MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d63236061e8caa4d138ee3c0ebb9a92ee1d68e3a6fae0aacfe11ce41eafad93b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: d63236061e8caa4d138ee3c0ebb9a92ee1d68e3a6fae0aacfe11ce41eafad93b
SHA3-384 hash: 99f320aefe8ef26d7d83d9db8967d18f98f3559960728d810ce39d50cf873c9266116d7160ff48334fbb866c80b34b9d
SHA1 hash: 3813e75c3cc62194039aa0f1fd4abd22b89750ab
MD5 hash: 2fafd78d5a9117fa66fd36c79a1ffd8f
humanhash: october-johnny-two-montana
File name:Cyemer-Client-Fabric-1.21.1_1.jar
Download: download sample
File size:4'808'139 bytes
First seen:2026-03-16 22:54:35 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 98304:1uQ0qomP+12p6/WWdspLFqk4RJBtE+gyCz68QZWI9I6oba5cRCv5jwi2Q:1TK124/ZGpL74bnGyCzFwu6ogcRCvBQQ
TLSH T127263373FE9ACD0CE553A333647980D2361504F5D224A27B385981D2A6F7C2717CAAEE
TrID 57.8% (.JAR) Minecraft Fabric Mod (24020/2/4)
32.5% (.JAR) Java Archive (13500/1/2)
9.6% (.ZIP) ZIP compressed archive (4000/1)
Magika jar
Reporter Giveup
Tags:contains_base64 DebuggerPattern__CPUID DebuggerPattern__RDTSC domain jar PM_Zip_with_js


Avatar
Giveup
Auto-submitted by RATScanner (score 28/100, MEDIUM)

Intelligence


File Origin
# of uploads :
1
# of downloads :
129
Origin country :
US US
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
Cyemer-Client-Fabric-1.21.1_1.jar
Verdict:
No threats detected
Analysis date:
2026-03-16 22:56:09 UTC
Tags:
java

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
macros-on-close
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments