MB-1af3c5d99b48516ad0424d0441075c3209a7dcbe42ce78bfec8958c181e2f0a2
high
📛 Threat Title
Unknown: calcium-.jar.github-Course23sz
Description
File type: zip. Size: 253103 bytes. Reporter: GhostTypes. First seen: 2026-09-25 12:09:29.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
1af3c5d99b48516ad0424d0441075c3209a7dcbe42ce78bfec8958c181e2f0a2
VT 5 / 75
IOC database
- Type
- hash_sha256
- Value
1af3c5d99b48516ad0424d0441075c3209a7dcbe42ce78bfec8958c181e2f0a2- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 5 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ESET-NOD32 | malicious | Java/Agent.ADG trojan |
| Fortinet | malicious | Java/Agent.ADG!tr |
| Ikarus | malicious | Win32.Outbreak |
| Kaspersky | malicious | HEUR:Trojan.Java.Generic |
| Tencent | malicious | Java.Trojan.Generic.Vmhl |
Details From VirusTotal
Basic Properties
| MD5 | 1c511777a20d65303f1634ff10c87105 |
| SHA-1 | 0b461c532a2df39cbbf5032f24dacf4e982b9793 |
| SHA-256 | 1af3c5d99b48516ad0424d0441075c3209a7dcbe42ce78bfec8958c181e2f0a2 |
| VHash | b0ed1f22b8529993e99f17a74dc4bf39 |
| SSDEEP | 3072:GvVbB771jQA9SxqKbKb/qEIUBixNvm5UO6/7JS3fvxfmBdYOfiIE2rHsCRYySFZB:AVB79BtKbaqEIU4/Bd1MYBdbvRdSdf |
| TLSH | T124340127A16C0932DC1F9771A792E872A47C65D0B10D340B43F8989698C35DF1F96BEE |
| File type | JAR |
| File type tag | jar |
| File extension | jar |
| Magic | Zip archive data, at least v2.0 to extract, compression method=deflate |
| File size | 247.2 KB |
History
| First seen on VirusTotal | 2026-09-25 14:38 UTC |
| Last submission | 2026-09-25 14:38 UTC |
| Last analysis | 2026-09-25 14:38 UTC |
| Last modified on VirusTotal | 2026-09-25 16:39 UTC |
Known Names
6lr7pswi0.execalcium-.jar.github-Course23sz.zip
hash_sha1
0b461c532a2df39cbbf5032f24dacf4e982b9793
VT 5 / 75
IOC database
- Type
- hash_sha1
- Value
0b461c532a2df39cbbf5032f24dacf4e982b9793- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 5 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ESET-NOD32 | malicious | Java/Agent.ADG trojan |
| Fortinet | malicious | Java/Agent.ADG!tr |
| Ikarus | malicious | Win32.Outbreak |
| Kaspersky | malicious | HEUR:Trojan.Java.Generic |
| Tencent | malicious | Java.Trojan.Generic.Vmhl |
Details From VirusTotal
Basic Properties
| MD5 | 1c511777a20d65303f1634ff10c87105 |
| SHA-1 | 0b461c532a2df39cbbf5032f24dacf4e982b9793 |
| SHA-256 | 1af3c5d99b48516ad0424d0441075c3209a7dcbe42ce78bfec8958c181e2f0a2 |
| VHash | b0ed1f22b8529993e99f17a74dc4bf39 |
| SSDEEP | 3072:GvVbB771jQA9SxqKbKb/qEIUBixNvm5UO6/7JS3fvxfmBdYOfiIE2rHsCRYySFZB:AVB79BtKbaqEIU4/Bd1MYBdbvRdSdf |
| TLSH | T124340127A16C0932DC1F9771A792E872A47C65D0B10D340B43F8989698C35DF1F96BEE |
| File type | JAR |
| File type tag | jar |
| File extension | jar |
| Magic | Zip archive data, at least v2.0 to extract, compression method=deflate |
| File size | 247.2 KB |
History
| First seen on VirusTotal | 2026-09-25 14:38 UTC |
| Last submission | 2026-09-25 14:38 UTC |
| Last analysis | 2026-09-25 14:38 UTC |
| Last modified on VirusTotal | 2026-09-25 16:39 UTC |
Known Names
6lr7pswi0.execalcium-.jar.github-Course23sz.zip
hash_md5
1c511777a20d65303f1634ff10c87105
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/1c511777a20d65303f1634ff10c87105
IOC database
- Type
- hash_md5
- Value
1c511777a20d65303f1634ff10c87105- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/1c511777a20d65303f1634ff10c87105
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: zip. Size: 253103 bytes. Reporter: GhostTypes. First seen: 2026-09-25 12:09:29.
Remediations (10)
-
web:aembit.io
Secret remediation goes beyond revoking a leaked credential. Learn the three-phase framework for assessment, rotation and cleanup that works in production.
-
web:docs.github.com
This will help you assess the risk and determine the best course of action for remediation . Determine the secret type and its provider. For example, is the secret a GitHub personal access token (PAT), an OpenAI API key, an SSH private key? Locate the repository, file and line that contains the leaked secret. Identify the secret owner.
-
web:github.com
This PowerShell script will scan all Fixed local drives to discover potential vulnerable Jar-files that contain the JndiLookup class and remove it from the Jar-file, please patch to 2.17.0 or later as soon as possible to completely fix the vulnerability this is only a mitigation until application vendors release patches for their products.
-
web:github.com
The following library contains a collection of remediation scripts designed to remove common unwanted software, adware, and malware found in the wild. If you come across a particular program you'd like to remediate, feel free to download the corresponding script and use it in your environment.
-
web:kb.uwm.edu
The Center for Advancing Student Learning (CASL) accepts eligible course materials from academic units for digital accessibility remediation . CASL staff and trained student workers review and remediate submitted materials to improve their accessibility for students.
-
web:stackoverflow.com
For the mitigation of this vulnerability: These are the possible mitigations for this flaw for releases version 1.x: Comment out or remove JMSAppender in the Log4j configuration if it is used Remove the JMSAppender class from the classpath. For example:
-
web:trainex.org
We would like to show you a description here but the site won't allow us.
-
web:www.epa.gov
In partnership with other entities, the U.S. Environmental Protection Agency provides a range of training on hazardous waste management and remediation by different methods to EPA, federal agency, state, tribal, and local personnel, consulting engineers, technology developers and vendors, remediation contractors, researchers, community groups, and individual citizens. While some training is ...
-
web:www.petefreitag.com
Apache Log4j 1.x does have vulnerabilities. How to identify vulnerable classes, remove them from the jar files, and testing to make sure the server or application still works after patching.
-
web:ziadsaleemi.com
Step-by-step remediation guide for purging malicious IDE extension artifacts and hardening local developer workstations.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.