MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 db82da00eda13f472d231374d0d6f7bc43e913dde50a1d6ec4ee723d930b99a8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SilentNet


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: db82da00eda13f472d231374d0d6f7bc43e913dde50a1d6ec4ee723d930b99a8
SHA3-384 hash: da966263b2a0c9db756632572c34f8fa0018067c574a8fb28d707c5d72f1270633b5eaf505c81de5c405e05816360fb2
SHA1 hash: a36cbddabba301b33c521fee08a8ea7ac37d9ce9
MD5 hash: 98db820fbd497d37e1015efbe53c875c
humanhash: quiet-ceiling-wisconsin-social
File name:NopushAna.jar
Download: download sample
Signature SilentNet
File size:8'674'897 bytes
First seen:2026-07-14 14:35:28 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 196608:jpVq8ePYhsYIHIAVIqMkaZsAvyK+z6rAFN3Km/e60lu:jp3ePxpIRkaZs0EzCAFN3XV0lu
TLSH T1F2963382B25736A4043F6D101D0B7A04DA77D096D6899B36601F27EA862F8F0877DAF7
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika jar
Reporter burger
Tags:jar SilentNet

Intelligence


File Origin
# of uploads :
1
# of downloads :
159
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
jar
First seen:
2026-07-14T00:04:00Z UTC
Last seen:
2026-07-16T09:30:00Z UTC
Hits:
~10
Result
Threat name:
SilentNet
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Creates a thread in another existing process (thread injection)
Exploit detected, runtime environment starts unknown processes
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for submitted file
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sigma detected: Rare Remote Thread Creation By Uncommon Source Image
Suricata IDS alerts for network traffic
Tries to harvest and steal browser information (history, passwords, etc)
Unusual module load detection (module proxying)
Writes to foreign memory regions
Yara detected SilentNet
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1942301 Sample: NopushAna.jar Startdate: 14/07/2026 Architecture: WINDOWS Score: 100 79 thisisafalsepositive.st 2->79 81 pypi.org 2->81 83 3 other IPs or domains 2->83 97 Suricata IDS alerts for network traffic 2->97 99 Multi AV Scanner detection for submitted file 2->99 101 Yara detected SilentNet 2->101 103 4 other signatures 2->103 12 cmd.exe 1 2->12         started        signatures3 process4 process5 14 java.exe 5 12->14         started        16 conhost.exe 12->16         started        process6 18 javaw.exe 884 14->18         started        dnsIp7 85 150.136.141.142, 443, 49688, 49709 ORACLE-BMC-31898-OracleCorporationUS United States 18->85 87 198.178.224.35, 443, 49686, 49707 LATITUDE-SH-LatitudeshUS United States 18->87 89 thisisafalsepositive.st 185.178.208.191, 443, 49690, 49704 DDOS-GUARDRU Russia 18->89 47 C:\Users\user\AppData\Local\...\python.exe, PE32+ 18->47 dropped 49 C:\Users\user\AppData\Local\...\winsound.pyd, PE32+ 18->49 dropped 51 C:\Users\user\AppData\...\vcruntime140_1.dll, PE32+ 18->51 dropped 53 623 other files (none is malicious) 18->53 dropped 22 python.exe 217 18->22         started        file8 process9 dnsIp10 91 pypi.org 151.101.192.223, 443, 49713, 49730 FASTLY-FastlyIncUS Canada 22->91 93 151.101.64.175, 443, 49719 FASTLY-FastlyIncUS Canada 22->93 95 2 other IPs or domains 22->95 63 C:\Users\user\AppData\...\tmpkil2_kt_.tmp, PE32+ 22->63 dropped 65 C:\Users\user\AppData\Local\...\winsound.pyd, PE32+ 22->65 dropped 67 C:\Users\user\AppData\...\vcruntime140_1.dll, PE32+ 22->67 dropped 69 32 other files (none is malicious) 22->69 dropped 105 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 22->105 107 Tries to harvest and steal browser information (history, passwords, etc) 22->107 109 Writes to foreign memory regions 22->109 111 2 other signatures 22->111 27 pip.exe 22->27         started        29 python.exe 1088 22->29         started        32 python.exe 22->32         started        34 2 other processes 22->34 file11 signatures12 process13 file14 36 python.exe 27->36         started        39 conhost.exe 27->39         started        71 C:\Users\user\AppData\Local\...\pip3.exe, PE32+ 29->71 dropped 73 C:\Users\user\AppData\Local\...\pip3.12.exe, PE32+ 29->73 dropped 75 C:\Users\user\AppData\Local\...\pip.exe, PE32+ 29->75 dropped 77 378 other files (none is malicious) 29->77 dropped 41 conhost.exe 29->41         started        43 conhost.exe 32->43         started        process15 file16 55 C:\Users\user\AppData\Local\...\wsdump.exe, PE32+ 36->55 dropped 57 C:\Users\user\AppData\...\cffi-gen-src.exe, PE32+ 36->57 dropped 59 C:\Users\user\AppData\Local\...\win32wnet.pyd, PE32+ 36->59 dropped 61 520 other files (none is malicious) 36->61 dropped 45 cmd.exe 36->45         started        process17
Threat name:
Win32.Trojan.Ravartar
Status:
Malicious
First seen:
2026-07-13 17:57:31 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Result
Malware family:
silentnet
Score:
  10/10
Tags:
family:silentnet stealer
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:RANSOMWARE
Author:ToroGuitar

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments