s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-6b5c3c3ae0da4d2207b0ebfc3d4cf03537622bf624a9753858ca8c2b1757c9e8 high

📛 Threat Title

Unknown: AstraWare-v4-.jar.github-Course23sz

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: zip. Size: 6801405 bytes. Reporter: GhostTypes. First seen: 2026-09-25 12:09:08.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 6b5c3c3ae0da4d2207b0ebfc3d4cf03537622bf624a9753858ca8c2b1757c9e8 VT 4 / 75

IOC database

Type
hash_sha256
Value
6b5c3c3ae0da4d2207b0ebfc3d4cf03537622bf624a9753858ca8c2b1757c9e8
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 4 of 75 VirusTotal vendors

VendorVerdictDetection
ESET-NOD32 malicious Java/Agent.ADG trojan
Fortinet malicious Java/Agent.ADG!tr
Kaspersky malicious HEUR:Trojan.Java.Generic
Tencent malicious Java.Trojan.Generic.Ckjl

Details From VirusTotal

Basic Properties
MD5f8b52e51b8807afa752417cd25b15081
SHA-15e0f57972f2616e262c1d0d798d395ee2fb87a12
SHA-2566b5c3c3ae0da4d2207b0ebfc3d4cf03537622bf624a9753858ca8c2b1757c9e8
VHash0d598bb20d93416d2b6e226972c311ef
SSDEEP196608:CibAAaJ6o8VqssMF575Jo6Yh7g/m1moNM6bqlD:CibAAaJGsMr5lY++ZM6yD
TLSHT1DB6633E1F5485020E823933845084EC37B7D93CCA95F94EE1AFDD07A9B8B9C95F5638A
File typeJAR
File type tagjar
File extensionjar
MagicZip archive data, at least v2.0 to extract, compression method=deflate
File size6.5 MB
History
First seen on VirusTotal2026-09-25 14:38 UTC
Last submission2026-09-25 14:38 UTC
Last analysis2026-09-25 14:38 UTC
Last modified on VirusTotal2026-09-25 16:40 UTC
Known Names
  • y6tok0lt.exe
  • AstraWare-v4-.jar.github-Course23sz.zip
hash_sha1 5e0f57972f2616e262c1d0d798d395ee2fb87a12 VT 4 / 75

IOC database

Type
hash_sha1
Value
5e0f57972f2616e262c1d0d798d395ee2fb87a12
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 4 of 75 VirusTotal vendors

VendorVerdictDetection
ESET-NOD32 malicious Java/Agent.ADG trojan
Fortinet malicious Java/Agent.ADG!tr
Kaspersky malicious HEUR:Trojan.Java.Generic
Tencent malicious Java.Trojan.Generic.Ckjl

Details From VirusTotal

Basic Properties
MD5f8b52e51b8807afa752417cd25b15081
SHA-15e0f57972f2616e262c1d0d798d395ee2fb87a12
SHA-2566b5c3c3ae0da4d2207b0ebfc3d4cf03537622bf624a9753858ca8c2b1757c9e8
VHash0d598bb20d93416d2b6e226972c311ef
SSDEEP196608:CibAAaJ6o8VqssMF575Jo6Yh7g/m1moNM6bqlD:CibAAaJGsMr5lY++ZM6yD
TLSHT1DB6633E1F5485020E823933845084EC37B7D93CCA95F94EE1AFDD07A9B8B9C95F5638A
File typeJAR
File type tagjar
File extensionjar
MagicZip archive data, at least v2.0 to extract, compression method=deflate
File size6.5 MB
History
First seen on VirusTotal2026-09-25 14:38 UTC
Last submission2026-09-25 14:38 UTC
Last analysis2026-09-25 14:38 UTC
Last modified on VirusTotal2026-09-25 16:40 UTC
Known Names
  • y6tok0lt.exe
  • AstraWare-v4-.jar.github-Course23sz.zip
hash_md5 f8b52e51b8807afa752417cd25b15081 VT 4 / 75

IOC database

Type
hash_md5
Value
f8b52e51b8807afa752417cd25b15081
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 4 of 75 VirusTotal vendors

VendorVerdictDetection
ESET-NOD32 malicious Java/Agent.ADG trojan
Fortinet malicious Java/Agent.ADG!tr
Kaspersky malicious HEUR:Trojan.Java.Generic
Tencent malicious Java.Trojan.Generic.Ckjl

Details From VirusTotal

Basic Properties
MD5f8b52e51b8807afa752417cd25b15081
SHA-15e0f57972f2616e262c1d0d798d395ee2fb87a12
SHA-2566b5c3c3ae0da4d2207b0ebfc3d4cf03537622bf624a9753858ca8c2b1757c9e8
VHash0d598bb20d93416d2b6e226972c311ef
SSDEEP196608:CibAAaJ6o8VqssMF575Jo6Yh7g/m1moNM6bqlD:CibAAaJGsMr5lY++ZM6yD
TLSHT1DB6633E1F5485020E823933845084EC37B7D93CCA95F94EE1AFDD07A9B8B9C95F5638A
File typeJAR
File type tagjar
File extensionjar
MagicZip archive data, at least v2.0 to extract, compression method=deflate
File size6.5 MB
History
First seen on VirusTotal2026-09-25 14:38 UTC
Last submission2026-09-25 14:38 UTC
Last analysis2026-09-25 14:38 UTC
Last modified on VirusTotal2026-09-25 16:40 UTC
Known Names
  • y6tok0lt.exe
  • AstraWare-v4-.jar.github-Course23sz.zip

References (1)

Remediations (10)

  • web:any.run

    Online sandbox report for AstraWare - v4 -.jar, tagged as etherhiding, arch-exec, arch-doc, python, arch-scr, verdict: Malicious activity

  • web:any.run

    Online sandbox report for astraware v4 .jar, tagged as etherhiding, stealer, weedhack, verdict: Malicious activity

  • web:astraclientorg.github.io

    1.12.2 has not been released yet, and Social Features will come in v1.6.1.

  • web:astraware.com

    Registration Codes If you are wanting to play our games on your old Palm OS, Pocket PC or Windows Mobile device, we have a page containing registration codes to unlock them.

  • web:github.com

    astra releases and builds. Contribute to AstraClientOrg/AstraClientOrg.github.io development by creating an account on GitHub.

  • web:github.com

    Maker of great games and apps for iOS and Android. GitHub is where Astraware Limited builds software.

  • web:learn.microsoft.com

    Use Microsoft Defender Vulnerability Management to discover, monitor, and mitigate Log4Shell (CVE-2021-44228) exposure across your devices with security recommendations and advanced hunting.

  • web:tria.ge

    Check this weedhack report astraware-1 [.]21 [.]4 [.]jar, with a score of 10 out of 10.

  • web:www.air.security

    Plugin4Shell is a zero-click, high-severity RCE affecting all four major AI coding agents - Claude Code, Codex, Copilot, and Gemini. In this first-of-its-kind AI supply-chain attack, a trusted plugin is silently swapped for a malicious one and auto-installed past the agent's SHA pinning - a flaw no marketplace can fix, so users must update their agent.

  • web:www.cisa.gov

    For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework. Learn more about ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.