🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 72d9dbf486baf38d1d14ecf4afafc8517bb66d340044d4edb29c49fc93daf11c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments 1

SHA256 hash: 72d9dbf486baf38d1d14ecf4afafc8517bb66d340044d4edb29c49fc93daf11c
SHA3-384 hash: 4253e8294b1dd5fbc5789b01e07ef311873abfb0e8f70526e73d940dc61ac61f0d28aaf05c6a2fb8e938197837d4d8f4
SHA1 hash: 5f4cfb95b31fa0eb7895a294756c0211c0adeceb
MD5 hash: a17f664c452b32dabbbe1dc6c07dd871
humanhash: single-mexico-utah-enemy
File name:sigmaclient.net--SigmaClient-Fabric-1.21.jar.jar
Download: download sample
File size:1'558'851 bytes
First seen:2026-09-16 03:08:16 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 24576:omYsLXAsDCWQDIOFPwEaM5seuZVtr78WjOc1dh06labZGedXofAHzVP9n3n1+Sct:Jws+WQDIQP5qJ7ljOeC6AbNd4IlN3ux
TLSH T11B753306966CB853FCB30275874C63A9C9C9B01B0DD0996B5EB957318D5FF880D2C9BE
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika zip
Reporter GhostTypes
Tags:EtherHiding jar SilentNet stealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
FR FR
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
jar
Verdict:
No threats detected
Analysis date:
2026-09-16 03:16:13 UTC
Tags:
arch-exec

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Java file jar 72d9dbf486baf38d1d14ecf4afafc8517bb66d340044d4edb29c49fc93daf11c

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
commented on 2026-09-16 19:38:44 UTC

Distribution site: sigmaclient.net (https://sigmaclient.net/). SilentNet gen-4 github-mixin-loader fleet; nested loader built 2026-09-12 21:50-52 UTC. Smart-contract dead-drop ETH 0x9044f5762e43b23ba91d124b51a045f1b51da652 (text(), deployer 0x34d7fb0cdd43f39ddbdbe85cd6e0688b7596e665) resolves to live C2 windowsdiagnostics.st; stage-2 served at https://windowsdiagnostics.st/api/static/loading. Detected by static analysis (bbmmd donki-vm).