MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 72d9dbf486baf38d1d14ecf4afafc8517bb66d340044d4edb29c49fc93daf11c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 2
| SHA256 hash: | 72d9dbf486baf38d1d14ecf4afafc8517bb66d340044d4edb29c49fc93daf11c |
|---|---|
| SHA3-384 hash: | 4253e8294b1dd5fbc5789b01e07ef311873abfb0e8f70526e73d940dc61ac61f0d28aaf05c6a2fb8e938197837d4d8f4 |
| SHA1 hash: | 5f4cfb95b31fa0eb7895a294756c0211c0adeceb |
| MD5 hash: | a17f664c452b32dabbbe1dc6c07dd871 |
| humanhash: | single-mexico-utah-enemy |
| File name: | sigmaclient.net--SigmaClient-Fabric-1.21.jar.jar |
| Download: | download sample |
| File size: | 1'558'851 bytes |
| First seen: | 2026-09-16 03:08:16 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/zip |
| ssdeep | 24576:omYsLXAsDCWQDIOFPwEaM5seuZVtr78WjOc1dh06labZGedXofAHzVP9n3n1+Sct:Jws+WQDIQP5qJ7ljOeC6AbNd4IlN3ux |
| TLSH | T11B753306966CB853FCB30275874C63A9C9C9B01B0DD0996B5EB957318D5FF880D2C9BE |
| TrID | 77.1% (.JAR) Java Archive (13500/1/2) 22.8% (.ZIP) ZIP compressed archive (4000/1) |
| Magika | zip |
| Reporter | |
| Tags: | EtherHiding jar SilentNet stealer |
Intelligence
File Origin
FRVendor Threat Intelligence
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
jar 72d9dbf486baf38d1d14ecf4afafc8517bb66d340044d4edb29c49fc93daf11c
(this sample)
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.Distribution site: sigmaclient.net (https://sigmaclient.net/). SilentNet gen-4 github-mixin-loader fleet; nested loader built 2026-09-12 21:50-52 UTC. Smart-contract dead-drop ETH 0x9044f5762e43b23ba91d124b51a045f1b51da652 (text(), deployer 0x34d7fb0cdd43f39ddbdbe85cd6e0688b7596e665) resolves to live C2 windowsdiagnostics.st; stage-2 served at https://windowsdiagnostics.st/api/static/loading. Detected by static analysis (bbmmd donki-vm).