🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f96bed16099b7fc1d010dfb44d8871e6652fe1ae2c296ce9d6e1ce7eaa74b793. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SilentNet


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments 1

SHA256 hash: f96bed16099b7fc1d010dfb44d8871e6652fe1ae2c296ce9d6e1ce7eaa74b793
SHA3-384 hash: 236fe8e008a7044497cf42a4b958d9cf97ee9d2232d5f0782095cc2a017f61317e55a123f5b1580da1e183fec8791e42
SHA1 hash: 244221ff7dd1629be9c4705f9ef89d6ccb1f94d8
MD5 hash: d198a6c2ca5508af2eef39a7f524f5a0
humanhash: finch-wolfram-maryland-louisiana
File name:luminexclient.net--luminex-client-26.2.jar.jar
Download: download sample
Signature SilentNet
File size:1'577'447 bytes
First seen:2026-09-16 03:09:21 UTC
Last seen:Never
File type:Java file jar
MIME type:application/zip
ssdeep 24576:L8eNjYiDmkQHceFnaYak5Ei4FJtr58EjccZxziwRWLnGKdNIbC5zlP9d3RN+iIni:L9UiykQHcAnXwR5NjcyOwsL/dOeTL3Kc
TLSH T188753317966CA413FCB34274874DB3FA8EC970160D88996B5EB657218C5FFC80E2C9B6
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika zip
Reporter GhostTypes
Tags:EtherHiding jar SilentNet

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
FR FR
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
jar
Verdict:
No threats detected
Analysis date:
2026-09-16 03:42:15 UTC
Tags:
arch-exec

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Threat name:
Binary.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-16 03:10:43 UTC
File Type:
Binary (Archive)
Extracted files:
44
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments



Avatar
commented on 2026-09-16 19:37:21 UTC

Distribution site: luminexclient.net (https://luminexclient.net/luminex-client-1.21.4-beta.jar). SilentNet gen-4 github-mixin-loader fleet; nested loader built 2026-09-12 21:50-52 UTC. Smart-contract dead-drop ETH 0x9044f5762e43b23ba91d124b51a045f1b51da652 (text(), deployer 0x34d7fb0cdd43f39ddbdbe85cd6e0688b7596e665) resolves to live C2 windowsdiagnostics.st; stage-2 served at https://windowsdiagnostics.st/api/static/loading. Detected by static analysis (bbmmd donki-vm).