s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-1af3c5d99b48516ad0424d0441075c3209a7dcbe42ce78bfec8958c181e2f0a2 high

📛 Threat Title

Unknown: calcium-.jar.github-Course23sz

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: zip. Size: 253103 bytes. Reporter: GhostTypes. First seen: 2026-09-25 12:09:29.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 1af3c5d99b48516ad0424d0441075c3209a7dcbe42ce78bfec8958c181e2f0a2 VT 5 / 75

IOC database

Type
hash_sha256
Value
1af3c5d99b48516ad0424d0441075c3209a7dcbe42ce78bfec8958c181e2f0a2
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 5 of 75 VirusTotal vendors

VendorVerdictDetection
ESET-NOD32 malicious Java/Agent.ADG trojan
Fortinet malicious Java/Agent.ADG!tr
Ikarus malicious Win32.Outbreak
Kaspersky malicious HEUR:Trojan.Java.Generic
Tencent malicious Java.Trojan.Generic.Vmhl

Details From VirusTotal

Basic Properties
MD51c511777a20d65303f1634ff10c87105
SHA-10b461c532a2df39cbbf5032f24dacf4e982b9793
SHA-2561af3c5d99b48516ad0424d0441075c3209a7dcbe42ce78bfec8958c181e2f0a2
VHashb0ed1f22b8529993e99f17a74dc4bf39
SSDEEP3072:GvVbB771jQA9SxqKbKb/qEIUBixNvm5UO6/7JS3fvxfmBdYOfiIE2rHsCRYySFZB:AVB79BtKbaqEIU4/Bd1MYBdbvRdSdf
TLSHT124340127A16C0932DC1F9771A792E872A47C65D0B10D340B43F8989698C35DF1F96BEE
File typeJAR
File type tagjar
File extensionjar
MagicZip archive data, at least v2.0 to extract, compression method=deflate
File size247.2 KB
History
First seen on VirusTotal2026-09-25 14:38 UTC
Last submission2026-09-25 14:38 UTC
Last analysis2026-09-25 14:38 UTC
Last modified on VirusTotal2026-09-25 16:39 UTC
Known Names
  • 6lr7pswi0.exe
  • calcium-.jar.github-Course23sz.zip
hash_sha1 0b461c532a2df39cbbf5032f24dacf4e982b9793 VT 5 / 75

IOC database

Type
hash_sha1
Value
0b461c532a2df39cbbf5032f24dacf4e982b9793
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 5 of 75 VirusTotal vendors

VendorVerdictDetection
ESET-NOD32 malicious Java/Agent.ADG trojan
Fortinet malicious Java/Agent.ADG!tr
Ikarus malicious Win32.Outbreak
Kaspersky malicious HEUR:Trojan.Java.Generic
Tencent malicious Java.Trojan.Generic.Vmhl

Details From VirusTotal

Basic Properties
MD51c511777a20d65303f1634ff10c87105
SHA-10b461c532a2df39cbbf5032f24dacf4e982b9793
SHA-2561af3c5d99b48516ad0424d0441075c3209a7dcbe42ce78bfec8958c181e2f0a2
VHashb0ed1f22b8529993e99f17a74dc4bf39
SSDEEP3072:GvVbB771jQA9SxqKbKb/qEIUBixNvm5UO6/7JS3fvxfmBdYOfiIE2rHsCRYySFZB:AVB79BtKbaqEIU4/Bd1MYBdbvRdSdf
TLSHT124340127A16C0932DC1F9771A792E872A47C65D0B10D340B43F8989698C35DF1F96BEE
File typeJAR
File type tagjar
File extensionjar
MagicZip archive data, at least v2.0 to extract, compression method=deflate
File size247.2 KB
History
First seen on VirusTotal2026-09-25 14:38 UTC
Last submission2026-09-25 14:38 UTC
Last analysis2026-09-25 14:38 UTC
Last modified on VirusTotal2026-09-25 16:39 UTC
Known Names
  • 6lr7pswi0.exe
  • calcium-.jar.github-Course23sz.zip
hash_md5 1c511777a20d65303f1634ff10c87105 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/1c511777a20d65303f1634ff10c87105

IOC database

Type
hash_md5
Value
1c511777a20d65303f1634ff10c87105
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/1c511777a20d65303f1634ff10c87105

References (1)

Remediations (10)

  • web:aembit.io

    Secret remediation goes beyond revoking a leaked credential. Learn the three-phase framework for assessment, rotation and cleanup that works in production.

  • web:docs.github.com

    This will help you assess the risk and determine the best course of action for remediation . Determine the secret type and its provider. For example, is the secret a GitHub personal access token (PAT), an OpenAI API key, an SSH private key? Locate the repository, file and line that contains the leaked secret. Identify the secret owner.

  • web:github.com

    This PowerShell script will scan all Fixed local drives to discover potential vulnerable Jar-files that contain the JndiLookup class and remove it from the Jar-file, please patch to 2.17.0 or later as soon as possible to completely fix the vulnerability this is only a mitigation until application vendors release patches for their products.

  • web:github.com

    The following library contains a collection of remediation scripts designed to remove common unwanted software, adware, and malware found in the wild. If you come across a particular program you'd like to remediate, feel free to download the corresponding script and use it in your environment.

  • web:kb.uwm.edu

    The Center for Advancing Student Learning (CASL) accepts eligible course materials from academic units for digital accessibility remediation . CASL staff and trained student workers review and remediate submitted materials to improve their accessibility for students.

  • web:stackoverflow.com

    For the mitigation of this vulnerability: These are the possible mitigations for this flaw for releases version 1.x: Comment out or remove JMSAppender in the Log4j configuration if it is used Remove the JMSAppender class from the classpath. For example:

  • web:trainex.org

    We would like to show you a description here but the site won't allow us.

  • web:www.epa.gov

    In partnership with other entities, the U.S. Environmental Protection Agency provides a range of training on hazardous waste management and remediation by different methods to EPA, federal agency, state, tribal, and local personnel, consulting engineers, technology developers and vendors, remediation contractors, researchers, community groups, and individual citizens. While some training is ...

  • web:www.petefreitag.com

    Apache Log4j 1.x does have vulnerabilities. How to identify vulnerable classes, remove them from the jar files, and testing to make sure the server or application still works after patching.

  • web:ziadsaleemi.com

    Step-by-step remediation guide for purging malicious IDE extension artifacts and hardening local developer workstations.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.