MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4b5cc2b2a50535231d7c11517892009b12a304df5ece045dd7fa308c417b6bdb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



WeedHack


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 4b5cc2b2a50535231d7c11517892009b12a304df5ece045dd7fa308c417b6bdb
SHA3-384 hash: cfc5582f0effcd7cdc8089bf778bf9e6f7b35f8379428ce7c2b82ee32b1538e8972538f8cfa98988cdbd401f55e2250c
SHA1 hash: 099bb1788104bdabf6ad54b9a54d5191858e797d
MD5 hash: eaefffc921faaedefffa2b8b51534dda
humanhash: speaker-friend-oklahoma-bulldog
File name:Beta.skeli-scamm-1.21.1-1.0.0.jar
Download: download sample
Signature WeedHack
File size:97'391 bytes
First seen:2026-04-16 21:11:09 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 1536:xKR56ea+ejwVdZ75MX5qiR/bKcwu9wHHBg6Eenzv2RdIAOZ9p3Id/0cMR8:xK5hapwLMXUiRzpmHhg6ie3k3MR8
TLSH T1F99302D55C0DA5B1EBEC8A7D507ECED26DCF2398C682FFB648D57508A071292CE1C1A2
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika jar
Reporter burger
Tags:jar WeedHack

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
Beta.skeli-scamm-1.21.1-1.0.0.jar
Verdict:
Malicious activity
Analysis date:
2026-04-16 16:57:12 UTC
Tags:
etherhiding stealer antivm

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
anti-debug obfuscated
Verdict:
Malicious
File Type:
jar
First seen:
2026-04-16T14:17:00Z UTC
Last seen:
2026-04-17T13:24:00Z UTC
Hits:
~10
Detections:
HEUR:Backdoor.Java.Generic
Result
Threat name:
n/a
Detection:
suspicious
Classification:
n/a
Score:
22 / 100
Signature
Joe Sandbox ML detected suspicious sample
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1899761 Sample: Beta.skeli-scamm-1.21.1-1.0.0.jar Startdate: 16/04/2026 Architecture: WINDOWS Score: 22 12 Joe Sandbox ML detected suspicious sample 2->12 6 cmd.exe 2 2->6         started        process3 process4 8 java.exe 3 6->8         started        10 conhost.exe 6->10         started       
Threat name:
Win32.Trojan.Kepavll
Status:
Malicious
First seen:
2026-04-16 16:57:14 UTC
File Type:
Binary (Archive)
Extracted files:
14
AV detection:
7 of 38 (18.42%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments