🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b449341fb97c5dd248f2091d92ad27d4dc32861ba5bc86deb0ccbbc627d4843e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: b449341fb97c5dd248f2091d92ad27d4dc32861ba5bc86deb0ccbbc627d4843e
SHA3-384 hash: 3198b4da06c09ebe0e91a0b8cdcd5ab587530656a2347332dbda0533ddfaeb15d0e9f4a4f4d42ac501a1fa8c3bb04847
SHA1 hash: 41c3f27f851be32e7fd5bced683b0adc75aa23b3
MD5 hash: 106bae70ce4409b563f75768b58f3b31
humanhash: nineteen-illinois-delta-fix
File name:Spoon2.jar
Download: download sample
Signature CoinMiner
File size:3'973'841 bytes
First seen:2026-10-06 15:45:12 UTC
Last seen:2026-10-06 15:51:49 UTC
File type:Java file jar
MIME type:application/zip
ssdeep 98304:gwwhCbGsIVJ8S+y+zg9QOKHmimN+AIJdGLCG7kWTM5O:gP/HVtygaOMmnN+PDDGQWwE
TLSH T17A06F123BD9AC428DE7744B7B1C28652262A1568BC0F907F03985D869B70D4F4B72FF9
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika jar
Reporter rc4
Tags:Clipper jar java runelite runelure stealer

Intelligence


File Origin
# of uploads :
2
# of downloads :
87
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
Spoon2.jar
Verdict:
Malicious activity
Analysis date:
2026-10-06 15:24:13 UTC
Tags:
ip-check evasion

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
active-directory anti-debug anti-vm hacktool obfuscated
Verdict:
Malicious
File Type:
jar
First seen:
2026-10-05T13:33:00Z UTC
Last seen:
2026-10-08T04:24:00Z UTC
Hits:
~10
Threat name:
Package.Trojan.Generic
Status:
Suspicious
First seen:
2026-10-05 18:34:33 UTC
File Type:
Package (Java)
Extracted files:
1499
AV detection:
4 of 23 (17.39%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery execution persistence privilege_escalation
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Executes a command shell one-liner
Looks up external IP address via web service
Creates a file in the Startup directory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

1c4b39bd0c5297e17eef4fe87f46826f86baecd5f5f3bc0940e3d167b444e96f

CoinMiner

Java file jar b449341fb97c5dd248f2091d92ad27d4dc32861ba5bc86deb0ccbbc627d4843e

(this sample)

  
Dropped by
SHA256 1c4b39bd0c5297e17eef4fe87f46826f86baecd5f5f3bc0940e3d167b444e96f
  
Delivery method
Distributed via web download

Comments