🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 88cd0f5f6f0ed0780b450cc53f18136cb3f8245aef432e563ca30b6ec30bbfc6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SilentNet


Vendor detections: 5


Intelligence 5 IOCs YARA 3 File information Comments 1

SHA256 hash: 88cd0f5f6f0ed0780b450cc53f18136cb3f8245aef432e563ca30b6ec30bbfc6
SHA3-384 hash: 21632c4dd009397152b3e82021c6090c744636e68f36e323c30a3dbfb9089ba964d92a8266ca3332becfc4ef9ed4529e
SHA1 hash: d9a5c124433a06c79a05395ef3da3ddd3c7c730b
MD5 hash: 4e9d03120fbf22907879c9328a07f6da
humanhash: tennis-three-triple-football
File name:python312-runtime-apphost.zip
Download: download sample
Signature SilentNet
File size:16'677'521 bytes
First seen:2026-09-17 00:03:04 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 393216:PXMCHWUjetodaI8pEB1bSEKhmR44t0Mc933zqv80:PXMb8etDIDhKhmh+N933zCZ
TLSH T132F63333C85653B7DADB9D321EF66D2B050EE16A7A1799DBBFA026503C331DA0127C09
TrID 26.9% (.PYZ) Python Zip Application (10500/1/1)
26.9% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
20.5% (.XPI) Mozilla Firefox browser extension (8000/1/1)
15.3% (.USDZ) Universal Scene Description Zipped AR format (generic) (6000/1/1)
10.2% (.ZIP) ZIP compressed archive (4000/1)
Magika zip
Reporter GhostTypes
Tags:EtherHiding SilentNet zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
126
Origin country :
US US
Vendor Threat Intelligence
Verdict:
Malware
YARA:
3 match(es)
Tags:
COM Behavior Trace DeObfuscated Executable Obfuscated PDB Path PE (Portable Executable) PE File Layout Python.Dictionary Python.PerfmonQuery T1027 T1059.005 VBScript Zip Archive
Result
Malware family:
n/a
Score:
  6/10
Tags:
evasion execution pdf
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

SilentNet

zip 88cd0f5f6f0ed0780b450cc53f18136cb3f8245aef432e563ca30b6ec30bbfc6

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
commented on 2026-09-17 00:03:12 UTC

SilentNet stage-3 bundle: Fernet-decrypted payload of https://thisisafalsepositive.st/cdn/e/3b8f6d2a9c1e (key dK9mT3nR7xQ2pL8wF4jH6yB1cN5gA0sZ12345678abc=). Pre-built Python 3.12 embeddable runtime with site-packages (requests, pycryptodome, psutil, pywin32, wmi, vdf, PIL) and AppHost/app.pyd (sha256 1280ff5f2c4a59e8a9301d8e2eb7c2e9774ec6026a48905c52d23fb1974438bf, Nuitka stealer) + AppHost/main.py loader. Not a JRE.