Suspicious
Unsigned JAR shows direct-IP contact and two offensive MITRE techniques but zero antivirus detections and a clean community verdict.
0ba5c89b4873e2a24a…d0bb3390fdThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The complete absence of malicious detections across tier-1 and tier-2 engines strongly favors a benign or low-risk classification. However the sandbox observed direct IP contact without DNS resolution and recorded two techniques commonly abused by malware for persistence and defense evasion. Medium prevalence and an explicit researcher comment labeling the sample clean offset the heuristic concern, resulting in a borderline suspicious verdict rather than outright malicious or safe.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines: 0/59 malicious (tier1Malicious=0, onlyLowTrustFlagging=false)
triggeredHeuristics: MalwareTips.Synth.DirectIpC2 fired on IP 162.159.36.2
behaviour.offensiveTechniques: T1543.002 and T1562.001 present
communityComments[0].text: 'Verdict: **Clean** Score: **0/100**'
prevalence.classification: medium (306 submitters)
- Zero malicious detections across 59 engines
- Medium prevalence with 306 submitters
- Explicit community clean verdict
- Direct IP contact without DNS (DirectIpC2 heuristic)
- Offensive MITRE techniques T1543.002 and T1562.001
- Unsigned JAR
Treat as suspicious until additional runtime telemetry or updated AV coverage clarifies intent; do not execute on production systems without isolation.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
- C:\Users\<USER>\AppData\Local\Temp\hsperfdata_<USER>\6956
- C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestamp
- C:\ProgramData\Oracle\Java\.oracle_jre_usage\17dfc292991c8786.timestamp
- C:\Users\user\AppData\Local\Temp\hsperfdata_user
- C:\Users\user\AppData\Local\Temp\hsperfdata_user\1220
- C:\Users\user\AppData\Local\Temp\hsperfdata_user\6808
- /tmp/hsperfdata_root/5006
Files this sample writes at runtime
This file drops 5 children at runtime. None are currently flagged malicious in our cache.
- 698f7e50cd92e670b729…3a5023Never scannednever seen before
- c1de3a9376fdaef0ba6a…308b70Never scannednever seen before
- d87c5f3cdfb5b7c0510e…1ade9eNever scannednever seen before
- 44a3bab2c338e3bca24c…d3b9e7Never scannednever seen before
- ac941ead01d5451a7a9f…253227Never scannednever seen before
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence162.159.36.2
0 detections across 75 engines
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- Argon.jar
- Size
- 334.7 KB
- MIME type
- (unknown)
- Detected type
- JAR
- SHA-256
- 0ba5c89b4873e2a24a31d316a090cc98353ee1d04881695cafee18d0bb3390fd
- MD5
- 8f57ba7e132968ec75473e6f0e7b71b3
- SHA-1
- 39b697a348d8f711eb9aeb9b7d914faf8642a6ed
- First seen (VT)
- 12/2/2025, 11:42:46 AM
- Last analysis (VT)
- 5/8/2026, 7:19:52 AM
- First scan (MalwareTips)
- 5/17/2026, 7:24:27 PM
- Last scan (MalwareTips)
- 5/17/2026, 7:24:27 PM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.