MB-6b5c3c3ae0da4d2207b0ebfc3d4cf03537622bf624a9753858ca8c2b1757c9e8
high
📛 Threat Title
Unknown: AstraWare-v4-.jar.github-Course23sz
Description
File type: zip. Size: 6801405 bytes. Reporter: GhostTypes. First seen: 2026-09-25 12:09:08.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
6b5c3c3ae0da4d2207b0ebfc3d4cf03537622bf624a9753858ca8c2b1757c9e8
VT 4 / 75
IOC database
- Type
- hash_sha256
- Value
6b5c3c3ae0da4d2207b0ebfc3d4cf03537622bf624a9753858ca8c2b1757c9e8- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 4 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ESET-NOD32 | malicious | Java/Agent.ADG trojan |
| Fortinet | malicious | Java/Agent.ADG!tr |
| Kaspersky | malicious | HEUR:Trojan.Java.Generic |
| Tencent | malicious | Java.Trojan.Generic.Ckjl |
Details From VirusTotal
Basic Properties
| MD5 | f8b52e51b8807afa752417cd25b15081 |
| SHA-1 | 5e0f57972f2616e262c1d0d798d395ee2fb87a12 |
| SHA-256 | 6b5c3c3ae0da4d2207b0ebfc3d4cf03537622bf624a9753858ca8c2b1757c9e8 |
| VHash | 0d598bb20d93416d2b6e226972c311ef |
| SSDEEP | 196608:CibAAaJ6o8VqssMF575Jo6Yh7g/m1moNM6bqlD:CibAAaJGsMr5lY++ZM6yD |
| TLSH | T1DB6633E1F5485020E823933845084EC37B7D93CCA95F94EE1AFDD07A9B8B9C95F5638A |
| File type | JAR |
| File type tag | jar |
| File extension | jar |
| Magic | Zip archive data, at least v2.0 to extract, compression method=deflate |
| File size | 6.5 MB |
History
| First seen on VirusTotal | 2026-09-25 14:38 UTC |
| Last submission | 2026-09-25 14:38 UTC |
| Last analysis | 2026-09-25 14:38 UTC |
| Last modified on VirusTotal | 2026-09-25 16:40 UTC |
Known Names
y6tok0lt.exeAstraWare-v4-.jar.github-Course23sz.zip
hash_sha1
5e0f57972f2616e262c1d0d798d395ee2fb87a12
VT 4 / 75
IOC database
- Type
- hash_sha1
- Value
5e0f57972f2616e262c1d0d798d395ee2fb87a12- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 4 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ESET-NOD32 | malicious | Java/Agent.ADG trojan |
| Fortinet | malicious | Java/Agent.ADG!tr |
| Kaspersky | malicious | HEUR:Trojan.Java.Generic |
| Tencent | malicious | Java.Trojan.Generic.Ckjl |
Details From VirusTotal
Basic Properties
| MD5 | f8b52e51b8807afa752417cd25b15081 |
| SHA-1 | 5e0f57972f2616e262c1d0d798d395ee2fb87a12 |
| SHA-256 | 6b5c3c3ae0da4d2207b0ebfc3d4cf03537622bf624a9753858ca8c2b1757c9e8 |
| VHash | 0d598bb20d93416d2b6e226972c311ef |
| SSDEEP | 196608:CibAAaJ6o8VqssMF575Jo6Yh7g/m1moNM6bqlD:CibAAaJGsMr5lY++ZM6yD |
| TLSH | T1DB6633E1F5485020E823933845084EC37B7D93CCA95F94EE1AFDD07A9B8B9C95F5638A |
| File type | JAR |
| File type tag | jar |
| File extension | jar |
| Magic | Zip archive data, at least v2.0 to extract, compression method=deflate |
| File size | 6.5 MB |
History
| First seen on VirusTotal | 2026-09-25 14:38 UTC |
| Last submission | 2026-09-25 14:38 UTC |
| Last analysis | 2026-09-25 14:38 UTC |
| Last modified on VirusTotal | 2026-09-25 16:40 UTC |
Known Names
y6tok0lt.exeAstraWare-v4-.jar.github-Course23sz.zip
hash_md5
f8b52e51b8807afa752417cd25b15081
VT 4 / 75
IOC database
- Type
- hash_md5
- Value
f8b52e51b8807afa752417cd25b15081- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 4 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ESET-NOD32 | malicious | Java/Agent.ADG trojan |
| Fortinet | malicious | Java/Agent.ADG!tr |
| Kaspersky | malicious | HEUR:Trojan.Java.Generic |
| Tencent | malicious | Java.Trojan.Generic.Ckjl |
Details From VirusTotal
Basic Properties
| MD5 | f8b52e51b8807afa752417cd25b15081 |
| SHA-1 | 5e0f57972f2616e262c1d0d798d395ee2fb87a12 |
| SHA-256 | 6b5c3c3ae0da4d2207b0ebfc3d4cf03537622bf624a9753858ca8c2b1757c9e8 |
| VHash | 0d598bb20d93416d2b6e226972c311ef |
| SSDEEP | 196608:CibAAaJ6o8VqssMF575Jo6Yh7g/m1moNM6bqlD:CibAAaJGsMr5lY++ZM6yD |
| TLSH | T1DB6633E1F5485020E823933845084EC37B7D93CCA95F94EE1AFDD07A9B8B9C95F5638A |
| File type | JAR |
| File type tag | jar |
| File extension | jar |
| Magic | Zip archive data, at least v2.0 to extract, compression method=deflate |
| File size | 6.5 MB |
History
| First seen on VirusTotal | 2026-09-25 14:38 UTC |
| Last submission | 2026-09-25 14:38 UTC |
| Last analysis | 2026-09-25 14:38 UTC |
| Last modified on VirusTotal | 2026-09-25 16:40 UTC |
Known Names
y6tok0lt.exeAstraWare-v4-.jar.github-Course23sz.zip
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: zip. Size: 6801405 bytes. Reporter: GhostTypes. First seen: 2026-09-25 12:09:08.
Remediations (10)
-
web:any.run
Online sandbox report for AstraWare - v4 -.jar, tagged as etherhiding, arch-exec, arch-doc, python, arch-scr, verdict: Malicious activity
-
web:any.run
Online sandbox report for astraware v4 .jar, tagged as etherhiding, stealer, weedhack, verdict: Malicious activity
-
web:astraclientorg.github.io
1.12.2 has not been released yet, and Social Features will come in v1.6.1.
-
web:astraware.com
Registration Codes If you are wanting to play our games on your old Palm OS, Pocket PC or Windows Mobile device, we have a page containing registration codes to unlock them.
-
web:github.com
astra releases and builds. Contribute to AstraClientOrg/AstraClientOrg.github.io development by creating an account on GitHub.
-
web:github.com
Maker of great games and apps for iOS and Android. GitHub is where Astraware Limited builds software.
-
web:learn.microsoft.com
Use Microsoft Defender Vulnerability Management to discover, monitor, and mitigate Log4Shell (CVE-2021-44228) exposure across your devices with security recommendations and advanced hunting.
-
web:tria.ge
Check this weedhack report astraware-1 [.]21 [.]4 [.]jar, with a score of 10 out of 10.
-
web:www.air.security
Plugin4Shell is a zero-click, high-severity RCE affecting all four major AI coding agents - Claude Code, Codex, Copilot, and Gemini. In this first-of-its-kind AI supply-chain attack, a trusted plugin is silently swapped for a malicious one and auto-installed past the agent's SHA pinning - a flaw no marketplace can fix, so users must update their agent.
-
web:www.cisa.gov
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework. Learn more about ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.