MB-20d8bd5ba2be4f62a921fec36adb66239a070ca88b932e2e2076ad25fa3385b5
high
📛 Threat Title
Unknown: 4E-client.jar.github-Course23sz
Description
File type: zip. Size: 505859 bytes. Reporter: GhostTypes. First seen: 2026-09-25 12:08:32.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
20d8bd5ba2be4f62a921fec36adb66239a070ca88b932e2e2076ad25fa3385b5
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/20d8bd5ba2be4f62a921fec36adb66239a070ca88b932e2e2076ad25fa3385b5
IOC database
- Type
- hash_sha256
- Value
20d8bd5ba2be4f62a921fec36adb66239a070ca88b932e2e2076ad25fa3385b5- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/20d8bd5ba2be4f62a921fec36adb66239a070ca88b932e2e2076ad25fa3385b5
hash_sha1
53f8a33b2d80a10c80f0348b0598e9ad1e950d66
VT 5 / 75
IOC database
- Type
- hash_sha1
- Value
53f8a33b2d80a10c80f0348b0598e9ad1e950d66- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 5 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ESET-NOD32 | malicious | Java/Agent.ADG trojan |
| Fortinet | malicious | Java/Agent.ADG!tr |
| Ikarus | malicious | Win32.Outbreak |
| Kaspersky | malicious | HEUR:Trojan.Java.Generic |
| Tencent | malicious | Java.Trojan.Generic.Ctgl |
Details From VirusTotal
Basic Properties
| MD5 | 778e161ac57121eb798410ab13d5f832 |
| SHA-1 | 53f8a33b2d80a10c80f0348b0598e9ad1e950d66 |
| SHA-256 | 20d8bd5ba2be4f62a921fec36adb66239a070ca88b932e2e2076ad25fa3385b5 |
| VHash | 7d3eb7c1fb2c3c20c74f06b9339afaf8 |
| SSDEEP | 12288:GmbjtiJdj4jFR0axG8jedr/I0+ILHOHbqCsD+5m5:G88j630uGCedrgXItCsD0m5 |
| TLSH | T19CB4F112E23C007EDE377332E806DA90BCA5D6D2E012741A6A7C04D919D36BB5F99BDD |
| File type | JAR |
| File type tag | jar |
| File extension | jar |
| Magic | Zip archive data, at least v2.0 to extract, compression method=deflate |
| File size | 494.0 KB |
History
| First seen on VirusTotal | 2026-09-25 14:38 UTC |
| Last submission | 2026-09-25 14:38 UTC |
| Last analysis | 2026-09-25 14:38 UTC |
| Last modified on VirusTotal | 2026-09-25 16:39 UTC |
Known Names
7obelv0.exe4E-client.jar.github-Course23sz.zip
hash_md5
778e161ac57121eb798410ab13d5f832
VT 5 / 75
IOC database
- Type
- hash_md5
- Value
778e161ac57121eb798410ab13d5f832- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 5 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ESET-NOD32 | malicious | Java/Agent.ADG trojan |
| Fortinet | malicious | Java/Agent.ADG!tr |
| Ikarus | malicious | Win32.Outbreak |
| Kaspersky | malicious | HEUR:Trojan.Java.Generic |
| Tencent | malicious | Java.Trojan.Generic.Ctgl |
Details From VirusTotal
Basic Properties
| MD5 | 778e161ac57121eb798410ab13d5f832 |
| SHA-1 | 53f8a33b2d80a10c80f0348b0598e9ad1e950d66 |
| SHA-256 | 20d8bd5ba2be4f62a921fec36adb66239a070ca88b932e2e2076ad25fa3385b5 |
| VHash | 7d3eb7c1fb2c3c20c74f06b9339afaf8 |
| SSDEEP | 12288:GmbjtiJdj4jFR0axG8jedr/I0+ILHOHbqCsD+5m5:G88j630uGCedrgXItCsD0m5 |
| TLSH | T19CB4F112E23C007EDE377332E806DA90BCA5D6D2E012741A6A7C04D919D36BB5F99BDD |
| File type | JAR |
| File type tag | jar |
| File extension | jar |
| Magic | Zip archive data, at least v2.0 to extract, compression method=deflate |
| File size | 494.0 KB |
History
| First seen on VirusTotal | 2026-09-25 14:38 UTC |
| Last submission | 2026-09-25 14:38 UTC |
| Last analysis | 2026-09-25 14:38 UTC |
| Last modified on VirusTotal | 2026-09-25 16:39 UTC |
Known Names
7obelv0.exe4E-client.jar.github-Course23sz.zip
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: zip. Size: 505859 bytes. Reporter: GhostTypes. First seen: 2026-09-25 12:08:32.
Remediations (10)
-
web:any.run
Online sandbox report for 4E -Client-1.21.-latest.jar, tagged as etherhiding, antivm, verdict: Malicious activity
-
web:any.run
Online sandbox report for 4E -Client.jar, tagged as stealer, weedhack, anti-evasion, rat, pua, adware, auto, rustystealer, verdict: Malicious activity
-
web:github.com
Contribute to poorjenny/ 4e development by creating an account on GitHub.
-
web:grokipedia.com
The 4E Client is a free, lightweight, Fabric-based Minecraft utility and ghost client compatible with version 1.21 (including 1.21.1), designed primarily for PvP, base hunting, and automation on Donut
-
web:virusscan.jotti.org
Report for scan job: vmnsuax9y5 May 14, 2026
-
web:www.donutsmpclients.com
DonutSMP Clients is a free Minecraft client hub featuring client information, free downloads, guides, and resources for Minecraft 1.21.11.
-
web:www.joesandbox.com
Found application associated with file extension: .jar Stop behavior analysis, all processes terminated
-
web:www.joesandbox.com
Deep Malware Analysis - Joe Sandbox Analysis Report
-
web:www.tiktok.com
4e Client How to Install 4E Client Easily Learn the step-by-step process to install the 4E client. Enhance your gaming experience today! #BestClient #4EClientOnTop This is an AI-generated summary of the content, and is not intended to provide factual context. If you think it may contain an error, please report at:Feedback and help - TikTok 172 ...
-
web:www.youtube.com
In this video I showcased 4E Client 1.21.11 in Minecraft and tested it in different PvP fights. 4E Client is a PC, Mobile & Pojav compatible client made for p...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.