MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 b6a1855faf4e23f9967192dcd6dfd2cf022c9b9f8ab5061edfc28a442b3e5c36. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 2
| SHA256 hash: | b6a1855faf4e23f9967192dcd6dfd2cf022c9b9f8ab5061edfc28a442b3e5c36 |
|---|---|
| SHA3-384 hash: | 2ba975cd4683c5f20832070a13dac644fbe99ab0290db8c0f95da562345db05a91a869b0a750b787e397acbc956463e6 |
| SHA1 hash: | cf28a8ca6caa69c55dd0b9e6dbba902834d81e14 |
| MD5 hash: | 43d8ea99ecbcaa694b75703027b4a0f3 |
| humanhash: | winner-rugby-august-paris |
| File name: | ghostclient.net--GhostClient-26.2.jar.jar |
| Download: | download sample |
| File size: | 1'577'451 bytes |
| First seen: | 2026-09-16 03:09:21 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/zip |
| ssdeep | 24576:+SQ0rja0DisQ162FR8sas54YYjptrH8Kj0ctjBKCh+LRG2dxod+tzLP9P3DZ+6cy:+SG0+sQ16oRNmHHPj0wYCELRd6Y513OA |
| TLSH | T15F7533039A6CA813FCB342744A9D73FBC9C570170D84996B4DBA97218D5BFC84E389B6 |
| TrID | 77.1% (.JAR) Java Archive (13500/1/2) 22.8% (.ZIP) ZIP compressed archive (4000/1) |
| Magika | zip |
| Reporter |
Intelligence
File Origin
FRVendor Threat Intelligence
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
jar b6a1855faf4e23f9967192dcd6dfd2cf022c9b9f8ab5061edfc28a442b3e5c36
(this sample)
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.