MB-7c577b7fbd3519a282a447e15fbe11febd3b2708fc02d36bd591ea00821ddc37
high
📛 Threat Title
Unknown: NoxxClient-.jar.github-Course23sz
Description
File type: zip. Size: 5542639 bytes. Reporter: GhostTypes. First seen: 2026-09-25 12:08:20.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
7c577b7fbd3519a282a447e15fbe11febd3b2708fc02d36bd591ea00821ddc37
VT 4 / 75
IOC database
- Type
- hash_sha256
- Value
7c577b7fbd3519a282a447e15fbe11febd3b2708fc02d36bd591ea00821ddc37- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 4 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ESET-NOD32 | malicious | Java/Agent.ADG trojan |
| Fortinet | malicious | Java/Agent.ADG!tr |
| Kaspersky | malicious | HEUR:Trojan.Java.Generic |
| Tencent | malicious | Java.Trojan.Generic.Ztjl |
Details From VirusTotal
Basic Properties
| MD5 | a17d52f195272720f34898371998b761 |
| SHA-1 | 5aaa49853b4186615d6bd10c72933a9d259b3b62 |
| SHA-256 | 7c577b7fbd3519a282a447e15fbe11febd3b2708fc02d36bd591ea00821ddc37 |
| VHash | 9446524d07e1718fccfe63dcf2c1d471 |
| SSDEEP | 98304:CqKx5wXm3KMMyLbPn9NuNAwbrupLggtRBdCp2moRFMhG2UkyMFe4:CTgW6a/9NmAwbruPti2fSh8nKf |
| TLSH | T12D462352FA0DA47DE007937358154FA6B82896C9F14FE6BB32F811E51C869C72F6870E |
| File type | JAR |
| File type tag | jar |
| File extension | jar |
| Magic | Zip archive data, at least v2.0 to extract, compression method=deflate |
| File size | 5.3 MB |
History
| First seen on VirusTotal | 2026-09-25 14:38 UTC |
| Last submission | 2026-09-25 14:38 UTC |
| Last analysis | 2026-09-25 14:38 UTC |
| Last modified on VirusTotal | 2026-09-25 16:40 UTC |
Known Names
3xcwiql.exeNoxxClient-.jar.github-Course23sz.zip
hash_sha1
5aaa49853b4186615d6bd10c72933a9d259b3b62
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/5aaa49853b4186615d6bd10c72933a9d259b3b62
IOC database
- Type
- hash_sha1
- Value
5aaa49853b4186615d6bd10c72933a9d259b3b62- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/5aaa49853b4186615d6bd10c72933a9d259b3b62
hash_md5
a17d52f195272720f34898371998b761
VT 4 / 75
IOC database
- Type
- hash_md5
- Value
a17d52f195272720f34898371998b761- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 4 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ESET-NOD32 | malicious | Java/Agent.ADG trojan |
| Fortinet | malicious | Java/Agent.ADG!tr |
| Kaspersky | malicious | HEUR:Trojan.Java.Generic |
| Tencent | malicious | Java.Trojan.Generic.Ztjl |
Details From VirusTotal
Basic Properties
| MD5 | a17d52f195272720f34898371998b761 |
| SHA-1 | 5aaa49853b4186615d6bd10c72933a9d259b3b62 |
| SHA-256 | 7c577b7fbd3519a282a447e15fbe11febd3b2708fc02d36bd591ea00821ddc37 |
| VHash | 9446524d07e1718fccfe63dcf2c1d471 |
| SSDEEP | 98304:CqKx5wXm3KMMyLbPn9NuNAwbrupLggtRBdCp2moRFMhG2UkyMFe4:CTgW6a/9NmAwbruPti2fSh8nKf |
| TLSH | T12D462352FA0DA47DE007937358154FA6B82896C9F14FE6BB32F811E51C869C72F6870E |
| File type | JAR |
| File type tag | jar |
| File extension | jar |
| Magic | Zip archive data, at least v2.0 to extract, compression method=deflate |
| File size | 5.3 MB |
History
| First seen on VirusTotal | 2026-09-25 14:38 UTC |
| Last submission | 2026-09-25 14:38 UTC |
| Last analysis | 2026-09-25 14:38 UTC |
| Last modified on VirusTotal | 2026-09-25 16:40 UTC |
Known Names
3xcwiql.exeNoxxClient-.jar.github-Course23sz.zip
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: zip. Size: 5542639 bytes. Reporter: GhostTypes. First seen: 2026-09-25 12:08:20.
Remediations (10)
-
web:noxxclient.com
Noxx Client is a powerful Fabric mod built for Donut SMP. 25+ modules: Combat Suite, ESP, Tracers, Auto Crystal, World Tools, Spotify integration and more.
-
web:app.any.run
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.
-
web:docs.github.com
Tip Organizations on GitHub Team and GitHub Enterprise plans can perform a free secret risk assessment (an on-demand, point-in-time scan) that evaluates their exposure to leaked secrets. See Secret security with GitHub.
-
web:github.com
A Gorilla Tag mod checker with many cool things! Contribute to Nnnoxxxx/Nox-Client development by creating an account on GitHub.
-
web:github.com
A practical methodology and remediation playbook built while preparing for the PJPT certification. - hutodani/PJPT-Pentesting-Playbook
-
web:kodari.ai
A feature-rich PvP client mod for Fabric 1.21.4 optimized for Mace and Crystal PvP. Includes a dark-themed GUI system with extensive module toggles, HUD overlays, keybind customization, and responsive settings panels. Features organized combat enhancements, visual aids, movement modules, and detailed tooltips for easy configuration. Built with performance and usability in mind for competitive ...
-
web:noxxclient.net
Noxx Client A Minecraft 1.21.11 utility client. 40+ modules. Clean UI.
-
web:tria.ge
Check this silentnet report NoxxClient (2)[.]jar, with a score of 10 out of 10.
-
web:trillium.solutions
Idk bruh. How to use: Download NoxxClient .jar Put it in .minecraft/mods folder Launch with Fabric 1.21.11 Click RShift to open UI
-
web:www.joesandbox.com
Is malicious Internet behaviorgraph top1 signatures2 2 Behavior Graph ID: 1928673 Sample: NoxxClient -1.21.11 (2).jar Startdate: 16/06/2026 Architecture: WINDOWS Score: 52 12 Multi AV Scanner detection for submitted file 2->12 14 Joe Sandbox ML detected suspicious sample 2->14 6 cmd.exe 2 2->6 started process3 process4 8 java.exe 3 6->8 started ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.