CLEAN — 16e153644094fbba7ec924680c2f8cb203604bee06f3a77cbddb803c147af121.jar
CLEAN — 16e153644094fbba7ec924680c2f8cb203604bee06f3a77cbddb803c147af121.jar is a jar sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (14/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
16e153644094fbba7ec924680c2f8cb203604bee06f3a77cbddb803c147af121 - SHA-1:
4b5b967a4dc6e2b3c1f1e33822c5b597814fe9d1 - MD5:
36a74261325516f07331ce6eb5db3c33 - ssdeep:
1536:IwABuAtvWci1n3d2oH4nNq8tVoRj4v7FqAtd/VpIC/XUgGp1Z+l5avN2rR:IHuAtGen9wREv7MOdpI+XqWl5aVyR - TLSH:
T1EB391293CD108527D5EE9BD091E8B8DC987E532EE8790184B625294113BE2DF835C9FC - Submitted as: 16e153644094fbba7ec924680c2f8cb203604bee06f3a77cbddb803c147af121.jar
- File type: jar · Size: 89101 bytes
- Verdict: clean (14/100)
Source: MalwareBazaar · first seen 2026-08-02T00:00:00.000Z · SHA-256 verified
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:Win32/Ravartar!rfn
- Emsisoft (Emergency Kit): Trojan.GenericKD.80909473
- Kaspersky (KVRT): HEUR:Trojan.Java.Agent.gen
Why this verdict
The clean score of 14/100 is the fusion of 1 weighted signal:
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Archive contents (7 executables)
This jar carries 7 extracted members, each analyzed as its own sample:
- byBzuei$CTAyMxzawJ1.class -
d3be60c49204c7484416c31bb0ee88178926f8634d0e22e1be6e0dd558086048 - byBzuei$LxiXVsvrCJc.class -
3d970b6a429545488551036a340aab281909bbf80a384c0266a936c98d56479c - byBzuei$hlyVmk1GKce.class -
d0068911ca1560d2c4cba74e7077fd6d3ab81ddf2972bfc7ff2ba152fdc22eaa - byBzuei.class -
9f85be9457610af4b15542446efd2ec5e45fd19d84422f2f8f3874cadf9c1d56 - dr_eslg_agxe.class -
eb21cc22d0fbb3f74124bee8b3bcaffb54810b0ef2d1445dac2f63acef81bbda - ji_lyje.class -
72000cebe3efe8c1108d720fa5e71ce595c163aab4a9fd9c88aa17c35bde1c8a - ycps_cpk.class -
8b2c749e907522d27c15d8e34dfc3a45c492a6d848f56e6d3d8fe3526fbe2d81
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report