File name:

HMCL-3.5.5.exe

Full analysis: https://app.any.run/tasks/86157bd4-6354-4cc1-bd66-a1554a5e9ff5
Verdict: Malicious activity
Analysis date: January 01, 2024, 23:34:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

B8BBBA8CD778E2DAE662AADD3F7C8A3F

SHA1:

B416350BD1F6D23E69B7B7EF7A4B69B7110D79BD

SHA256:

BD34D38FE56F0ED1337FEDAD96A4BB97A1EE1E5288766596D2E28C36E9E31924

SSDEEP:

98304:BtTUZEXyY+wDuUggN9+qLbqmG5y5KgDowAOrEXNhWVNhCjo0luef+zSJuOD2BeM9:6sRKTFJNwBo2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Checks for Java to be installed

      • HMCL-3.5.5.exe (PID: 124)
      • java.exe (PID: 2336)
    • Starts CMD.EXE for commands execution

      • javaw.exe (PID: 1432)
    • Reads the Internet Settings

      • javaw.exe (PID: 1432)
      • rundll32.exe (PID: 1768)
    • Uses RUNDLL32.EXE to load library

      • javaw.exe (PID: 1432)
  • INFO

    • Checks supported languages

      • HMCL-3.5.5.exe (PID: 124)
      • javaw.exe (PID: 1432)
      • java.exe (PID: 2336)
    • Creates files in the program directory

      • javaw.exe (PID: 1432)
    • Drops the executable file immediately after the start

      • HMCL-3.5.5.exe (PID: 124)
    • Create files in a temporary directory

      • javaw.exe (PID: 1432)
      • java.exe (PID: 2336)
    • Checks operating system version

      • javaw.exe (PID: 1432)
    • Reads the computer name

      • javaw.exe (PID: 1432)
    • Creates files or folders in the user directory

      • javaw.exe (PID: 1432)
    • Reads the machine GUID from the registry

      • javaw.exe (PID: 1432)
    • Checks proxy server information

      • javaw.exe (PID: 1432)
    • Application launched itself

      • msedge.exe (PID: 2584)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:11:05 13:09:55+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 58368
InitializedDataSize: 43008
UninitializedDataSize: -
EntryPoint: 0x37ed
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 3.4.0.0
ProductVersionNumber: 3.4.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: huanghongxun
FileDescription: Hello Minecraft! Launcher For Windows
FileVersion: 3.5.0.0
InternalName: HMCL.exe
LegalCopyright: Copyright (C) 2021 huangyuhui
OriginalFileName: HMCL.exe
ProductName: Hello Minecraft! Launcher
ProductVersion: 3.5.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
80
Monitored processes
38
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start hmcl-3.5.5.exe no specs javaw.exe icacls.exe no specs cmd.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs cmd.exe no specs reg.exe no specs java.exe no specs rundll32.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
124"C:\Users\admin\AppData\Local\Temp\HMCL-3.5.5.exe" C:\Users\admin\AppData\Local\Temp\HMCL-3.5.5.exeexplorer.exe
User:
admin
Company:
huanghongxun
Integrity Level:
MEDIUM
Description:
Hello Minecraft! Launcher For Windows
Exit code:
0
Version:
3.5.0.0
Modules
Images
c:\users\admin\appdata\local\temp\hmcl-3.5.5.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
712reg query "HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment\1.8.0_271"C:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
844reg query "HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment\1.8.0_271" /v JavaHomeC:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
956reg query "HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment\1.8"C:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1236cmd /c reg query "HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Runtime Environment\1.8"C:\Windows\System32\cmd.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1432"C:\Program Files\Java\jre1.8.0_271\bin\javaw.exe" -XX:MinHeapFreeRatio=5 -XX:MaxHeapFreeRatio=15 -jar "HMCL-3.5.5.exe"C:\Program Files\Java\jre1.8.0_271\bin\javaw.exe
HMCL-3.5.5.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
8.0.2710.9
Modules
Images
c:\program files\java\jre1.8.0_271\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1540reg query "HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Development Kit\\"C:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1560cmd /c reg query HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\JDK\C:\Windows\System32\cmd.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1740cmd /c reg query "HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\Java Development Kit\\"C:\Windows\System32\cmd.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1748reg query HKEY_LOCAL_MACHINE\SOFTWARE\JavaSoft\JDK\C:\Windows\System32\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
2 798
Read events
2 775
Write events
22
Delete events
1

Modification events

(PID) Process:(1432) javaw.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Explorer.EXE
(PID) Process:(2584) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2584) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2584) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(2584) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2584) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:dr
Value:
1
(PID) Process:(2584) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
1
(PID) Process:(2584) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1302019708-1500728564-335382590-1000
Value:
8A1A1F2B695E2F00
(PID) Process:(2584) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge
Operation:writeName:UsageStatsInSample
Value:
1
(PID) Process:(2584) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:usagestats
Value:
1
Executable files
1
Suspicious files
94
Text files
48
Unknown types
0

Dropped files

PID
Process
Filename
Type
2584msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RFe6b48.TMP
MD5:
SHA256:
2584msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
1432javaw.exeC:\Users\admin\AppData\Local\Temp\.hmcl.json.tmpbinary
MD5:9BE5553489C6CBDE5DDBC9A6C9558329
SHA256:C72807872B254227DEA579EC0A6AE5DC5D7BECA589D3C65D9E215E58C3C2065E
1432javaw.exeC:\Users\admin\AppData\Roaming\.minecraft\cache\SHA-1\c0\c011ed2b4d3ec272a9dc36144db86499b052ecf3compressed
MD5:FD70567223228D171357FFD59B000F71
SHA256:795B276CB40855ED04DC7FCABC2A6D150DE4600B542875A6522E65F6B25BCA9F
1432javaw.exeC:\Users\admin\AppData\Roaming\.minecraft\cache\etag.jsonbinary
MD5:FF4E54EF156194E3A66CCEEAE0CD237A
SHA256:702E82D123FE33039AC23DB1C78D579EC0E66591021F4DCC9C7F970C2222624F
2584msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RFe6ba6.TMP
MD5:
SHA256:
2584msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old
MD5:
SHA256:
1432javaw.exeC:\Users\admin\AppData\Roaming\.hmcl\.config.json.tmpbinary
MD5:AFE1BA2FAA51DBD985E5DFFC60D6CD04
SHA256:2E59FA757C9D25E25FC02FB740F7AD598D8F17E5AF1EC00DBB295CCE72DE6D1F
2584msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Variationsbinary
MD5:961E3604F228B0D10541EBF921500C86
SHA256:F7B24F2EB3D5EB0550527490395D2F61C3D2FE74BB9CB345197DAD81B58B5FED
2760msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\CrashpadMetrics.pmabinary
MD5:C612E96CBFAC63232FC2062E15600FB1
SHA256:DB3C05D5EC0B6719A73E7F0BE84BCE9342772DA70567E7CE08CF6573480B38FF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
28
DNS requests
49
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
1432
javaw.exe
43.152.26.142:443
download.mcbbs.net
ACE
DE
unknown
1432
javaw.exe
172.67.185.194:443
littleskin.cn
CLOUDFLARENET
US
unknown
1432
javaw.exe
1.117.239.163:443
hmcl.huangyuhui.net
Shenzhen Tencent Computer Systems Company Limited
CN
unknown
1432
javaw.exe
20.190.159.64:443
login.microsoftonline.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2672
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2584
msedge.exe
239.255.255.250:1900
whitelisted
2672
msedge.exe
104.119.109.218:443
www.microsoft.com
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
download.mcbbs.net
  • 43.152.26.142
  • 43.152.26.151
  • 43.152.26.197
  • 43.152.44.160
  • 43.152.26.154
  • 43.152.26.58
  • 43.152.26.104
  • 43.152.26.221
unknown
littleskin.cn
  • 172.67.185.194
  • 104.21.0.107
unknown
hmcl.huangyuhui.net
  • 1.117.239.163
unknown
login.microsoftonline.com
  • 20.190.159.64
  • 40.126.31.73
  • 20.190.159.23
  • 20.190.159.4
  • 20.190.159.68
  • 20.190.159.75
  • 20.190.159.71
  • 20.190.159.2
unknown
config.edge.skype.com
  • 13.107.42.16
unknown
www.microsoft.com
  • 104.119.109.218
unknown
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
unknown
nav-edge.smartscreen.microsoft.com
  • 20.103.180.120
unknown
login.live.com
  • 40.126.32.72
  • 40.126.32.136
  • 20.190.160.22
  • 20.190.160.14
  • 40.126.32.68
  • 40.126.32.138
  • 20.190.160.17
  • 40.126.32.140
unknown
data-edge.smartscreen.microsoft.com
  • 20.103.180.120
unknown

Threats

No threats detected
No debug info