File name:

minecraft-alpha-1.2.3-03.zip

Full analysis: https://app.any.run/tasks/acaf3df1-45e5-4e81-9de9-6d0129a1e9f4
Verdict: Malicious activity
Analysis date: March 23, 2024, 18:23:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
minecraft
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

8B4C542ED7EB90B6B9C75EDA665A271C

SHA1:

4EE3493FEF2EFB2FDD3CC6AE771BFDB455CFABB3

SHA256:

A2EAF7DCC240265CE058C62DB7C1A4B394BBDA34F014F098C0EF3422F0682A30

SSDEEP:

98304:YxNe0yiockN6MTv1QZtIxKbRfOOHKoY25faFENq7fF+cwF/LNB23RmcawhCRwz8+:HtrtG6zgH/YJWVGP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Checks for Java to be installed

      • java.exe (PID: 748)
      • java.exe (PID: 1624)
  • INFO

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3936)
    • Checks supported languages

      • java.exe (PID: 748)
      • java.exe (PID: 1624)
    • Create files in a temporary directory

      • java.exe (PID: 748)
      • java.exe (PID: 1624)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3936)
    • Manual execution by a user

      • cmd.exe (PID: 3684)
      • taskmgr.exe (PID: 1772)
      • cmd.exe (PID: 968)
    • Reads the machine GUID from the registry

      • java.exe (PID: 748)
      • java.exe (PID: 1624)
    • Reads the computer name

      • java.exe (PID: 748)
      • java.exe (PID: 1624)
    • Creates files in the program directory

      • java.exe (PID: 748)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2023:07:01 08:34:16
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Minecraft alpha 1.2.3_03/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
7
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe cmd.exe no specs java.exe no specs icacls.exe no specs taskmgr.exe no specs cmd.exe no specs java.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
240C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)MC:\Windows\System32\icacls.exejava.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
748java -Xmx1024M -Xms1024M -cp Minecraft.jar "-Dorg.lwjgl.librarypath=C:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03/natives" "-Dnet.java.games.input.librarypath=C:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03/natives" rlC:\Program Files\Common Files\Oracle\Java\javapath_target_52116515\java.execmd.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Version:
8.0.2710.9
Modules
Images
c:\program files\common files\oracle\java\javapath_target_52116515\java.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
968C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\ᅠ.bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1624java -Xmx1024M -Xms1024M -cp Minecraft.jar "-Dorg.lwjgl.librarypath=C:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03/natives" "-Dnet.java.games.input.librarypath=C:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03/natives" rlC:\Program Files\Common Files\Oracle\Java\javapath_target_52116515\java.execmd.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Version:
8.0.2710.9
Modules
Images
c:\program files\common files\oracle\java\javapath_target_52116515\java.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1772"C:\Windows\system32\taskmgr.exe" /4C:\Windows\System32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3684C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\ᅠ.bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3936"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
5 956
Read events
5 941
Write events
15
Delete events
0

Modification events

(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3936) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03.zip
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
8
Suspicious files
1 191
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\jars\saves\World1\0\18\c.0.-k.datcompressed
MD5:A104C2C871A920E9B510B63193475CC8
SHA256:25FF110E314A7AC4997F362D92AE4E790E6964F2937A5AAB40B932B55FD7B855
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\jars\saves\World1\0\19\c.0.-j.datcompressed
MD5:66AFB9DCFD48A5C7AB3551804C38E672
SHA256:A9E45645597ED5F2C38CC0A0449458C8AFA82CDD9F629DD09C825A9A1A8F75E3
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\jars\saves\World1\0\15\c.0.-n.datcompressed
MD5:5E9316AD7FE7966F328F02B6E8DA0137
SHA256:904825ACB90EAA368164E1FD968C99A2742C419A2DF98A5786B00D241F3BE7ED
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\jars\saves\World1\0\14\c.0.-o.datcompressed
MD5:2D058072D3F07E5BAE9A321B4F903E62
SHA256:471BB014D8D61143EDDF521FA1877623994FF3E888860D593DAD8F1F88E3B39E
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\jars\saves\World1\0\1\c.0.1.datcompressed
MD5:9192459A385BF6877E7D5AA35251CEA1
SHA256:DEABB3A7E5301DFD6405D43F376C5EBE0E544660616D94A03BFE51F1265FFBDE
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\jars\saves\World1\0\17\c.0.-l.datcompressed
MD5:C3B17330E5CC771BE4C13158BCD5E3F0
SHA256:A83D72488EB464ED5467EA1D463AEE8E29B28C9146FDE8DDB4566DE70C3653F3
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\jars\options.txttext
MD5:943C9549109C15A00E593E9EDDBB736F
SHA256:F6D573592D363B4B32F31ECB9672AA456D99A77921B0B617EC1DBECDFB7D993D
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\jars\saves\World1\0\0\c.0.0.datcompressed
MD5:3119761084B131391470BB8F99432B1C
SHA256:A5C6DAAC557BA4C0BE5047CD69E1B05DFDEC6840C89F6292799F366D7F4E049E
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\jars\saves\World1\0\1c\c.0.-g.datcompressed
MD5:FEFCD29796510E93B81F2EB34E4D4C3A
SHA256:84CE4838D2B92DF048D068EB10008A26EB15A263C9AF7DE803E0D73B22210958
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\jars\saves\World1\0\1f\c.0.-d.datcompressed
MD5:1AF8EC137DEBF23EDA88B42F0D3A7B26
SHA256:4F11647C281DD2AD3B08FE093CE886C3E170BADC25DC98BDD27D0F70001FF1A8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
unknown
4
System
192.168.100.255:137
unknown
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info