🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4d00bb086743546c31cfef1815f4e15b13559537699af7ac8ec64db3815a7404. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 5 File information Comments

SHA256 hash: 4d00bb086743546c31cfef1815f4e15b13559537699af7ac8ec64db3815a7404
SHA3-384 hash: 48f14354f6ba90fe4e32b7e2cc25ce0df4e1c5e5ff88d35ca9574e9379c606ac2cfb25d6733f96ef4b6333bb7396dc36
SHA1 hash: 403d5f55e7fef94500009e60599c65118a3a87b3
MD5 hash: 23324b2bd2cda369b51b0a34d15c99b4
humanhash: twelve-gee-four-butter
File name:4d00bb086743546c.bin
Download: download sample
File size:1'584'465 bytes
First seen:2026-10-06 07:24:16 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:e7+ZbyADoAUja4Fz6EGE5KKox5tPTcm/0c/7n2U3W/bKkdJQlI5zfPR33FZUoWc5:5WAMAUjamzvEhTV/0M2Um/TdGC913Kw
TLSH T19B753306AA6CE413FCA342B4878DB3BAC5C570570E848E7B5E7592218D5FFD40F28A76
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika jar
Reporter whack_sh
Tags:zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
31
Origin country :
US US
File Archive Information

This file archive contains 19 file(s), sorted by their relevance:

File name:HudMixin.class
File size:12'162 bytes
SHA256 hash: d0edb9a27e794f808d056abac5f64841e0e008138d73d2b11fe85a46be303046
MD5 hash: b8913232e673cbe13297a382141166f2
MIME type:application/x-java-applet
File name:ModMenuIntegration.class
File size:1'303 bytes
SHA256 hash: 7ed0e677a0e0d45fa45a0c0eada8140467c42cce024047b8372d4a4437c86304
MD5 hash: 7c9f2d7f0ae9a03f4accbbbd8b7b1db5
MIME type:application/x-java-applet
File name:MANIFEST.MF
File size:346 bytes
SHA256 hash: fef16c0a8c2facf4c28871bdcc1e1a87bddbfbdb8c73bc47f285c308db7c36ad
MD5 hash: ce800052a7e57f05484b10d35efe3438
MIME type:text/plain
File name:Anchor$2.class
File size:846 bytes
SHA256 hash: 6bc3aa80786265158d45d960cac15f52d3febb03223771046f4f87b8575ad5a4
MD5 hash: d809cb89c6574158e9b2c39e91fb78b1
MIME type:application/x-java-applet
File name:VisualsType.class
File size:1'273 bytes
SHA256 hash: 459ab0bbc107e3f3dc8b487854478d40d2b8a98313e6aa58b22a2cba0efdba64
MD5 hash: 6013dc3c953f8d04fe7287948a9259a6
MIME type:application/x-java-applet
File name:en_us.json
File size:3'611 bytes
SHA256 hash: 4c77bd4d2eac48c99cdc8721732f92d80139c2a52f7c66c9746a4ee79e2ae913
MD5 hash: 31f8c01836179839d8b310edce8faae9
MIME type:application/json
File name:SprintConfig.class
File size:3'444 bytes
SHA256 hash: 79ba4bee16a15605c5104137e29646d19f766b328ddc74506e0b718aee594cc9
MD5 hash: 712e1d2eed08c3704394e538240f52bd
MIME type:application/x-java-applet
File name:Anchor$1.class
File size:673 bytes
SHA256 hash: ee17f2b43642969d1e3d8ab659ca9c8b8472dbf79e0e3601ded417b85916a869
MD5 hash: 21f32bdaff940c316b978a51656b168a
MIME type:application/x-java-applet
File name:github-mixin-loader-2.1.2-obfuscated.jar
File size:1'559'885 bytes
SHA256 hash: 89ea935ecb1f973315921058d6f66f4e3800d0ab89faeb1b814289f767de3bbb
MD5 hash: 8de65f6115aef89223495155867b8be4
MIME type:application/java-archive
File name:HudMixin$1.class
File size:879 bytes
SHA256 hash: 46682d4a9ff47c5b81838e379d1e234a9cd00127aa200d03bd7f896fe419dc54
MD5 hash: f957ac8bf367f3ef459d88b0e4ff697d
MIME type:application/x-java-applet
File name:Anchor$4.class
File size:927 bytes
SHA256 hash: 6a445462925e39ae066a19690424caa3d99ba9e5e48381d539f1e1fb805a8c96
MD5 hash: 318f978d2d5e04958e075bc7a67e3523
MIME type:application/x-java-applet
File name:SprintOptions.class
File size:13'045 bytes
SHA256 hash: ee9b0458299fa9414779fa3771b88e570ab484114f5261068e11f4384520d672
MD5 hash: 9fbe145f4526307ac865485e653ffba7
MIME type:application/x-java-applet
File name:Anchor.class
File size:1'897 bytes
SHA256 hash: 06f4914469d8c523925ec07bda764693c7523d33a0b8d4f109667b6efe364b6b
MD5 hash: c279300f50939d4ea8f9705ef0de7ede
MIME type:application/x-java-applet
File name:icon.png
File size:6'312 bytes
SHA256 hash: 429b3cc4b15868de72a3aec6118b8e1a82fe84e56b6735095dc62fad6d5ec3c3
MD5 hash: 3c273febce9d9066b9a6e564ee71bf74
MIME type:image/png
File name:LICENSE_toggle-sprint-display
File size:7'815 bytes
SHA256 hash: f831e7eed577481687a9bc0b48024e5e40b6f655fcde073ede964b50be5d55d9
MD5 hash: cc46e3e9ef97cbdc56318ee7ff23d73e
MIME type:text/plain
File name:SettingsScreen.class
File size:2'015 bytes
SHA256 hash: f779791fecff79682674a5f5c3a36d1fea4e47bba771c069a0182c808e0ce99b
MD5 hash: ef1b61cd7e34e20a2b084dd2b25aef75
MIME type:application/x-java-applet
File name:toggle-sprint-display.mixins.json
File size:248 bytes
SHA256 hash: 1dbc5e081641a45fa26bc17d3524a9722c61d18e24600617db766ea914b78f8f
MD5 hash: c393dd759e7e4881780a798ba6321b8c
MIME type:text/plain
File name:fabric.mod.json
File size:688 bytes
SHA256 hash: a48ef58368f32eb980cb92673e29d62cdff682480bcf2f14d5d8d86a81d7e80c
MD5 hash: 6d34ba869a4b5e8ceef1042224a92777
MIME type:text/plain
File name:Anchor$3.class
File size:847 bytes
SHA256 hash: c28d2e950f7fa55c545e4b23ae4c4f67e6880df9109966fc7d5394e2e2fa781d
MD5 hash: 80ed04cf29e10100506718b8f0e31536
MIME type:application/x-java-applet
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
masquerade
Verdict:
Unknown
File Type:
jar
First seen:
2026-09-24T09:59:00Z UTC
Last seen:
2026-10-07T01:41:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Zip Archive
Threat name:
Win32.Trojan.Ravartar
Status:
Malicious
First seen:
2026-09-19 19:23:51 UTC
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ANDROID_Sample_Unique_2599c5a6
Author:Marjoriefort
Description:Specimen unique (soumission Bazaar) - strings distinctifs propres au sample
Reference:2599c5a6191bc208c4f0f1fcafba81b0f8d4099de6dc8d64ee7aec0b5289833e.jar
Rule name:JAVA_Malware_Unknown_ForgeAuto_90eece6c_Extrait
Author:Marjoriefort
Description:Detects Unknown (class, etat extrait)
Rule name:MULTI_Malware_Unknown_ForgeAuto_6dc545a6
Author:Marjoriefort
Description:Detects Unknown (inconnu, etat binaire)
Rule name:MULTI_Malware_Unknown_ForgeAuto_b2a4008d
Author:Marjoriefort
Description:Detects Unknown (inconnu, etat binaire)
Rule name:MULTI_PUA_ToggleSprintMod_MassSubmit
Author:Marjoriefort
Description:Mod Minecraft toggle-sprint-display (com.aeltumn) soumis en masse - pattern anormal + mixin-loader obfusque, PUA a confirmer
Reference:misses_archive 569 / grappe 39 archives identiques

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

zip 4d00bb086743546c31cfef1815f4e15b13559537699af7ac8ec64db3815a7404

(this sample)

  
Delivery method
Distributed via web download

Comments