s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-7c577b7fbd3519a282a447e15fbe11febd3b2708fc02d36bd591ea00821ddc37 high

📛 Threat Title

Unknown: NoxxClient-.jar.github-Course23sz

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: zip. Size: 5542639 bytes. Reporter: GhostTypes. First seen: 2026-09-25 12:08:20.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 7c577b7fbd3519a282a447e15fbe11febd3b2708fc02d36bd591ea00821ddc37 VT 4 / 75

IOC database

Type
hash_sha256
Value
7c577b7fbd3519a282a447e15fbe11febd3b2708fc02d36bd591ea00821ddc37
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 4 of 75 VirusTotal vendors

VendorVerdictDetection
ESET-NOD32 malicious Java/Agent.ADG trojan
Fortinet malicious Java/Agent.ADG!tr
Kaspersky malicious HEUR:Trojan.Java.Generic
Tencent malicious Java.Trojan.Generic.Ztjl

Details From VirusTotal

Basic Properties
MD5a17d52f195272720f34898371998b761
SHA-15aaa49853b4186615d6bd10c72933a9d259b3b62
SHA-2567c577b7fbd3519a282a447e15fbe11febd3b2708fc02d36bd591ea00821ddc37
VHash9446524d07e1718fccfe63dcf2c1d471
SSDEEP98304:CqKx5wXm3KMMyLbPn9NuNAwbrupLggtRBdCp2moRFMhG2UkyMFe4:CTgW6a/9NmAwbruPti2fSh8nKf
TLSHT12D462352FA0DA47DE007937358154FA6B82896C9F14FE6BB32F811E51C869C72F6870E
File typeJAR
File type tagjar
File extensionjar
MagicZip archive data, at least v2.0 to extract, compression method=deflate
File size5.3 MB
History
First seen on VirusTotal2026-09-25 14:38 UTC
Last submission2026-09-25 14:38 UTC
Last analysis2026-09-25 14:38 UTC
Last modified on VirusTotal2026-09-25 16:40 UTC
Known Names
  • 3xcwiql.exe
  • NoxxClient-.jar.github-Course23sz.zip
hash_sha1 5aaa49853b4186615d6bd10c72933a9d259b3b62 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/5aaa49853b4186615d6bd10c72933a9d259b3b62

IOC database

Type
hash_sha1
Value
5aaa49853b4186615d6bd10c72933a9d259b3b62
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/5aaa49853b4186615d6bd10c72933a9d259b3b62

hash_md5 a17d52f195272720f34898371998b761 VT 4 / 75

IOC database

Type
hash_md5
Value
a17d52f195272720f34898371998b761
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 4 of 75 VirusTotal vendors

VendorVerdictDetection
ESET-NOD32 malicious Java/Agent.ADG trojan
Fortinet malicious Java/Agent.ADG!tr
Kaspersky malicious HEUR:Trojan.Java.Generic
Tencent malicious Java.Trojan.Generic.Ztjl

Details From VirusTotal

Basic Properties
MD5a17d52f195272720f34898371998b761
SHA-15aaa49853b4186615d6bd10c72933a9d259b3b62
SHA-2567c577b7fbd3519a282a447e15fbe11febd3b2708fc02d36bd591ea00821ddc37
VHash9446524d07e1718fccfe63dcf2c1d471
SSDEEP98304:CqKx5wXm3KMMyLbPn9NuNAwbrupLggtRBdCp2moRFMhG2UkyMFe4:CTgW6a/9NmAwbruPti2fSh8nKf
TLSHT12D462352FA0DA47DE007937358154FA6B82896C9F14FE6BB32F811E51C869C72F6870E
File typeJAR
File type tagjar
File extensionjar
MagicZip archive data, at least v2.0 to extract, compression method=deflate
File size5.3 MB
History
First seen on VirusTotal2026-09-25 14:38 UTC
Last submission2026-09-25 14:38 UTC
Last analysis2026-09-25 14:38 UTC
Last modified on VirusTotal2026-09-25 16:40 UTC
Known Names
  • 3xcwiql.exe
  • NoxxClient-.jar.github-Course23sz.zip

References (1)

Remediations (10)

  • web:noxxclient.com

    Noxx Client is a powerful Fabric mod built for Donut SMP. 25+ modules: Combat Suite, ESP, Tracers, Auto Crystal, World Tools, Spotify integration and more.

  • web:app.any.run

    Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

  • web:docs.github.com

    Tip Organizations on GitHub Team and GitHub Enterprise plans can perform a free secret risk assessment (an on-demand, point-in-time scan) that evaluates their exposure to leaked secrets. See Secret security with GitHub.

  • web:github.com

    A Gorilla Tag mod checker with many cool things! Contribute to Nnnoxxxx/Nox-Client development by creating an account on GitHub.

  • web:github.com

    A practical methodology and remediation playbook built while preparing for the PJPT certification. - hutodani/PJPT-Pentesting-Playbook

  • web:kodari.ai

    A feature-rich PvP client mod for Fabric 1.21.4 optimized for Mace and Crystal PvP. Includes a dark-themed GUI system with extensive module toggles, HUD overlays, keybind customization, and responsive settings panels. Features organized combat enhancements, visual aids, movement modules, and detailed tooltips for easy configuration. Built with performance and usability in mind for competitive ...

  • web:noxxclient.net

    Noxx Client A Minecraft 1.21.11 utility client. 40+ modules. Clean UI.

  • web:tria.ge

    Check this silentnet report NoxxClient (2)[.]jar, with a score of 10 out of 10.

  • web:trillium.solutions

    Idk bruh. How to use: Download NoxxClient .jar Put it in .minecraft/mods folder Launch with Fabric 1.21.11 Click RShift to open UI

  • web:www.joesandbox.com

    Is malicious Internet behaviorgraph top1 signatures2 2 Behavior Graph ID: 1928673 Sample: NoxxClient -1.21.11 (2).jar Startdate: 16/06/2026 Architecture: WINDOWS Score: 52 12 Multi AV Scanner detection for submitted file 2->12 14 Joe Sandbox ML detected suspicious sample 2->14 6 cmd.exe 2 2->6 started process3 process4 8 java.exe 3 6->8 started ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.