MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cee20b0ab5a4f45984e8692355fd73082c52120875101bd3ff87d07c82646ee7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SilentNet


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: cee20b0ab5a4f45984e8692355fd73082c52120875101bd3ff87d07c82646ee7
SHA3-384 hash: d242e7049f56d0ac2122e10260762be4b655810f04fee10de81d4c9fb12679983fa83694d12f26f09e31bc7f3ac827ee
SHA1 hash: 3405920f9737f5526176bd5f7808a939b8f45621
MD5 hash: b8bf1f89d0d89c1e8f0a8af92b34afa8
humanhash: monkey-william-sixteen-robin
File name:Krypton.jar
Download: download sample
Signature SilentNet
File size:6'185'180 bytes
First seen:2026-06-22 12:34:49 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 98304:72XBrokwVgCXeEpiOQGWc8IQYrc16j5E0iGcPg/lIDAsXJoEiVQIUize8Tk7wf:YegCupOQ/+QR16j5E0b4guROXpzp5
TLSH T169562378D37E7176C98F3E304A0766CF27D6528AD6103D4F2A721B65BA0F2906731BA4
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika jar
Reporter burger
Tags:jar SilentNet

Intelligence


File Origin
# of uploads :
1
# of downloads :
108
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
Krypton.jar
Verdict:
Malicious activity
Analysis date:
2026-06-22 12:34:41 UTC
Tags:
etherhiding silentnet stealer python evasion arch-exec openssl tool arch-doc

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
File Type:
jar
Detections:
HEUR:Trojan.Java.Generic
Result
Threat name:
n/a
Detection:
suspicious
Classification:
n/a
Score:
23 / 100
Signature
Joe Sandbox ML detected suspicious sample
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1931787 Sample: Krypton.jar Startdate: 22/06/2026 Architecture: WINDOWS Score: 23 12 Joe Sandbox ML detected suspicious sample 2->12 6 cmd.exe 2 2->6         started        process3 process4 8 java.exe 3 6->8         started        10 conhost.exe 6->10         started       
Result
Malware family:
silentnet
Score:
  10/10
Tags:
family:silentnet adware persistence ransomware spyware stealer
Behaviour
Checks SCSI registry key(s)
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Uses Volume Shadow Copy WMI provider
Uses Volume Shadow Copy service COM API
Enumerates connected drives
Boot or Logon Autostart Execution: Active Setup
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

SilentNet

Java file jar cee20b0ab5a4f45984e8692355fd73082c52120875101bd3ff87d07c82646ee7

(this sample)

  
Delivery method
Distributed via web download

Comments