🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 efe7091399a8eb31effa1ebd9180fe2a68b7503ea5942a762aaa96b0b19806d0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SilentNet


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments 1

SHA256 hash: efe7091399a8eb31effa1ebd9180fe2a68b7503ea5942a762aaa96b0b19806d0
SHA3-384 hash: 809d944f93aad91c4bb98c117b6107dffa2cdc00880daa517f607e93606eabdf3dd327b1d37d508c770aca0d164fe52f
SHA1 hash: 4dd57b558fa70037cc2607f5cd13bd0cb0449a25
MD5 hash: 04125d0b21418f1c907688148b3ef35f
humanhash: wolfram-kitten-tennis-happy
File name:cheetoclient.com--CheetoClient-26.2.jar.jar
Download: download sample
Signature SilentNet
File size:1'577'454 bytes
First seen:2026-09-16 03:08:49 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 24576:fTv0ZjG6D0wQNQyFtoga+5IQ2L1tr18IjOcVpvs+5iHJG6dFe3YfzFP9j39v+0uk:8S6gwQNQEtPQ711jOqk+IHxdEINp3Ua
TLSH T167753307995CA813FCB342B4875DA3FACAC570160D84996B1DBA92318D5FFC8093CDBA
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika zip
Reporter GhostTypes
Tags:EtherHiding jar SilentNet stealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
FR FR
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
jar
Verdict:
No threats detected
Analysis date:
2026-09-16 03:52:45 UTC
Tags:
arch-exec

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Threat name:
Binary.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-14 00:02:23 UTC
File Type:
Binary (Archive)
Extracted files:
44
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

SilentNet

Java file jar efe7091399a8eb31effa1ebd9180fe2a68b7503ea5942a762aaa96b0b19806d0

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
commented on 2026-09-16 19:35:28 UTC

Distribution site: cheetoclient.com (https://cheetoclient.com/). SilentNet gen-4 github-mixin-loader fleet; nested loader built 2026-09-12 21:50-52 UTC. Smart-contract dead-drop ETH 0x9044f5762e43b23ba91d124b51a045f1b51da652 (text(), deployer 0x34d7fb0cdd43f39ddbdbe85cd6e0688b7596e665) resolves to live C2 windowsdiagnostics.st; stage-2 served at https://windowsdiagnostics.st/api/static/loading. Detected by static analysis (bbmmd donki-vm).