File name:

Plain Craft Launcher 2.exe

Full analysis: https://app.any.run/tasks/e0802023-0113-45b3-85c9-1579bc9b3638
Verdict: Malicious activity
Analysis date: February 18, 2024, 22:59:20
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

5C448C56420F40C829276CF1E0C33B08

SHA1:

F12EE57EB98AA48AD74C4C32F52F83E3D2597564

SHA256:

BE7D9F01527AFC929C139DC39FB796FEAA877CC75478920E8196CD61279E79FE

SSDEEP:

98304:9zy0IlFpepUHS2d7AXrLEruX85hNzcfyvLNwo7es1VjWnx2bMmj0WllEpQeDcFqj:uSwXs

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Plain Craft Launcher 2.exe (PID: 3864)
      • Plain Craft Launcher 2.exe (PID: 2408)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Plain Craft Launcher 2.exe (PID: 3864)
      • Plain Craft Launcher 2.exe (PID: 2408)
      • Plain Craft Launcher 2.exe (PID: 1496)
    • Reads settings of System Certificates

      • Plain Craft Launcher 2.exe (PID: 3864)
      • Plain Craft Launcher 2.exe (PID: 1496)
    • Process requests binary or script from the Internet

      • Plain Craft Launcher 2.exe (PID: 3864)
    • Executable content was dropped or overwritten

      • Plain Craft Launcher 2.exe (PID: 3864)
      • Plain Craft Launcher 2.exe (PID: 2408)
    • Reads security settings of Internet Explorer

      • Plain Craft Launcher 2.exe (PID: 3864)
      • Plain Craft Launcher 2.exe (PID: 2408)
    • Starts itself from another location

      • Plain Craft Launcher 2.exe (PID: 2408)
  • INFO

    • Checks supported languages

      • Plain Craft Launcher 2.exe (PID: 3864)
      • java.exe (PID: 3948)
      • Plain Craft Launcher 2.exe (PID: 2408)
      • Plain Craft Launcher 2.exe (PID: 1496)
      • java.exe (PID: 1560)
    • Reads the computer name

      • Plain Craft Launcher 2.exe (PID: 3864)
      • Plain Craft Launcher 2.exe (PID: 2408)
      • Plain Craft Launcher 2.exe (PID: 1496)
    • Reads the machine GUID from the registry

      • Plain Craft Launcher 2.exe (PID: 3864)
      • Plain Craft Launcher 2.exe (PID: 2408)
      • Plain Craft Launcher 2.exe (PID: 1496)
    • Create files in a temporary directory

      • Plain Craft Launcher 2.exe (PID: 3864)
      • java.exe (PID: 3948)
      • Plain Craft Launcher 2.exe (PID: 2408)
      • Plain Craft Launcher 2.exe (PID: 1496)
      • java.exe (PID: 1560)
    • Reads Environment values

      • Plain Craft Launcher 2.exe (PID: 3864)
      • Plain Craft Launcher 2.exe (PID: 1496)
    • Creates files in the program directory

      • java.exe (PID: 3948)
    • Reads the software policy settings

      • Plain Craft Launcher 2.exe (PID: 3864)
      • Plain Craft Launcher 2.exe (PID: 1496)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:02:03 15:12:57+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 80
CodeSize: 2511872
InitializedDataSize: 205312
UninitializedDataSize: -
EntryPoint: 0x26737e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.2.0.9
ProductVersionNumber: 2.2.0.9
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Minecraft 启动器 (制作:龙腾猫跃)
CompanyName: -
FileDescription: Plain Craft Launcher 2 启动器
FileVersion: 2.2.0.9
InternalName: Plain Craft Launcher 2.exe
LegalCopyright: Copyright © 龙腾猫跃 2016-2021. All Rights Reserved.
OriginalFileName: Plain Craft Launcher 2.exe
ProductName: Plain Craft Launcher 2
ProductVersion: 2.2.0.9
AssemblyVersion: 2.2.0.9
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
6
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start plain craft launcher 2.exe java.exe no specs icacls.exe no specs plain craft launcher 2.exe plain craft launcher 2.exe java.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1496"C:\Users\admin\AppData\Local\Temp\Plain Craft Launcher 2.exe" C:\Users\admin\AppData\Local\Temp\Plain Craft Launcher 2.exe
Plain Craft Launcher 2.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Plain Craft Launcher 2 启动器
Exit code:
0
Version:
2.6.13.0
Modules
Images
c:\users\admin\appdata\local\temp\plain craft launcher 2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
1560"C:\Program Files\Java\jre1.8.0_271\bin\java.exe" -versionC:\Program Files\Java\jre1.8.0_271\bin\java.exePlain Craft Launcher 2.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
8.0.2710.9
Modules
Images
c:\program files\java\jre1.8.0_271\bin\java.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2408"C:\Users\admin\AppData\Local\Temp\PCL\Plain Craft Launcher 2.exe" --update 3864 "Plain Craft Launcher 2.exe" "Plain Craft Launcher 2.exe" TrueC:\Users\admin\AppData\Local\Temp\PCL\Plain Craft Launcher 2.exe
Plain Craft Launcher 2.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Plain Craft Launcher 2 启动器
Exit code:
4
Version:
2.6.13.0
Modules
Images
c:\users\admin\appdata\local\temp\pcl\plain craft launcher 2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2636C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)MC:\Windows\System32\icacls.exejava.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ntmarta.dll
3864"C:\Users\admin\AppData\Local\Temp\Plain Craft Launcher 2.exe" C:\Users\admin\AppData\Local\Temp\Plain Craft Launcher 2.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Plain Craft Launcher 2 启动器
Exit code:
4294967295
Version:
2.2.0.9
Modules
Images
c:\users\admin\appdata\local\temp\plain craft launcher 2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
3948"C:\Program Files\Java\jre1.8.0_271\bin\java.exe" -versionC:\Program Files\Java\jre1.8.0_271\bin\java.exePlain Craft Launcher 2.exe
User:
admin
Company:
Oracle Corporation
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
8.0.2710.9
Modules
Images
c:\program files\java\jre1.8.0_271\bin\java.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
20 513
Read events
20 407
Write events
106
Delete events
0

Modification events

(PID) Process:(3864) Plain Craft Launcher 2.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3864) Plain Craft Launcher 2.exeKey:HKEY_CURRENT_USER\Software\PCL
Operation:writeName:Identify
Value:
21490541972534707200
(PID) Process:(3864) Plain Craft Launcher 2.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Plain Craft Launcher 2.exe
(PID) Process:(3864) Plain Craft Launcher 2.exeKey:HKEY_CURRENT_USER\Software\PCL
Operation:writeName:SystemLastVersionReg
Value:
NyITQHxgPrM=
(PID) Process:(3864) Plain Craft Launcher 2.exeKey:HKEY_CURRENT_USER\Software\PCL
Operation:writeName:SystemHighestBetaVersionReg
Value:
NyITQHxgPrM=
(PID) Process:(3864) Plain Craft Launcher 2.exeKey:HKEY_CURRENT_USER\Software\PCL
Operation:writeName:UiLauncherThemeHide2
Value:
M5zz6IwA5XjTX4rwaoYPhA==
(PID) Process:(3864) Plain Craft Launcher 2.exeKey:HKEY_CURRENT_USER\Software\PCL
Operation:writeName:LaunchFolders
Value:
(PID) Process:(3864) Plain Craft Launcher 2.exeKey:HKEY_CURRENT_USER\Software\PCL
Operation:writeName:CacheJavaListVersion
Value:
1
(PID) Process:(3864) Plain Craft Launcher 2.exeKey:HKEY_CURRENT_USER\Software\PCL
Operation:writeName:WindowHeight
Value:
500
(PID) Process:(3864) Plain Craft Launcher 2.exeKey:HKEY_CURRENT_USER\Software\PCL
Operation:writeName:WindowWidth
Value:
810
Executable files
4
Suspicious files
2
Text files
7
Unknown types
1

Dropped files

PID
Process
Filename
Type
3864Plain Craft Launcher 2.exeC:\Users\admin\AppData\Local\Temp\.minecraft\PCL.initext
MD5:C4BA10F0814A60B6C4F4F9B95CFF47DF
SHA256:F513F5C0DD5E5DB4F2F77C14D33AA6B1050C4F233313348BFC72C4576EC80633
3948java.exeC:\ProgramData\Oracle\Java\.oracle_jre_usage\17dfc292991c8061.timestamptext
MD5:6728277A5B40FD3F37F1A79443323C41
SHA256:FB61D2AF4D0E720F1576C4DEC0C417A40C9574F74F54721DA4D255FDEAF8FB90
2408Plain Craft Launcher 2.exeC:\Users\admin\AppData\Local\Temp\Plain Craft Launcher 2.exeexecutable
MD5:BB8AA69C974CCEE9C39A6D5A950AE492
SHA256:7008B26EA9D43BAEC552FAE449A165C301D6BDE7B93656A498C01CFC538DB9A6
3864Plain Craft Launcher 2.exeC:\Users\admin\AppData\Local\Temp\PCL\Cache\download.jsontext
MD5:2F0202BBA51CD6078C711D6D06A9C8F6
SHA256:35DA044B108AE68320EEB790382981FEE092C3E239408135B9836AC65306F1FB
3864Plain Craft Launcher 2.exeC:\Users\admin\AppData\Local\Temp\PCL\Cache\Notice.jsonini
MD5:A28B493374FF23A3AAD6EA9F043A1EB4
SHA256:2631E0EACB8E4DBAF508972DFD45E08470C5143F4EBE7DC6C18FB2EB118A6CEB
3864Plain Craft Launcher 2.exeC:\Users\admin\AppData\Local\Temp\PCL\Update.zipcompressed
MD5:D5A134F94C35644A4085298E0858E067
SHA256:72A10440FA20019D9D65005DF0E0290D2C8FA64DF4C726449188835CBE8D4164
1496Plain Craft Launcher 2.exeC:\Users\admin\AppData\Local\Temp\PCL\Log2.txttext
MD5:C15EBCDA9ABEC004A15130CDB8656BEA
SHA256:0C2E4B195733868183A467CC501522DAE586C382C8526FFC65A87D05A3735CE7
3864Plain Craft Launcher 2.exeC:\Users\admin\AppData\Local\Temp\PCL\Plain Craft Launcher 2.exeexecutable
MD5:BB8AA69C974CCEE9C39A6D5A950AE492
SHA256:7008B26EA9D43BAEC552FAE449A165C301D6BDE7B93656A498C01CFC538DB9A6
3864Plain Craft Launcher 2.exeC:\Users\admin\AppData\Local\Temp\.minecraft\launcher_profiles.jsonbinary
MD5:01118E8192B0EB234801630A0642040E
SHA256:7307AE5308DDE5882FF2AAD327F31829F98454F8D1F9881BD6020326FB96487C
3864Plain Craft Launcher 2.exeC:\Users\admin\AppData\Local\Temp\PCL\Download\154_160_530334.tmpcompressed
MD5:D5A134F94C35644A4085298E0858E067
SHA256:72A10440FA20019D9D65005DF0E0290D2C8FA64DF4C726449188835CBE8D4164
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
10
DNS requests
2
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3864
Plain Craft Launcher 2.exe
GET
200
221.15.67.241:80
http://pcl2-server-1253424809.file.myqcloud.com/notice.cfg?sign=1708297187-51c074ca-0-689bcf3d40054af8d972bce0d1215c36
unknown
text
13 b
3864
Plain Craft Launcher 2.exe
GET
200
221.15.67.241:80
http://pcl2-server-1253424809.file.myqcloud.com/notice.json?sign=1708297191-50aed8d3-0-6c75521c5b710c5c062ce40a51aaa7bf
unknown
text
6.25 Kb
3864
Plain Craft Launcher 2.exe
GET
206
221.15.67.241:80
http://pcl2-server-1253424809.file.myqcloud.com/minecraft/download.json?sign=1708297191-450580ff-0-e5d935608c4087ee42b1ce536b7f0e5a
unknown
text
3.80 Kb
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
unknown
3864
Plain Craft Launcher 2.exe
13.107.213.62:443
launchermeta.mojang.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3864
Plain Craft Launcher 2.exe
221.15.67.241:80
pcl2-server-1253424809.file.myqcloud.com
CHINA UNICOM China169 Backbone
CN
unknown
3864
Plain Craft Launcher 2.exe
221.15.67.241:443
pcl2-server-1253424809.file.myqcloud.com
CHINA UNICOM China169 Backbone
CN
unknown
1496
Plain Craft Launcher 2.exe
13.107.213.62:443
launchermeta.mojang.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
1496
Plain Craft Launcher 2.exe
221.15.67.241:443
pcl2-server-1253424809.file.myqcloud.com
CHINA UNICOM China169 Backbone
CN
unknown

DNS requests

Domain
IP
Reputation
launchermeta.mojang.com
  • 13.107.213.62
  • 13.107.246.62
unknown
pcl2-server-1253424809.file.myqcloud.com
  • 221.15.67.241
  • 42.177.83.87
  • 42.177.83.225
  • 42.177.83.82
  • 42.177.83.224
  • 42.177.83.214
  • 42.177.83.78
  • 211.97.81.227
  • 221.204.166.213
  • 113.194.50.188
  • 42.177.83.63
  • 113.201.158.139
  • 113.194.51.51
unknown

Threats

PID
Process
Class
Message
Misc activity
ET INFO Tencent Cloud Storage Domain in DNS Lookup (myqcloud .com)
Misc activity
ET INFO Observed Tencent Cloud Storage Domain (myqcloud .com in TLS SNI)
Misc activity
ET INFO Observed Tencent Cloud Storage Domain (myqcloud .com in TLS SNI)
No debug info