File name:

liteloader-installer-1.12.2-00-SNAPSHOT.jar

Full analysis: https://app.any.run/tasks/2ebde985-75e9-4931-b268-f8c7720c6729
Verdict: No threats detected
Analysis date: July 27, 2020, 03:55:24
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract
MD5:

968B3CEAA2E4CB9A779A02D8BF02D7AF

SHA1:

E9AC0BA10DC6D4B33B607446C73B4DEAEE354B1E

SHA256:

28B26E1397B2FDDC5A0E43B79A44B61229E4D26E6A57F4E2E972C6E48D4E70F5

SSDEEP:

98304:LpPgV4FKxwGu2mxIlRVwGuvrbq0VpLzJW9GbwmXq3y13i:L2VR02mxIlRVwr31VpQSFXq3y1S

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Creates files in the user directory

      • javaw.exe (PID: 2528)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.jar | Java Archive (50)
.litemod | Minecraft LiteLoader Mod (36.2)
.zip | ZIP compressed archive (13.7)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: 0x0800
ZipCompression: Deflated
ZipModifyDate: 2017:11:28 14:45:05
ZipCRC: 0x00000000
ZipCompressedSize: 2
ZipUncompressedSize: -
ZipFileName: META-INF/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
1
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start javaw.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2528"C:\Program Files\Java\jre1.8.0_92\bin\javaw.exe" -jar "C:\Users\admin\AppData\Local\Temp\liteloader-installer-1.12.2-00-SNAPSHOT.jar"C:\Program Files\Java\jre1.8.0_92\bin\javaw.exeexplorer.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
8.0.920.14
Modules
Images
c:\program files\java\jre1.8.0_92\bin\javaw.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
421
Read events
414
Write events
7
Delete events
0

Modification events

(PID) Process:(2528) javaw.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
javaw.exe
(PID) Process:(2528) javaw.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\132\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
1
Suspicious files
0
Text files
1
Unknown types
1

Dropped files

PID
Process
Filename
Type
2528javaw.exeC:\Users\admin\AppData\Local\Temp\imageio3529379309558392977.tmp
MD5:
SHA256:
2528javaw.exeC:\Users\admin\AppData\Local\Temp\imageio1388854454467938055.tmp
MD5:
SHA256:
2528javaw.exeC:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamptext
MD5:
SHA256:
2528javaw.exeC:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\83aa4cc77f591dfc2374580bbd95f6ba_90059c37-1320-41a4-b58d-2b75a9850d2fdbf
MD5:C8366AE350E7019AEFC9D1E6E6A498C6
SHA256:11E6ACA8E682C046C83B721EEB5C72C5EF03CB5936C60DF6F4993511DDC61238
2528javaw.exeC:\Users\admin\Desktop\liteloader-1.12.2-SNAPSHOT-release.jarjava
MD5:1420785ECBFED5AFF4A586C5C9DD97EB
SHA256:D7D6DBFB704E5E4393D4337C4AF0BA21F680A6D42B36DDAE4A2C7DB59885D30E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info