea0cf69e13ce676cdcbe4e04eb4e0
MD5 hash: bb777637635b4a8170bf20133d4f5d0e
MIME type:text/plain
File name:toggle-sprint-display-refmap.json
File size:422 bytes
SHA256 hash: 5f15bffdb82561697b7c9beb33733c736ef4e9ac65238aa8b9f4db96f3880279
MD5 hash: 392de46494a37307bc662782de53512d
MIME type:application/json
Vendor Threat Intelligence
No detections
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Zip Archive
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

zip 490bd7f74ab85cdbfe757047b013debae8e56cc0d959c6f8bfef4e8bac1ed8f9

(this sample)

  
Delivery method
Distributed via web download

Comments