Safe
Unsigned Java JAR with zero malicious detections across 65 engines, 675 submitters, and 268 days of prevalence; heuristic C2 flag references legitimate DNS resolver.
806c971227130c677f…17cddefd50The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The file exhibits a clean profile: zero malicious detections, 17 tier-1 engines silent, and widespread prevalence (common_old classification) spanning 268 days. The triggered heuristic 'DirectIpC2' references contact to 162.159.36.2, which is Cloudflare's public DNS resolver — not a malicious C2 server. Java applications routinely contact public DNS for network diagnostics and updates. Offensive MITRE techniques (T1543.002, T1562.001) are paired with 8 ambient techniques typical of Java runtime introspection, not malware evasion. No malicious sandbox verdicts, no malicious dropped children, and no malicious contacted hosts in our cache. An independent researcher annotation also rated the file clean.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines: 0/65 malicious; tier1Malicious=0; tier1ReportedClean=17 (Kaspersky, Microsoft, BitDefender, ESET-NOD32, Fortinet, Avira, Emsisoft, F-Secure, GData, Ikarus, DrWeb, Avast, AVG all undetected)
prevalence.classification='common_old': 675 unique submitters, 760 submissions over 268 days — widespread distribution without malicious consensus
triggeredHeuristics 'MalwareTips.Synth.DirectIpC2' fired on contact to 162.159.36.2 (Cloudflare public DNS) — benign resolver IP, not C2 infrastructure
behaviour: 2 offensive MITRE techniques paired with 8 ambient techniques typical of Java runtime introspection; no malicious sandbox verdict; no malicious dropped children (6/6 unknown)
communityComments researcher annotation: 'Verdict: Clean Score: 0/100' — independent analyst assessment aligns with engine silence
- Zero malicious detections across 65 engines including 17 tier-1 vendors
- Common_old prevalence: 675 submitters, 760 submissions over 268 days
- No tier-1 family consensus; no malicious sandbox verdict
- Contacted IP (162.159.36.2) is Cloudflare public DNS resolver, not malicious infrastructure
- Independent researcher annotation rated file clean
This file is safe. The heuristic C2 alert is a false positive caused by legitimate contact to Cloudflare's public DNS resolver. No action is needed.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 162.159.36.2
- C:\Users\<USER>\AppData\Local\Temp\hsperfdata_<USER>\5148
- C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestamp
- C:\ProgramData\Oracle\Java\.oracle_jre_usage\17dfc292991c8786.timestamp
- C:\Users\user\AppData\Local\Temp\hsperfdata_user
- C:\Users\user\AppData\Local\Temp\hsperfdata_user\2320
- C:\Users\user\AppData\Local\Temp\hsperfdata_user\6896
- C:\Users\user\AppData\Local\Temp\hsperfdata_user\6824
- /tmp/hsperfdata_root/4961
- /tmp/hsperfdata_root/5007
- \Sessions\1\BaseNamedObjects\Local\SessionImmersiveColorMutex
Files this sample writes at runtime
This file drops 6 children at runtime. None are currently flagged malicious in our cache.
- 9d21522e33d33ca1a889…36a55fNever scannednever seen before
- 5f0cff6364d37a64e7da…03f2aaNever scannednever seen before
- b468bf508c1b034631c5…457d6eNever scannednever seen before
- 3286581a3fb4e656be6b…ad63c1Never scannednever seen before
- d87c5f3cdfb5b7c0510e…1ade9eNever scannednever seen before
- 44a3bab2c338e3bca24c…d3b9e7Never scannednever seen before
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence162.159.36.2
0 detections across 74 engines
How often this file shows up in the wild
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Forensic fingerprint
- File name
- zenithdlc-2.0.jar
- Size
- 9.24 MB
- MIME type
- (unknown)
- Detected type
- JAR
- SHA-256
- 806c971227130c677f10cb4b76a21498c12f55dca66fd1ca560d0717cddefd50
- MD5
- 685c79991f66ec5821e5caa79040ca1d
- SHA-1
- dbec28f3972b9b66de05ea8aab93ee0ba2606ddb
- First seen (VT)
- 10/4/2025, 12:25:16 PM
- Last analysis (VT)
- 6/15/2026, 10:40:19 AM
- First scan (MalwareTips)
- 6/29/2026, 8:57:05 AM
- Last scan (MalwareTips)
- 6/29/2026, 8:57:05 AM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.