MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 737d649e7e99b68182764de02bf075c49b141d9fd45f0d1cc2c8016b703a2672. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 2
| SHA256 hash: | 737d649e7e99b68182764de02bf075c49b141d9fd45f0d1cc2c8016b703a2672 |
|---|---|
| SHA3-384 hash: | c4760258b05bfc21e66b118c24b9106686a8c7170ad0023a1e3657bd99d92d91e72c874dd5adf7d0f1491c3f834e8c18 |
| SHA1 hash: | efa686d3c0d4a8b90b655bfebfeb8bdd596761db |
| MD5 hash: | 9ae170dec924f9c119df9ec4161d88d3 |
| humanhash: | ceiling-diet-nebraska-low |
| File name: | breezeclient.com--BreezeLoader-1.21.11.jar.jar |
| Download: | download sample |
| File size: | 1'558'879 bytes |
| First seen: | 2026-09-16 03:07:42 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/zip |
| ssdeep | 24576:zmd9yBj0WDQGQncAFFA0ag5IS+j/trX8wFqcZRtU8RSx3GkddehE1zxP9z3z3+eo:zSgwWcGQnceFZ2tXDFq6u8sxNdcK7538 |
| TLSH | T1F2753303957CBC13FCB34274474DB3A98AC9B01B0DC0DA6B5EB94661DD5EF884D289BA |
| TrID | 77.1% (.JAR) Java Archive (13500/1/2) 22.8% (.ZIP) ZIP compressed archive (4000/1) |
| Magika | zip |
| Reporter | |
| Tags: | EtherHiding jar SilentNet stealer |
Intelligence
File Origin
FRVendor Threat Intelligence
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
jar 737d649e7e99b68182764de02bf075c49b141d9fd45f0d1cc2c8016b703a2672
(this sample)
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.Distribution site: breezeclient.com (https://breezeclient.com/). SilentNet gen-4 github-mixin-loader fleet; nested loader built 2026-09-12 21:50-52 UTC. Smart-contract dead-drop ETH 0x9044f5762e43b23ba91d124b51a045f1b51da652 (text(), deployer 0x34d7fb0cdd43f39ddbdbe85cd6e0688b7596e665) resolves to live C2 windowsdiagnostics.st; stage-2 served at https://windowsdiagnostics.st/api/static/loading. Detected by static analysis (bbmmd donki-vm).