🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4b253880629b092f2c8d6ba9d53312d217320ecbea07e67324ea43538cade724. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SilentNet


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments 1

SHA256 hash: 4b253880629b092f2c8d6ba9d53312d217320ecbea07e67324ea43538cade724
SHA3-384 hash: 3f6abe25c12d006a9ad65d24f2187d13ee79f7ff48b0296246c9c066639589d3394b8c8787355e1bff5098a4b5427b7c
SHA1 hash: 670cdb46252afabf9005e7a2f060debaba5c4888
MD5 hash: 80497e618652bd1fcf987855077d822f
humanhash: arkansas-finch-neptune-eighteen
File name:odinclient.com--OdinClient-26.2.jar.jar
Download: download sample
Signature SilentNet
File size:1'577'569 bytes
First seen:2026-09-16 03:09:21 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 49152:xV20yCQHE6RhUT3rj2WiqOD3dQAhJ3z4p:K0yI6RhUT3rj2WZOxQQB4p
TLSH T19F7533079A6CE813FCF34274874DA3BEC6D970160D84996B5EB593218D6FE880E385F6
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika zip
Reporter GhostTypes
Tags:EtherHiding jar SilentNet stealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
FR FR
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
jar
Verdict:
No threats detected
Analysis date:
2026-09-16 03:47:15 UTC
Tags:
arch-exec

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

SilentNet

Java file jar 4b253880629b092f2c8d6ba9d53312d217320ecbea07e67324ea43538cade724

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
commented on 2026-09-16 19:37:51 UTC

Distribution site: odinclient.com (https://odinclient.com/Odin-1.21.11-v2.9.5.jar). SilentNet gen-4 github-mixin-loader fleet; nested loader built 2026-09-12 21:50-52 UTC. Smart-contract dead-drop ETH 0x9044f5762e43b23ba91d124b51a045f1b51da652 (text(), deployer 0x34d7fb0cdd43f39ddbdbe85cd6e0688b7596e665) resolves to live C2 windowsdiagnostics.st; stage-2 served at https://windowsdiagnostics.st/api/static/loading. Detected by static analysis (bbmmd donki-vm). Host geo-fenced on AS216246 (Aeza): unreachable from some regions.