MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f7b0d34a8cd8841cf48036e4155da13d741697f5f8e83965178e5e8f1763059e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RapidStealer


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: f7b0d34a8cd8841cf48036e4155da13d741697f5f8e83965178e5e8f1763059e
SHA3-384 hash: be5e049ea87bba2641c18179498ca68a496af4675ac371bfc8cf8c7875660a096f22f59cdbd8c7fd53341bb7b500516f
SHA1 hash: b47e6b31424ff2f4ea95b58a2ed568b6f401b773
MD5 hash: 25a6f749fac33d3eee4b0bf685614f2b
humanhash: batman-king-four-oregon
File name:kittycraft-1.0.0.jar
Download: download sample
Signature RapidStealer
File size:233'095 bytes
First seen:2026-06-21 17:02:13 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 3072:iDV78Kw4F/15nP8xtNg0mXk16NWmPjE8l/1Qs9w3ctwe0RnlzTOCgW37YOZhn:iuAF/15nP8xn5QNzV+sUcBKllg8
TLSH T1A434120ABB8DE10DD93F11FB642DC7F2967447F1E10A250F3C5294A919B4B295B02AEF
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika jar
Reporter burger
Tags:jar RapidStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
120
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
kittycraft-1.0.0.jar
Verdict:
No threats detected
Analysis date:
2026-06-21 17:01:50 UTC
Tags:
arch-doc

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Clean
File Type:
jar
First seen:
2026-06-21T14:06:00Z UTC
Last seen:
2026-06-21T15:47:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
suspicious
Classification:
n/a
Score:
22 / 100
Signature
Joe Sandbox ML detected suspicious sample
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1931510 Sample: kittycraft-1.0.0.jar Startdate: 21/06/2026 Architecture: WINDOWS Score: 22 12 Joe Sandbox ML detected suspicious sample 2->12 6 cmd.exe 2 2->6         started        process3 process4 8 java.exe 3 6->8         started        10 conhost.exe 6->10         started       
Threat name:
ByteCode-JAVA.Trojan.Generic
Status:
Suspicious
First seen:
2026-06-21 17:01:53 UTC
File Type:
Binary (Archive)
Extracted files:
31
AV detection:
5 of 23 (21.74%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RapidStealer

Java file jar f7b0d34a8cd8841cf48036e4155da13d741697f5f8e83965178e5e8f1763059e

(this sample)

  
Delivery method
Distributed via web download

Comments