🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 754f68b4cbf5957a34bbd75ed8aa3fe6091986d2edae145688479de064880c54. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SilentNet


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments 1

SHA256 hash: 754f68b4cbf5957a34bbd75ed8aa3fe6091986d2edae145688479de064880c54
SHA3-384 hash: 3493bbbff5068df752d809d6d1bb97c935da5a08fb4be61c4a5287621c7ed8b017026abf886c2811a95341a29d7f7dcd
SHA1 hash: 2d1f371750efa1965bd4de91bdf0cd46ae66003f
MD5 hash: 288c4cb991d0daf295be3190e5703593
humanhash: earth-pasta-finch-apart
File name:198-macros.com--198-Macros-Cracked-v1.4.0.jar.jar
Download: download sample
Signature SilentNet
File size:1'558'900 bytes
First seen:2026-09-16 03:07:42 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 24576:3c8Dru8DgcQ94mFrCkaS5+6en3trD8oXCcTVP0gXYn1GmdZ8Lahz5P953Zl+og5E:jS8McQ944rJUxDrXCYsgInFd2mnn3h
TLSH T11B7533069A6CA813FCF352794B4CA2E9CAC4B01A0DC4996B5E754221DD1EFD84D38DBA
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika zip
Reporter GhostTypes
Tags:EtherHiding jar SilentNet stealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
FR FR
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
jar
Verdict:
No threats detected
Analysis date:
2026-09-16 03:24:14 UTC
Tags:
arch-exec

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Threat name:
Binary.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-16 03:08:21 UTC
File Type:
Binary (Archive)
Extracted files:
34
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

SilentNet

Java file jar 754f68b4cbf5957a34bbd75ed8aa3fe6091986d2edae145688479de064880c54

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
commented on 2026-09-16 19:34:41 UTC

Distribution site: 198-macros.com (https://198-macros.com/198-Macros-Cracked-v1.4.0.jar). SilentNet gen-4 github-mixin-loader fleet; nested loader built 2026-09-12 21:50-52 UTC. Smart-contract dead-drop ETH 0x9044f5762e43b23ba91d124b51a045f1b51da652 (text(), deployer 0x34d7fb0cdd43f39ddbdbe85cd6e0688b7596e665) resolves to live C2 windowsdiagnostics.st; stage-2 served at https://windowsdiagnostics.st/api/static/loading. Detected by static analysis (bbmmd donki-vm).