MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8e1a49fcf2383b31cc172ea86e1b3661e006b6882f32e1beefb0dd9dfb6c1790. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments 1

SHA256 hash: 8e1a49fcf2383b31cc172ea86e1b3661e006b6882f32e1beefb0dd9dfb6c1790
SHA3-384 hash: b234456530b64f1c4525229996e0f66ca0fbdaed5aae0d0cf7ef234f506d03ac0d347c2103d90445fc00bd8e774c49ac
SHA1 hash: 0bbf95b353dfb108a0f42d4edb3c03e359a0232c
MD5 hash: ee885be1526612eea6170f2b41f855d5
humanhash: triple-magazine-nevada-avocado
File name:bd73841f8314.jar
Download: download sample
File size:26'445'300 bytes
First seen:2026-08-07 11:43:42 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 786432:NJM1u257AJXgufCtY94Ngh38hUKcm8Eo01ZVbZO0G2:HM1j0tgOIg4NgShFo01rdT
TLSH T1B4473326BDEAE938D85745BF99C2C152712A1ADEE80FC02F0EE009854D75D4A431AFFD
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika jar
Reporter Anonymous
Tags:IRAHook jar RAT stealer


Avatar
Anonymous
IRAHook RAT. This payload is dropped by an Electron application delivered through mostly Discord-distributed phishing campaigns. The Electron App launches it with "javaw -cp /path/to/jar V" via an embedded JRE. It contacts ocalp.lol for C2, injects malicious code into Discord Clients and Crypto Wallets. Then it opens a websocket to hxxps://ocalp.lol/ws to receive attacker commands, takes a screenshot, and sends stolen data to hxxps://ocalp.lol/babayla/zor/yarisirlar/ (XOR + base64 encoded. XOR Key: bravo-bunu-bularak-ananin-gotunden-sikilmesini-engelledin) using Discord webhook-style formatting.

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
jar
Verdict:
No threats detected
Analysis date:
2026-08-07 11:45:18 UTC
Tags:
evasion

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments



Avatar
commented on 2026-08-07 11:43:43 UTC

IRAHook RAT. This payload is dropped by an Electron application delivered through mostly Discord-distributed phishing campaigns. The Electron App launches it with "javaw -cp /path/to/jar V" via an embedded JRE. It contacts ocalp.lol for C2, injects malicious code into Discord Clients and Crypto Wallets. Then it opens a websocket to hxxps://ocalp.lol/ws to receive attacker commands, takes a screenshot, and sends stolen data to hxxps://ocalp.lol/babayla/zor/yarisirlar/ (XOR + base64 encoded. XOR Key: bravo-bunu-bularak-ananin-gotunden-sikilmesini-engelledin) using Discord webhook-style formatting.