MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 867f9c1d5a6ddec8565c7fdd4a83d7f84c9ec54cc822bb836e1ee7cde396ca5d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 867f9c1d5a6ddec8565c7fdd4a83d7f84c9ec54cc822bb836e1ee7cde396ca5d
SHA3-384 hash: 1f41fdcfdbdfa93ff12f78de611ecbca99d271d959402a156f95f27fd02af1fc82e8c3ebcd464a13dc5c363b5ba7cbfb
SHA1 hash: 3e40f8cc45f4b508f0ca991f1eaa5a3a59bf2e4e
MD5 hash: 8906e3de4d19bc2efc93357f8912240c
humanhash: happy-foxtrot-michigan-red
File name:Iris-Installer-3.2.1-protected.jar
Download: download sample
File size:2'129'783 bytes
First seen:2026-03-16 04:49:58 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 49152:Hn/cPUV+35bCRvqtV4amnQtHJ75LbH6sZvZwHGBr:H0PqgC5VnQ1BQ63
TLSH T1BFA5F1167EE2C4F8F013F3754182C15BD91A0EFC9A06B46B0DA4AD8DE421D8A571BBED
TrID 46.1% (.JAR) Minecraft Fabric Mod (24020/2/4)
25.9% (.JAR) Java Archive (13500/1/2)
20.1% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
7.6% (.ZIP) ZIP compressed archive (4000/1)
Magika jar
Reporter Giveup
Tags:jar


Avatar
Giveup
Auto-submitted by RATScanner (score 23/100, LOW)

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
_867f9c1d5a6ddec8565c7fdd4a83d7f84c9ec54cc822bb836e1ee7cde396ca5d.zip
Verdict:
No threats detected
Analysis date:
2026-03-16 04:50:56 UTC
Tags:
java

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
anti-debug expand lolbin macros-on-close obfuscated
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Verdict:
Malicious
File Type:
jar
Detections:
HEUR:Trojan.Java.Agent.gen
Threat name:
Package.Trojan.Generic
Status:
Suspicious
First seen:
2026-03-16 04:50:37 UTC
File Type:
Package (Java)
Extracted files:
882
AV detection:
3 of 24 (12.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Contacts third-party web service commonly abused for C2
Loads dropped DLL
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments