File name:

HMCL-3.5.5.exe

Full analysis: https://app.any.run/tasks/122b7215-66d5-420c-a230-c36eae110ed8
Verdict: Malicious activity
Analysis date: February 18, 2024, 22:53:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

B8BBBA8CD778E2DAE662AADD3F7C8A3F

SHA1:

B416350BD1F6D23E69B7B7EF7A4B69B7110D79BD

SHA256:

BD34D38FE56F0ED1337FEDAD96A4BB97A1EE1E5288766596D2E28C36E9E31924

SSDEEP:

98304:BtTUZEXyY+wDuUggN9+qLbqmG5y5KgDowAOrEXNhWVNhCjo0luef+zSJuOD2BeM9:6sRKTFJNwBo2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • HMCL-3.5.5.exe (PID: 4052)
  • SUSPICIOUS

    • Checks for Java to be installed

      • HMCL-3.5.5.exe (PID: 4052)
      • java.exe (PID: 1560)
    • Starts CMD.EXE for commands execution

      • javaw.exe (PID: 3656)
    • Reads the Internet Settings

      • javaw.exe (PID: 3656)
  • INFO

    • Checks proxy server information

      • javaw.exe (PID: 3656)
    • Checks supported languages

      • javaw.exe (PID: 3656)
      • HMCL-3.5.5.exe (PID: 4052)
      • java.exe (PID: 1560)
    • Creates files in the program directory

      • javaw.exe (PID: 3656)
    • Create files in a temporary directory

      • javaw.exe (PID: 3656)
      • java.exe (PID: 1560)
    • Checks operating system version

      • javaw.exe (PID: 3656)
    • Reads the computer name

      • javaw.exe (PID: 3656)
    • Creates files or folders in the user directory

      • javaw.exe (PID: 3656)
    • Reads the machine GUID from the registry

      • javaw.exe (PID: 3656)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:11:05 12:09:55+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 58368
InitializedDataSize: 43008
UninitializedDataSize: -
EntryPoint: 0x37ed
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 3.4.0.0
ProductVersionNumber: 3.4.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: huanghongxun
FileDescription: Hello Minecraft! Launcher For Windows
FileVersion: 3.5.0.0
InternalName: HMCL.exe
LegalCopyright: Copyright (C) 2021 huangyuhui
OriginalFileName: HMCL.exe
ProductName: Hello Minecraft! Launcher
ProductVersion: 3.5.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
64
Monitored processes
19
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start hmcl-3.5.5.exe no specs javaw.exe icacls.exe no specs cmd.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs java.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
796reg query HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\JRE\C:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1560"C:\Program Files\Common Files\Oracle\Java\javapath_target_52116515\java.exe" -XshowSettings:properties -versionC:\Program Files\Common Files\Oracle\Java\javapath_target_52116515\java.exejavaw.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
8.0.2710.9
Modules
Images
c:\program files\common files\oracle\java\javapath_target_52116515\java.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1972reg query "HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Development Kit\\"C:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2184reg query HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\JDK\C:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2408cmd /c reg query "HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment\1.8.0_271" /v JavaHomeC:\Windows\System32\cmd.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2580cmd /c reg query "HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment\1.8"C:\Windows\System32\cmd.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2672reg query "HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment\1.8.0_271" /v JavaHomeC:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2792cmd /c reg query "HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Development Kit\\"C:\Windows\System32\cmd.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2960cmd /c reg query HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\JRE\C:\Windows\System32\cmd.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3216cmd verC:\Windows\System32\cmd.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
2 201
Read events
2 200
Write events
1
Delete events
0

Modification events

(PID) Process:(3656) javaw.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
javaw.exe
Executable files
0
Suspicious files
0
Text files
8
Unknown types
5

Dropped files

PID
Process
Filename
Type
3656javaw.exeC:\Users\admin\AppData\Local\Temp\.hmcl.json.tmptext
MD5:8DC614CD75A466E89603284DC7D37EAE
SHA256:A968A3E0555D0E6DEC57BCFAED244E38BF26CDED3DEB6AE1CDC84EEFE044326D
3656javaw.exeC:\Users\admin\AppData\Roaming\.hmcl\.config.json.tmpbinary
MD5:AFE1BA2FAA51DBD985E5DFFC60D6CD04
SHA256:2E59FA757C9D25E25FC02FB740F7AD598D8F17E5AF1EC00DBB295CCE72DE6D1F
3656javaw.exeC:\Users\admin\AppData\Local\Temp\hmcl.jsontext
MD5:8DC614CD75A466E89603284DC7D37EAE
SHA256:A968A3E0555D0E6DEC57BCFAED244E38BF26CDED3DEB6AE1CDC84EEFE044326D
3656javaw.exeC:\Users\admin\AppData\Roaming\.hmcl\config.jsonbinary
MD5:AFE1BA2FAA51DBD985E5DFFC60D6CD04
SHA256:2E59FA757C9D25E25FC02FB740F7AD598D8F17E5AF1EC00DBB295CCE72DE6D1F
3656javaw.exeC:\ProgramData\Oracle\Java\.oracle_jre_usage\17dfc292991c8061.timestamptext
MD5:B48BE962E494D992DE6F63C2989597A6
SHA256:C8DEEBD353E8155DAC8D8237FE9FC95D011A69FB95A33E43CB99A3D585F4F0D8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
7
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3656
javaw.exe
104.21.0.107:443
littleskin.cn
CLOUDFLARENET
unknown
3656
javaw.exe
43.152.26.154:443
download.mcbbs.net
ACE
DE
unknown
3656
javaw.exe
1.117.239.163:443
hmcl.huangyuhui.net
Shenzhen Tencent Computer Systems Company Limited
CN
unknown

DNS requests

Domain
IP
Reputation
littleskin.cn
  • 104.21.0.107
  • 172.67.185.194
unknown
download.mcbbs.net
  • 43.152.26.154
  • 43.152.26.142
  • 43.152.26.151
  • 43.152.26.221
  • 43.152.44.160
  • 43.152.26.104
  • 43.152.26.197
  • 43.152.26.58
unknown
hmcl.huangyuhui.net
  • 1.117.239.163
unknown

Threats

No threats detected
No debug info