MB-0e54456701cb53a73c4330dbe4c749afa6a7f61406e6ed3df368329852737757
high
📛 Threat Title
Unknown: Thorium.jar.github-Course23sz
Description
File type: zip. Size: 614101 bytes. Reporter: GhostTypes. First seen: 2026-09-25 12:07:39.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
0e54456701cb53a73c4330dbe4c749afa6a7f61406e6ed3df368329852737757
VT 5 / 75
IOC database
- Type
- hash_sha256
- Value
0e54456701cb53a73c4330dbe4c749afa6a7f61406e6ed3df368329852737757- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 5 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Alibaba | malicious | Trojan:JAVA/Generic.8c75fbd5 |
| ESET-NOD32 | malicious | Java/Agent.ADG trojan |
| Fortinet | malicious | Java/Agent.ADG!tr |
| Ikarus | malicious | Win32.Outbreak |
| Kaspersky | malicious | HEUR:Trojan.Java.Generic |
Details From VirusTotal
Basic Properties
| MD5 | e295e74fd25a81ccc904808a0500df9a |
| SHA-1 | 340eafd6e02716e7e235ce060117c9a69adcd49c |
| SHA-256 | 0e54456701cb53a73c4330dbe4c749afa6a7f61406e6ed3df368329852737757 |
| VHash | 8c2d1ce2d4c15d473149357c36f30613 |
| SSDEEP | 12288:/KXo2vP3gI4lI24i9IlUYf0wbxg0umQj/urSitHc36:yfPXHgSlUYf0EtFuwVVc36 |
| TLSH | T1DED4125ED68510B1E12F527846141E62B81C9EC8FF06B0339EF25B5B48939DBDB036EE |
| File type | JAR |
| File type tag | jar |
| File extension | jar |
| Magic | Zip archive data, at least v2.0 to extract, compression method=deflate |
| File size | 599.7 KB |
History
| First seen on VirusTotal | 2026-08-30 17:49 UTC |
| Last submission | 2026-09-25 13:16 UTC |
| Last analysis | 2026-09-25 13:16 UTC |
| Last modified on VirusTotal | 2026-09-25 15:18 UTC |
Known Names
46jxm2nj.exe0e54456701cb53a73c4330dbe4c749afa6a7f61406e6ed3df368329852737757.zip2a691b81-9c56-4d47-8400-8be96a224fcbThorium.jarThorium (1).jarNicht bestätigt 170196.crdownload
hash_sha1
340eafd6e02716e7e235ce060117c9a69adcd49c
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/340eafd6e02716e7e235ce060117c9a69adcd49c
IOC database
- Type
- hash_sha1
- Value
340eafd6e02716e7e235ce060117c9a69adcd49c- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/340eafd6e02716e7e235ce060117c9a69adcd49c
hash_md5
e295e74fd25a81ccc904808a0500df9a
VT 5 / 75
IOC database
- Type
- hash_md5
- Value
e295e74fd25a81ccc904808a0500df9a- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 5 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Alibaba | malicious | Trojan:JAVA/Generic.8c75fbd5 |
| ESET-NOD32 | malicious | Java/Agent.ADG trojan |
| Fortinet | malicious | Java/Agent.ADG!tr |
| Ikarus | malicious | Win32.Outbreak |
| Kaspersky | malicious | HEUR:Trojan.Java.Generic |
Details From VirusTotal
Basic Properties
| MD5 | e295e74fd25a81ccc904808a0500df9a |
| SHA-1 | 340eafd6e02716e7e235ce060117c9a69adcd49c |
| SHA-256 | 0e54456701cb53a73c4330dbe4c749afa6a7f61406e6ed3df368329852737757 |
| VHash | 8c2d1ce2d4c15d473149357c36f30613 |
| SSDEEP | 12288:/KXo2vP3gI4lI24i9IlUYf0wbxg0umQj/urSitHc36:yfPXHgSlUYf0EtFuwVVc36 |
| TLSH | T1DED4125ED68510B1E12F527846141E62B81C9EC8FF06B0339EF25B5B48939DBDB036EE |
| File type | JAR |
| File type tag | jar |
| File extension | jar |
| Magic | Zip archive data, at least v2.0 to extract, compression method=deflate |
| File size | 599.7 KB |
History
| First seen on VirusTotal | 2026-08-30 17:49 UTC |
| Last submission | 2026-09-25 13:16 UTC |
| Last analysis | 2026-09-25 13:16 UTC |
| Last modified on VirusTotal | 2026-09-25 15:18 UTC |
Known Names
46jxm2nj.exe0e54456701cb53a73c4330dbe4c749afa6a7f61406e6ed3df368329852737757.zip2a691b81-9c56-4d47-8400-8be96a224fcbThorium.jarThorium (1).jarNicht bestätigt 170196.crdownload
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: zip. Size: 614101 bytes. Reporter: GhostTypes. First seen: 2026-09-25 12:07:39.
Remediations (10)
-
web:any.run
Online sandbox report for Thorium-1.21.1.jar, tagged as etherhiding, stealer, weedhack, verdict: Malicious activity
-
web:cybernews.com
The Windows malware can steal browser passwords, cryptocurrency wallet data, and other sensitive information from developers. GitHub removed many flagged repositories, but researchers expect attackers to keep creating new fake accounts automatically.
-
web:cybersecuritynews.com
GitHub malware campaign infects 10,000+ repositories with Trojanized files, exposing gaps in automated detection.
-
web:docs.github.com
This will help you assess the risk and determine the best course of action for remediation . Determine the secret type and its provider. For example, is the secret a GitHub personal access token (PAT), an OpenAI API key, an SSH private key? Locate the repository, file and line that contains the leaked secret. Identify the secret owner.
-
web:gbhackers.com
A large-scale malware distribution campaign utilizing GitHub repositories has been uncovered, weaponized over 10,000 repositories.
-
web:github.com
Chromium fork named after radioactive element No. 90. Source code and Linux releases. Windows/MacOS/ARM builds served in different repos, links are towards the top of the README.md. - Alex313031/th...
-
web:github.com
GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.
-
web:ratornot.com
Free online Minecraft JAR scanner. Check mods from CurseForge or Modrinth for RATs, token stealers, and infostealers. AI-powered verdict, no account needed.
-
web:securityaffairs.com
It uses techniques from public GitHub tools designed to bypass Chrome's App-Bound Encryption and decrypt stored browser credentials. The malware loads an encrypted internal payload that extracts saved passwords and records installed applications. BoryptGrab also downloads a helper tool to assist with Chromium-based browser extraction.
-
web:software.viginet.net
Learn how GitHub malware spreads through fake repositories, malicious code, and infected downloads. Discover warning signs and practical tips to protect your PC in 2026.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.