MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 54954314f1a5f5dbbfbdaf301c7e301f7b6ebec940d84b9979f8d84f936480f6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SilentNet


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: 54954314f1a5f5dbbfbdaf301c7e301f7b6ebec940d84b9979f8d84f936480f6
SHA3-384 hash: 21ff2c851836dbb09999050a203d9d07f3cdafdc90929ca606a9c9b30da4c2d809cc51bfa148fcf3d85ad8cf96d9f7bb
SHA1 hash: c7a72caf4f8ce7364727a18eaffbeb143c059a45
MD5 hash: 7759d943192d2df2542c0a62496a3c63
humanhash: vermont-spaghetti-cola-nebraska
File name:KryptonCracked-1.21+.jar
Download: download sample
Signature SilentNet
File size:612'306 bytes
First seen:2026-07-27 10:01:48 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 12288:ZXnw3irELtKQf9ISWNXP7tOkP/2CkdqvMZ2A4S3agjff8WORlYJ:ZXw3ir4EANWd7tOokdqkZt4SAD4
TLSH T17AD42363CE97841EE93F6A3642CA8609369BF861C312AC50A5F0768E0975F9DF7D3181
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika jar
Reporter burger
Tags:jar SilentNet

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
jar
Verdict:
Malicious activity
Analysis date:
2026-07-27 10:05:43 UTC
Tags:
silentnet stealer python arch-exec arch-doc openssl tool

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Threat name:
SilentNet
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Creates a thread in another existing process (thread injection)
Exploit detected, runtime environment starts unknown processes
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for submitted file
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sigma detected: Rare Remote Thread Creation By Uncommon Source Image
Suricata IDS alerts for network traffic
Tries to harvest and steal browser information (history, passwords, etc)
Unusual module load detection (module proxying)
Writes to foreign memory regions
Yara detected SilentNet
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1948267 Sample: KryptonCracked-1.21+.jar Startdate: 27/07/2026 Architecture: WINDOWS Score: 100 81 pypi.org 2->81 83 files.pythonhosted.org 2->83 85 2 other IPs or domains 2->85 103 Suricata IDS alerts for network traffic 2->103 105 Multi AV Scanner detection for submitted file 2->105 107 Yara detected SilentNet 2->107 109 4 other signatures 2->109 12 cmd.exe 1 2->12         started        signatures3 process4 process5 14 java.exe 5 12->14         started        16 conhost.exe 12->16         started        process6 18 javaw.exe 884 14->18         started        dnsIp7 87 132.145.155.63, 443, 49714 ORACLE-BMC-31898-OracleCorporationUS United States 18->87 89 198.178.224.35, 443, 49712, 49724 LATITUDE-SH-LatitudeshUS United States 18->89 91 185.178.208.191, 443, 49717, 49721 DDOS-GUARDRU Russia 18->91 49 C:\Users\user\AppData\Local\...\python.exe, PE32+ 18->49 dropped 51 C:\Users\user\AppData\Local\...\winsound.pyd, PE32+ 18->51 dropped 53 C:\Users\user\AppData\...\vcruntime140_1.dll, PE32+ 18->53 dropped 55 623 other files (none is malicious) 18->55 dropped 22 python.exe 213 18->22         started        file8 process9 dnsIp10 93 150.136.141.142, 443, 49726 ORACLE-BMC-31898-OracleCorporationUS United States 22->93 95 151.101.0.223, 443, 49730 FASTLY-FastlyIncUS Canada 22->95 97 3 other IPs or domains 22->97 57 C:\Users\user\AppData\...\tmph_5akf13.tmp, PE32+ 22->57 dropped 59 C:\Users\user\AppData\Local\...\winsound.pyd, PE32+ 22->59 dropped 61 C:\Users\user\AppData\...\vcruntime140_1.dll, PE32+ 22->61 dropped 63 30 other files (none is malicious) 22->63 dropped 111 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 22->111 113 Tries to harvest and steal browser information (history, passwords, etc) 22->113 115 Writes to foreign memory regions 22->115 117 2 other signatures 22->117 27 python.exe 1088 22->27         started        31 pip.exe 22->31         started        33 conhost.exe 22->33         started        35 chrome.exe 22->35         started        file11 signatures12 process13 dnsIp14 101 pypi.org 151.101.128.223, 443, 49738, 49739 FASTLY-FastlyIncUS Canada 27->101 73 C:\Users\user\AppData\Local\...\pip3.exe, PE32+ 27->73 dropped 75 C:\Users\user\AppData\Local\...\pip3.12.exe, PE32+ 27->75 dropped 77 C:\Users\user\AppData\Local\...\pip.exe, PE32+ 27->77 dropped 79 378 other files (none is malicious) 27->79 dropped 37 conhost.exe 27->37         started        39 cmd.exe 27->39         started        41 python.exe 31->41         started        45 conhost.exe 31->45         started        file15 process16 dnsIp17 99 151.101.64.223, 443, 49747 FASTLY-FastlyIncUS Canada 41->99 65 95ad9cf1790ae51303...729f24d.body (copy), Python 41->65 dropped 67 750721289c257d7ef1...c2c8a0f.body (copy), Python 41->67 dropped 69 49583e7972e864a609...ef5e4e7.body (copy), Python 41->69 dropped 71 17 other files (none is malicious) 41->71 dropped 47 cmd.exe 41->47         started        file18 process19
Result
Malware family:
silentnet
Score:
  10/10
Tags:
family:silentnet stealer
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:RANSOMWARE
Author:ToroGuitar

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments