MB-27fbc615a4944bbe0cf5e93ccc70297cbc6505ead338ae6798f1006ff3517390
high
📛 Threat Title
SilentNet: ScoobyLauncher.exe.github-Course23sz
Description
File type: exe. Size: 1139712 bytes. Reporter: GhostTypes. First seen: 2026-09-25 12:11:27.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
73f461c771aef77ec43d53a0c54f0c8d
IOC database
- Type
- hash_imphash
- Value
73f461c771aef77ec43d53a0c54f0c8d- First seen
- Last seen
- Attached to this threat
- Appears in
- 17 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
27fbc615a4944bbe0cf5e93ccc70297cbc6505ead338ae6798f1006ff3517390
VT 50 / 75
IOC database
- Type
- hash_sha256
- Value
27fbc615a4944bbe0cf5e93ccc70297cbc6505ead338ae6798f1006ff3517390- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- SilentNet
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 50 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Malware/Win.Dacic.R765588 |
| Alibaba | malicious | TrojanDownloader:Win64/Convagent.88aefc55 |
| alibabacloud | malicious | Trojan[downloader]:Win/FakeTool.C |
| ALYac | malicious | Generic.Dacic.11262.B60D951B |
| Antiy-AVL | malicious | Trojan/Win32.Agent |
| APEX | malicious | Malicious |
| Arcabit | malicious | Generic.Dacic.11262.B60D951B |
| Avast | malicious | Win64:MalwareX-gen [Misc] |
| AVG | malicious | Win64:MalwareX-gen [Misc] |
| Avira | malicious | TR/W64.Agent |
| BitDefender | malicious | Generic.Dacic.11262.B60D951B |
| Bkav | malicious | W32.Malware.52040248 |
| CrowdStrike | malicious | win/malicious_confidence_100% (D) |
| CTX | malicious | exe.trojan.dacic |
| Cylance | malicious | Unsafe |
| Cynet | malicious | Malicious (score: 99) |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.DownLoader49.40340 |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Generic.Dacic.11262.B60D951B (B) |
| ESET-NOD32 | malicious | Win64/FakeTool.C trojan |
| F-Secure | malicious | Trojan.TR/W64.Agent |
| GData | malicious | Generic.Dacic.11262.B60D951B |
| Gridinsoft | malicious | Trojan.Win64.Agent.oa!s1 |
| huorong | malicious | Backdoor/Agent.rv |
| Ikarus | malicious | Trojan.Win64.Agent |
| K7AntiVirus | malicious | Riskware ( 00584baa1 ) |
| K7GW | malicious | Riskware ( 00584baa1 ) |
| Kaspersky | malicious | HEUR:Trojan-Downloader.Win32.Magnar.gen |
| Kingsoft | malicious | Win32.Trojan-Downloader.Magnar.gen |
| Lionic | malicious | Trojan.Win32.Dacic.a!c |
| Malwarebytes | malicious | Trojan.Loader |
| MaxSecure | malicious | Trojan.Malware.121218.susgen |
| McAfeeD | malicious | Trojan:Win/Dacic.EBP |
| Microsoft | malicious | Trojan:Win64/Convagent.RVA!MTB |
| MicroWorld-eScan | malicious | Generic.Dacic.11262.B60D951B |
| NANO-Antivirus | malicious | Trojan.Win64.Magnar.ljyrcy |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/GdSda.A |
| Rising | malicious | Backdoor.Agent!8.C5D (CLOUD) |
| Sangfor | malicious | Downloader.Win64.Convagent.Vicb |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | ML.Attribute.HighConfidence |
| Tencent | malicious | Malware.Win32.Gencirc.10c46679 |
| TrellixENS | malicious | Artemis!0192402A73BC |
| TrendMicro | malicious | Trojan.Win64.MAGNAR.USBLIF26 |
| TrendMicro-HouseCall | malicious | Trojan.Win64.MAGNAR.USBLIF26 |
| Varist | malicious | W64/ARisk.PQ |
| VIPRE | malicious | Generic.Dacic.11262.B60D951B |
| Webroot | malicious | Win.Trojan.Gen |
Details From VirusTotal
Basic Properties
| MD5 | 0192402a73bc619a042dab8c1d6cf9e5 |
| SHA-1 | a492961849dd883f498b02fafc836611fb3d220c |
| SHA-256 | 27fbc615a4944bbe0cf5e93ccc70297cbc6505ead338ae6798f1006ff3517390 |
| VHash | 016076651d55550d151043z32z183zapz77z |
| SSDEEP | 12288:tbs/m0E54jwaFXGc8lEBBBHGBKq2IZwDPlvfqItNqdg:tbOVE5ifGPRZwZvf3fd |
| TLSH | T1D5357C83E7A385D8C116C9B5534BF137F9627C8E4B157197ABC41E633A67BA4E22CB00 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32+ executable (GUI) x86-64, for MS Windows |
| File size | 1.1 MB |
History
| Creation date | 2026-09-13 16:39 UTC |
| First seen on VirusTotal | 2026-09-15 16:09 UTC |
| Last submission | 2026-09-25 13:12 UTC |
| Last analysis | 2026-09-25 13:12 UTC |
| Last modified on VirusTotal | 2026-09-25 15:14 UTC |
Known Names
oxo4uc81r.exebtodfs76a.exeScoobyLauncher.exeScoobyLauncher (1).exeNon confermato 322596.crdownload
hash_sha1
a492961849dd883f498b02fafc836611fb3d220c
VT 50 / 75
IOC database
- Type
- hash_sha1
- Value
a492961849dd883f498b02fafc836611fb3d220c- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 50 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Malware/Win.Dacic.R765588 |
| Alibaba | malicious | TrojanDownloader:Win64/Convagent.88aefc55 |
| alibabacloud | malicious | Trojan[downloader]:Win/FakeTool.C |
| ALYac | malicious | Generic.Dacic.11262.B60D951B |
| Antiy-AVL | malicious | Trojan/Win32.Agent |
| APEX | malicious | Malicious |
| Arcabit | malicious | Generic.Dacic.11262.B60D951B |
| Avast | malicious | Win64:MalwareX-gen [Misc] |
| AVG | malicious | Win64:MalwareX-gen [Misc] |
| Avira | malicious | TR/W64.Agent |
| BitDefender | malicious | Generic.Dacic.11262.B60D951B |
| Bkav | malicious | W32.Malware.52040248 |
| CrowdStrike | malicious | win/malicious_confidence_100% (D) |
| CTX | malicious | exe.trojan.dacic |
| Cylance | malicious | Unsafe |
| Cynet | malicious | Malicious (score: 99) |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.DownLoader49.40340 |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Generic.Dacic.11262.B60D951B (B) |
| ESET-NOD32 | malicious | Win64/FakeTool.C trojan |
| F-Secure | malicious | Trojan.TR/W64.Agent |
| GData | malicious | Generic.Dacic.11262.B60D951B |
| Gridinsoft | malicious | Trojan.Win64.Agent.oa!s1 |
| huorong | malicious | Backdoor/Agent.rv |
| Ikarus | malicious | Trojan.Win64.Agent |
| K7AntiVirus | malicious | Riskware ( 00584baa1 ) |
| K7GW | malicious | Riskware ( 00584baa1 ) |
| Kaspersky | malicious | HEUR:Trojan-Downloader.Win32.Magnar.gen |
| Kingsoft | malicious | Win32.Trojan-Downloader.Magnar.gen |
| Lionic | malicious | Trojan.Win32.Dacic.a!c |
| Malwarebytes | malicious | Trojan.Loader |
| MaxSecure | malicious | Trojan.Malware.121218.susgen |
| McAfeeD | malicious | Trojan:Win/Dacic.EBP |
| Microsoft | malicious | Trojan:Win64/Convagent.RVA!MTB |
| MicroWorld-eScan | malicious | Generic.Dacic.11262.B60D951B |
| NANO-Antivirus | malicious | Trojan.Win64.Magnar.ljyrcy |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/GdSda.A |
| Rising | malicious | Backdoor.Agent!8.C5D (CLOUD) |
| Sangfor | malicious | Downloader.Win64.Convagent.Vicb |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | ML.Attribute.HighConfidence |
| Tencent | malicious | Malware.Win32.Gencirc.10c46679 |
| TrellixENS | malicious | Artemis!0192402A73BC |
| TrendMicro | malicious | Trojan.Win64.MAGNAR.USBLIF26 |
| TrendMicro-HouseCall | malicious | Trojan.Win64.MAGNAR.USBLIF26 |
| Varist | malicious | W64/ARisk.PQ |
| VIPRE | malicious | Generic.Dacic.11262.B60D951B |
| Webroot | malicious | Win.Trojan.Gen |
Details From VirusTotal
Basic Properties
| MD5 | 0192402a73bc619a042dab8c1d6cf9e5 |
| SHA-1 | a492961849dd883f498b02fafc836611fb3d220c |
| SHA-256 | 27fbc615a4944bbe0cf5e93ccc70297cbc6505ead338ae6798f1006ff3517390 |
| VHash | 016076651d55550d151043z32z183zapz77z |
| SSDEEP | 12288:tbs/m0E54jwaFXGc8lEBBBHGBKq2IZwDPlvfqItNqdg:tbOVE5ifGPRZwZvf3fd |
| TLSH | T1D5357C83E7A385D8C116C9B5534BF137F9627C8E4B157197ABC41E633A67BA4E22CB00 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32+ executable (GUI) x86-64, for MS Windows |
| File size | 1.1 MB |
History
| Creation date | 2026-09-13 16:39 UTC |
| First seen on VirusTotal | 2026-09-15 16:09 UTC |
| Last submission | 2026-09-25 13:12 UTC |
| Last analysis | 2026-09-25 13:12 UTC |
| Last modified on VirusTotal | 2026-09-25 15:14 UTC |
Known Names
oxo4uc81r.exebtodfs76a.exeScoobyLauncher.exeScoobyLauncher (1).exeNon confermato 322596.crdownload
hash_md5
0192402a73bc619a042dab8c1d6cf9e5
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/0192402a73bc619a042dab8c1d6cf9e5
IOC database
- Type
- hash_md5
- Value
0192402a73bc619a042dab8c1d6cf9e5- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/0192402a73bc619a042dab8c1d6cf9e5
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 1139712 bytes. Reporter: GhostTypes. First seen: 2026-09-25 12:11:27.
Remediations (10)
-
web:github.com
SilentNet is a fully operational Malware-as-a-Service (MaaS) infostealer targeting Windows systems via Minecraft mod loaders (Fabric, Forge) and a Java-based dropper distributed through DoubleClick ads.
-
web:github.com
⚠️ ScoobyMenu (scoobymenu.net) is a RAT — static reverse engineering of ScoobyLauncher.exe reveals a full Overlord RAT agent with keylogger, screen/webcam capture, and C2 communication disguised as...
-
web:gridinsoft.com
Heuristic detection uses behavioral analysis and pattern recognition to identify potential threats without specific signatures. This proactive approach detects suspicious code behavior that may indicate malware presence. Detection may occasionally produce false positives when legitimate software exhibits similar behavioral patterns.
-
web:jarscanner.github.io
How to recognise silentnet while checking files manually: Silentnet injects safe mods with malicious code, It always adds itself as a "github" folder (com/github/) and the .class file names are always different, But the obfuscation and the methods inside are still the same.
-
web:mail.silentnet.st
Guest login Sign in to one mailbox with just its email and password — no SilentNet account required.
-
web:scoobymenu.net
Scooby launcher for GTA 5, RDR2, FiveM, CS2 and GMOD. One small Windows download.
-
web:silentnet.st
Login with Discord Sign in with credentials instead Don't have an account? Sign up
-
web:silentnet.st
Discord Webhook URL We'll send your account credentials to this webhook
-
web:testing.silentnet.st
Sign in to your account Login with Discord Sign in with credentials instead User ID or Username Account Key Sign In Sign in with Discord instead
-
web:www.youtube.com
Share your videos with friends, family, and the world
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.