File name:

minecraft-alpha-1.2.3-03.zip

Full analysis: https://app.any.run/tasks/acaf3df1-45e5-4e81-9de9-6d0129a1e9f4
Verdict: Malicious activity
Analysis date: March 23, 2024, 18:23:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
minecraft
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

8B4C542ED7EB90B6B9C75EDA665A271C

SHA1:

4EE3493FEF2EFB2FDD3CC6AE771BFDB455CFABB3

SHA256:

A2EAF7DCC240265CE058C62DB7C1A4B394BBDA34F014F098C0EF3422F0682A30

SSDEEP:

98304:YxNe0yiockN6MTv1QZtIxKbRfOOHKoY25faFENq7fF+cwF/LNB23RmcawhCRwz8+:HtrtG6zgH/YJWVGP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Checks for Java to be installed

      • java.exe (PID: 748)
      • java.exe (PID: 1624)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3936)
    • Checks supported languages

      • java.exe (PID: 748)
      • java.exe (PID: 1624)
    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3936)
    • Manual execution by a user

      • cmd.exe (PID: 3684)
      • taskmgr.exe (PID: 1772)
      • cmd.exe (PID: 968)
    • Create files in a temporary directory

      • java.exe (PID: 748)
      • java.exe (PID: 1624)
    • Creates files in the program directory

      • java.exe (PID: 748)
    • Reads the machine GUID from the registry

      • java.exe (PID: 748)
      • java.exe (PID: 1624)
    • Reads the computer name

      • java.exe (PID: 748)
      • java.exe (PID: 1624)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2023:07:01 08:34:16
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Minecraft alpha 1.2.3_03/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
7
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe cmd.exe no specs java.exe no specs icacls.exe no specs taskmgr.exe no specs cmd.exe no specs java.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
240C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)MC:\Windows\System32\icacls.exejava.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
748java -Xmx1024M -Xms1024M -cp Minecraft.jar "-Dorg.lwjgl.librarypath=C:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03/natives" "-Dnet.java.games.input.librarypath=C:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03/natives" rlC:\Program Files\Common Files\Oracle\Java\javapath_target_52116515\java.execmd.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Version:
8.0.2710.9
Modules
Images
c:\program files\common files\oracle\java\javapath_target_52116515\java.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
968C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\ᅠ.bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1624java -Xmx1024M -Xms1024M -cp Minecraft.jar "-Dorg.lwjgl.librarypath=C:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03/natives" "-Dnet.java.games.input.librarypath=C:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03/natives" rlC:\Program Files\Common Files\Oracle\Java\javapath_target_52116515\java.execmd.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Version:
8.0.2710.9
Modules
Images
c:\program files\common files\oracle\java\javapath_target_52116515\java.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1772"C:\Windows\system32\taskmgr.exe" /4C:\Windows\System32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3684C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\ᅠ.bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3936"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
5 956
Read events
5 941
Write events
15
Delete events
0

Modification events

(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3936) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03.zip
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3936) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
8
Suspicious files
1 191
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\jars\saves\World1\0\0\c.0.0.datcompressed
MD5:3119761084B131391470BB8F99432B1C
SHA256:A5C6DAAC557BA4C0BE5047CD69E1B05DFDEC6840C89F6292799F366D7F4E049E
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\jars\saves\World1\0\13\c.0.-p.datcompressed
MD5:9888C0C1A1655EBC54A04BF8E051D51E
SHA256:9CBDF73F908DDFC18EB648773F47330E5CAE5CC9022C506993B3811AE2A74BD9
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\jars\saves\World1\0\1a\c.0.-i.datcompressed
MD5:3044EED400F4DCD5C1407B842543A37A
SHA256:E559C270E087E80D28AFF5B73EB8C8919B6C4F674AF66B8EC121529E380BE23D
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\jars\options.txttext
MD5:943C9549109C15A00E593E9EDDBB736F
SHA256:F6D573592D363B4B32F31ECB9672AA456D99A77921B0B617EC1DBECDFB7D993D
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\jars\saves\World1\0\14\c.0.-o.datcompressed
MD5:2D058072D3F07E5BAE9A321B4F903E62
SHA256:471BB014D8D61143EDDF521FA1877623994FF3E888860D593DAD8F1F88E3B39E
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\jars\saves\World1\0\1\c.0.1.datcompressed
MD5:9192459A385BF6877E7D5AA35251CEA1
SHA256:DEABB3A7E5301DFD6405D43F376C5EBE0E544660616D94A03BFE51F1265FFBDE
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\jars\saves\World1\0\1d\c.0.-f.datcompressed
MD5:63A011B4EA81535A1AC78676E0F3DB11
SHA256:3403E50AF299E876E974E69EEAB02B36CB72BABF883113EF2B19CA4163EFA174
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\jars\saves\World1\0\1e\c.0.-e.datcompressed
MD5:56430589B0F397548151BDA9600F39A0
SHA256:EA77BFF26BAFB04A5BC60A55CBF22C377015871F927B4572D7E3A35A6CFA7065
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\jars\saves\World1\0\18\c.0.-k.datcompressed
MD5:A104C2C871A920E9B510B63193475CC8
SHA256:25FF110E314A7AC4997F362D92AE4E790E6964F2937A5AAB40B932B55FD7B855
3936WinRAR.exeC:\Users\admin\AppData\Local\Temp\minecraft-alpha-1.2.3-03\Minecraft alpha 1.2.3_03\jars\saves\World1\0\19\c.0.-j.datcompressed
MD5:66AFB9DCFD48A5C7AB3551804C38E672
SHA256:A9E45645597ED5F2C38CC0A0449458C8AFA82CDD9F629DD09C825A9A1A8F75E3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info