File name: | MinecraftLauncher.exe |
Full analysis: | https://app.any.run/tasks/5c9ae465-799d-454d-8b7f-745aa9b3642d |
Verdict: | Malicious activity |
Analysis date: | November 30, 2020, 01:09:25 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 4ABAFE5E8B2ECA4BA677248370F5510B |
SHA1: | ABD8B957A8322D4FC6B34B949AC65CCB4A77E9ED |
SHA256: | 7466B0D856AB3734031C3BAAF7DC7553F725B4EC6F145DC366E927EA944E094A |
SSDEEP: | 49152:cljHdG8GcuzCO4XKaYRwXUtyqcM8pdIcA69j7GUsRTd8sxjOPJnUl68QFy13Tgbp:MjxDuzCOQg+9j7YdOPJ8xQx |
.exe | | | Win64 Executable (generic) (64.6) |
---|---|---|
.dll | | | Win32 Dynamic Link Library (generic) (15.4) |
.exe | | | Win32 Executable (generic) (10.5) |
.exe | | | Generic Win/DOS Executable (4.6) |
.exe | | | DOS Executable Generic (4.6) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2020:09:29 11:05:10+02:00 |
PEType: | PE32 |
LinkerVersion: | 14 |
CodeSize: | 1185792 |
InitializedDataSize: | 1767936 |
UninitializedDataSize: | - |
EntryPoint: | 0xd4381 |
OSVersion: | 5.1 |
ImageVersion: | - |
SubsystemVersion: | 5.1 |
Subsystem: | Windows GUI |
FileVersionNumber: | 1.0.1.0 |
ProductVersionNumber: | 1.0.1.0 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Windows NT 32-bit |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | English (U.S.) |
CharacterSet: | Unicode |
CompanyName: | Mojang |
FileDescription: | Minecraft launcher |
FileVersion: | 1.0.1.0 |
InternalName: | MinecraftLauncher |
LegalCopyright: | Copyright (C) 2016 Mojang |
OriginalFileName: | MinecraftLauncher.exe |
ProductName: | Minecraft |
ProductVersion: | 1.0.1.0 |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 29-Sep-2020 09:05:10 |
Detected languages: |
|
CompanyName: | Mojang |
FileDescription: | Minecraft launcher |
FileVersion: | 1.0.1.0 |
InternalName: | MinecraftLauncher |
LegalCopyright: | Copyright (C) 2016 Mojang |
OriginalFilename: | MinecraftLauncher.exe |
ProductName: | Minecraft |
ProductVersion: | 1.0.1.0 |
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x0090 |
Pages in file: | 0x0003 |
Relocations: | 0x0000 |
Size of header: | 0x0004 |
Min extra paragraphs: | 0x0000 |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x00B8 |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0000 |
Overlay number: | 0x0000 |
OEM identifier: | 0x0000 |
OEM information: | 0x0000 |
Address of NE header: | 0x00000110 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 7 |
Time date stamp: | 29-Sep-2020 09:05:10 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0012160F | 0x00121800 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.54671 |
.rdata | 0x00123000 | 0x00040C88 | 0x00040E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.42202 |
.data | 0x00164000 | 0x0001219C | 0x0000D400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.18788 |
.tls | 0x00177000 | 0x00000055 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0203931 |
.gfids | 0x00178000 | 0x0000102C | 0x00001200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.78005 |
.rsrc | 0x0017A000 | 0x0014B230 | 0x0014B400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.52075 |
.reloc | 0x002C6000 | 0x00010068 | 0x00010200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.62596 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 5.00927 | 1555 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 5.70087 | 4264 | UNKNOWN | Swedish - Sweden | RT_ICON |
3 | 5.56546 | 9640 | UNKNOWN | Swedish - Sweden | RT_ICON |
4 | 5.46909 | 16936 | UNKNOWN | Swedish - Sweden | RT_ICON |
5 | 5.26597 | 67624 | UNKNOWN | Swedish - Sweden | RT_ICON |
6 | 5.18146 | 270376 | UNKNOWN | Swedish - Sweden | RT_ICON |
9 | 3.18894 | 328 | UNKNOWN | English - United States | RT_DIALOG |
101 | 2.76511 | 90 | UNKNOWN | Swedish - Sweden | RT_GROUP_ICON |
ADVAPI32.dll |
COMCTL32.dll |
CRYPT32.dll |
KERNEL32.dll |
SHELL32.dll |
USER32.dll |
WINHTTP.dll |
WS2_32.dll |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2712 | "C:\Users\admin\AppData\Local\Temp\MinecraftLauncher.exe" | C:\Users\admin\AppData\Local\Temp\MinecraftLauncher.exe | explorer.exe | |
User: admin Company: Mojang Integrity Level: MEDIUM Description: Minecraft launcher Version: 1.0.1.0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2712 | MinecraftLauncher.exe | C:\Users\admin\AppData\Local\Temp\MinecraftLauncher\PistonStaging\cb63ad72bc3c7ec261b542a5991492148ef3f65d | compressed | |
MD5:44CFCEFD898257EAE2C0367F0E83F622 | SHA256:16A4BE3910C60E732402F489A31B60EC90527B5F2A95F8DA34E03E9E02869223 | |||
2712 | MinecraftLauncher.exe | C:\Users\admin\AppData\Local\Temp\MinecraftLauncher\PistonStaging\12eea93d4b31c1f2c709d2eb1861f5dab991bf89 | compressed | |
MD5:A50B6B836CC1C4871EBB9D6BC3948E87 | SHA256:3EC21A68E9CC2D3C0841CEE7DBB671F4D5D08092A3F7D5775E1BB67F191A1E9C | |||
2712 | MinecraftLauncher.exe | C:\Users\admin\AppData\Local\Temp\MinecraftLauncher\PistonStaging\dbb494c8cb44a88fd072909062270558be73b39e | compressed | |
MD5:6EAD1DC9F7E19C8D5DFFD071CFA67F9A | SHA256:F3A830E12CAECF66C270029CCA8F27A649ADDEA8D8B77605564E1D05F2E54E03 | |||
2712 | MinecraftLauncher.exe | C:\Users\admin\AppData\Local\Temp\MinecraftLauncher\PistonStaging\d75a0594f6c7b264dd83da4666a69687cb905d9c | compressed | |
MD5:5C3A92058F00CEA17E2BEA7121AD707E | SHA256:B41CCEECCBF11BE05D9091FE989FB2A1E3257D737FEA80C05727C5952E977E84 | |||
2712 | MinecraftLauncher.exe | C:\Users\admin\AppData\Local\Temp\MinecraftLauncher\PistonStaging\dbb91a14563712ee6d7b6361ead29ef43c89fe80 | compressed | |
MD5:66893964E05CC180B5BBB76ED6826F7F | SHA256:124F65D9AA9E5502D5042BDA9B4DF1FD46EFA5AD1957741119ECC5946EA344C6 | |||
2712 | MinecraftLauncher.exe | C:\Users\admin\AppData\Local\Temp\MinecraftLauncher\PistonStaging\bfece2935ed71c3ab20da9c01694c5fe42d63b48 | compressed | |
MD5:45005E95DCDA6636557E20E089DFD32E | SHA256:6861B3D4BC2F13C0443305B347624F2F849DF9905F70CBD4E4515D9A88D14F54 | |||
2712 | MinecraftLauncher.exe | C:\Users\admin\AppData\Local\Temp\MinecraftLauncher\PistonStaging\319726763f9df0faa54fe37d82076ee99840fd2a | compressed | |
MD5:BA7498836331C72D25C1C7613AC1A37F | SHA256:F52A8E098D91F46A1323193487360A43E92E60952D9B008670BF28B3B2C4C579 | |||
2712 | MinecraftLauncher.exe | C:\Users\admin\AppData\Local\Temp\MinecraftLauncher\PistonStaging\aa701676552d4f445327fe30c3386ec7a72680f3 | compressed | |
MD5:7FBE28FAB7F3BBA41F2786D34A1976B6 | SHA256:D860BCC05E3C59CA17EB37866C5752E9D7CAC28FA4B6EC90F9AC7AFA87B8D8D3 | |||
2712 | MinecraftLauncher.exe | C:\Users\admin\AppData\Local\Temp\MinecraftLauncher\PistonStaging\af39c13f70bc9c0aa775c44eb1632d49e620d463 | compressed | |
MD5:9A9B1738744A6208954B9F8BAAB07A14 | SHA256:7217B545B389110ECDD87861952740559B0EEE147ACB6640472C30BBA93725A1 | |||
2712 | MinecraftLauncher.exe | C:\Users\admin\AppData\Local\Temp\MinecraftLauncher\PistonStaging\36877948bd2ecdc9ae97dcd5eb9997c1d9ae45f4 | compressed | |
MD5:9D0761D1A9D36C10A0FF8D6B32794AA6 | SHA256:264613E8238642F9D276BEFF671D980FC9A2A4699A0C10E06A82754F23E44990 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2712 | MinecraftLauncher.exe | 65.9.7.20:443 | launchermeta.mojang.com | AT&T Services, Inc. | US | suspicious |
Domain | IP | Reputation |
---|---|---|
launchermeta.mojang.com |
| whitelisted |
launcher.mojang.com |
| whitelisted |