MB-0df208f9dbd3be1eb968b7eb18ca44ad725589313e1ea046dd338a1454ddea31
high
📛 Threat Title
Unknown: AstraWare-v5-.jar.github-Course23sz
Description
File type: zip. Size: 6305654 bytes. Reporter: GhostTypes. First seen: 2026-09-25 12:09:18.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
0df208f9dbd3be1eb968b7eb18ca44ad725589313e1ea046dd338a1454ddea31
VT 4 / 75
IOC database
- Type
- hash_sha256
- Value
0df208f9dbd3be1eb968b7eb18ca44ad725589313e1ea046dd338a1454ddea31- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 4 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ESET-NOD32 | malicious | Java/Agent.ADG trojan |
| Fortinet | malicious | Java/Agent.ADG!tr |
| Kaspersky | malicious | HEUR:Trojan.Java.Generic |
| Tencent | malicious | Java.Trojan.Generic.Cdhl |
Details From VirusTotal
Basic Properties
| MD5 | 094dd0c8890662e6330126343c878d1e |
| SHA-1 | 8ea81f0dc75f1a5a6292df478b985a242a764fb3 |
| SHA-256 | 0df208f9dbd3be1eb968b7eb18ca44ad725589313e1ea046dd338a1454ddea31 |
| VHash | 56125b0383588607d58569477c1c6fd5 |
| SSDEEP | 98304:7Ka4aErHu75PCzQs3CxCaxiLZVL7fN8fnwUwmUKTYuVEXu+UjBM0z7ENlL:7KZvDC5WQ2Q67RYFwm+SqoNMa7alL |
| TLSH | T1D2563332EF9D0124E527B33460554602BD2CA788F65EB49F2BB4145B7883EEF4B6639C |
| File type | JAR |
| File type tag | jar |
| File extension | jar |
| Magic | Zip archive data, at least v2.0 to extract, compression method=deflate |
| File size | 6.0 MB |
History
| First seen on VirusTotal | 2026-09-25 14:38 UTC |
| Last submission | 2026-09-25 14:38 UTC |
| Last analysis | 2026-09-25 14:38 UTC |
| Last modified on VirusTotal | 2026-09-25 16:39 UTC |
Known Names
xv95ewjbn.exeAstraWare-v5-.jar.github-Course23sz.zip
hash_sha1
8ea81f0dc75f1a5a6292df478b985a242a764fb3
VT 4 / 75
IOC database
- Type
- hash_sha1
- Value
8ea81f0dc75f1a5a6292df478b985a242a764fb3- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 4 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ESET-NOD32 | malicious | Java/Agent.ADG trojan |
| Fortinet | malicious | Java/Agent.ADG!tr |
| Kaspersky | malicious | HEUR:Trojan.Java.Generic |
| Tencent | malicious | Java.Trojan.Generic.Cdhl |
Details From VirusTotal
Basic Properties
| MD5 | 094dd0c8890662e6330126343c878d1e |
| SHA-1 | 8ea81f0dc75f1a5a6292df478b985a242a764fb3 |
| SHA-256 | 0df208f9dbd3be1eb968b7eb18ca44ad725589313e1ea046dd338a1454ddea31 |
| VHash | 56125b0383588607d58569477c1c6fd5 |
| SSDEEP | 98304:7Ka4aErHu75PCzQs3CxCaxiLZVL7fN8fnwUwmUKTYuVEXu+UjBM0z7ENlL:7KZvDC5WQ2Q67RYFwm+SqoNMa7alL |
| TLSH | T1D2563332EF9D0124E527B33460554602BD2CA788F65EB49F2BB4145B7883EEF4B6639C |
| File type | JAR |
| File type tag | jar |
| File extension | jar |
| Magic | Zip archive data, at least v2.0 to extract, compression method=deflate |
| File size | 6.0 MB |
History
| First seen on VirusTotal | 2026-09-25 14:38 UTC |
| Last submission | 2026-09-25 14:38 UTC |
| Last analysis | 2026-09-25 14:38 UTC |
| Last modified on VirusTotal | 2026-09-25 16:39 UTC |
Known Names
xv95ewjbn.exeAstraWare-v5-.jar.github-Course23sz.zip
hash_md5
094dd0c8890662e6330126343c878d1e
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/094dd0c8890662e6330126343c878d1e
IOC database
- Type
- hash_md5
- Value
094dd0c8890662e6330126343c878d1e- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/094dd0c8890662e6330126343c878d1e
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: zip. Size: 6305654 bytes. Reporter: GhostTypes. First seen: 2026-09-25 12:09:18.
Remediations (8)
-
web:any.run
Online sandbox report for AstraWare - v5 ..1.jar, tagged as etherhiding, stealer, weedhack, verdict: Malicious activity
-
web:astraware.com
Registration Codes If you are wanting to play our games on your old Palm OS, Pocket PC or Windows Mobile device, we have a page containing registration codes to unlock them.
-
web:github.com
CVE List V5 This repository is the official CVE List. It is a catalog of all CVE Records identified by, or reported to, the CVE Program. This repository hosts downloadable files of CVE Records in the CVE Record Format (view the schema). They are updated regularly (about every 7 minutes) using the official CVE Services API.
-
web:github.com
Maker of great games and apps for iOS and Android. GitHub is where Astraware Limited builds software.
-
web:tria.ge
Check this report AstraWare - v5 -Client-Mod-Fabric-1 [.]21 [.]4 (2) [.]jar, with a score of 3 out of 10.
-
web:www.uncoverit.org
Uncover it is a malware configuration extractor that can analyze files statically.
-
web:www.youtube.com
⚡ (LT1) AstraWare Hack Client 1.21.4 Best Sword/Crystal/Mace PvP Client For Mojo/Cracked Launcher Baltant Provdier 2.23K subscribers Like
-
web:www.youtube.com
⚡ ASTRAWARE V5 SHOWCASE ⚡ Welcome to another Minecraft PvP video! In this video, I'm showcasing AstraWare V5 , one of the smoothest and most powerful Minecraft PvP clients.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.