File name:

modloader-for-minecraft-1.4.7-installer_VEmbG-2.exe

Full analysis: https://app.any.run/tasks/78857095-6619-479a-b376-ffcac9e1f2ff
Verdict: Malicious activity
Analysis date: April 08, 2024, 07:24:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

8DF2952B4D4E397EC28E6D2E245B7D6A

SHA1:

581B988D9B782843B33506A9A19001D4FAF61F4C

SHA256:

F6B980BAC8E012F90A8FA04D2938B585EF0A60ABD398314570B2656977D1D98D

SSDEEP:

49152:y7HecD4dnbibBlP6Q0cV51EolHyNHEiYTy19S3yh8O40b/gBRqXt7nepppqgri2u:C+cD4dns3pwolHyN8TyCyhpj+gXMpvBu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.exe (PID: 1836)
      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.exe (PID: 1348)
      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp (PID: 1496)
      • avg_antivirus_free_setup.exe (PID: 3684)
      • icarus.exe (PID: 1900)
      • avg_antivirus_free_online_setup.exe (PID: 3776)
      • icarus.exe (PID: 568)
    • Creates a writable file in the system directory

      • icarus.exe (PID: 568)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.exe (PID: 1836)
      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.exe (PID: 1348)
      • avg_antivirus_free_setup.exe (PID: 3684)
      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp (PID: 1496)
      • icarus.exe (PID: 1900)
      • avg_antivirus_free_online_setup.exe (PID: 3776)
      • icarus.exe (PID: 568)
    • Reads settings of System Certificates

      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp (PID: 1496)
      • avg_antivirus_free_setup.exe (PID: 3684)
      • avg_antivirus_free_online_setup.exe (PID: 3776)
    • Reads the Windows owner or organization settings

      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp (PID: 1496)
    • Reads the Internet Settings

      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp (PID: 1496)
    • Reads security settings of Internet Explorer

      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp (PID: 1496)
    • Creates file in the systems drive root

      • ntvdm.exe (PID: 240)
    • Adds/modifies Windows certificates

      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp (PID: 1496)
    • Starts itself from another location

      • icarus.exe (PID: 1900)
    • Non-standard symbols in registry

      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp (PID: 1496)
    • The process creates files with name similar to system file names

      • icarus.exe (PID: 568)
    • The process verifies whether the antivirus software is installed

      • icarus.exe (PID: 568)
  • INFO

    • Checks supported languages

      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.exe (PID: 1836)
      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp (PID: 2580)
      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.exe (PID: 1348)
      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp (PID: 1496)
      • avg_antivirus_free_setup.exe (PID: 3684)
      • avg_antivirus_free_online_setup.exe (PID: 3776)
      • icarus.exe (PID: 1900)
      • icarus.exe (PID: 568)
      • icarus.exe (PID: 3544)
    • Reads the computer name

      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp (PID: 2580)
      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp (PID: 1496)
      • avg_antivirus_free_setup.exe (PID: 3684)
      • avg_antivirus_free_online_setup.exe (PID: 3776)
      • icarus.exe (PID: 1900)
      • icarus.exe (PID: 568)
      • icarus.exe (PID: 3544)
    • Create files in a temporary directory

      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.exe (PID: 1836)
      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.exe (PID: 1348)
      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp (PID: 1496)
      • icarus.exe (PID: 1900)
      • avg_antivirus_free_online_setup.exe (PID: 3776)
      • icarus.exe (PID: 568)
      • icarus.exe (PID: 3544)
    • Reads the software policy settings

      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp (PID: 1496)
      • avg_antivirus_free_setup.exe (PID: 3684)
      • avg_antivirus_free_online_setup.exe (PID: 3776)
    • Reads the machine GUID from the registry

      • modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp (PID: 1496)
      • avg_antivirus_free_setup.exe (PID: 3684)
      • avg_antivirus_free_online_setup.exe (PID: 3776)
      • icarus.exe (PID: 1900)
      • icarus.exe (PID: 568)
      • icarus.exe (PID: 3544)
    • Creates files in the program directory

      • avg_antivirus_free_online_setup.exe (PID: 3776)
      • icarus.exe (PID: 1900)
      • icarus.exe (PID: 568)
    • Reads CPU info

      • icarus.exe (PID: 1900)
      • icarus.exe (PID: 3544)
      • icarus.exe (PID: 568)
    • Dropped object may contain TOR URL's

      • icarus.exe (PID: 1900)
    • Reads Environment values

      • icarus.exe (PID: 568)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 89600
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 4.12.3.1231
ProductVersionNumber: 4.12.3.1231
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Softonic International SA
FileVersion: 4.12.3.1231
LegalCopyright: ©2023 Softonic International SA
OriginalFileName:
ProductName: Softonic International SA
ProductVersion: 4.12.3.1231
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
10
Malicious processes
8
Suspicious processes
0

Behavior graph

Click at the process to see the details
start modloader-for-minecraft-1.4.7-installer_vembg-2.exe modloader-for-minecraft-1.4.7-installer_vembg-2.tmp no specs modloader-for-minecraft-1.4.7-installer_vembg-2.exe modloader-for-minecraft-1.4.7-installer_vembg-2.tmp avg_antivirus_free_setup.exe avg_antivirus_free_online_setup.exe ntvdm.exe no specs icarus.exe icarus.exe no specs icarus.exe

Process information

PID
CMD
Path
Indicators
Parent process
240"C:\Windows\system32\ntvdm.exe" -i1 C:\Windows\System32\ntvdm.exemodloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
NTVDM.EXE
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntvdm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
568C:\Windows\Temp\asw-0dd65e27-8c31-427b-a0a9-b9059bb9b7d2\avg-av\icarus.exe /silent /ws /psh:92pTu5fa4JWbGFKW91XI57KRx0swxicKbMu1ZmLUPTz7Flx2yEntGh6VkODS8Dy5VvYMpcxWXCIBls /cookie:mmm_irs_ppi_902_451_o /edat_dir:C:\Windows\Temp\asw.94257389ba877463 /track-guid:03ae8095-b575-4628-8279-1eaa2cc76133 /er_master:master_ep_89554cbd-4f29-47e7-be49-0f51f6e74bab /er_ui:ui_ep_daa74b11-e372-4002-88e5-582968cbf11e /er_slave:avg-av_slave_ep_fa985cc1-b905-40ab-af94-44b938d56879 /slave:avg-avC:\Windows\Temp\asw-0dd65e27-8c31-427b-a0a9-b9059bb9b7d2\avg-av\icarus.exe
icarus.exe
User:
admin
Company:
AVG Technologies
Integrity Level:
HIGH
Description:
AVG Installer
Version:
24.3.7200.0
Modules
Images
c:\windows\temp\asw-0dd65e27-8c31-427b-a0a9-b9059bb9b7d2\avg-av\icarus.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\webio.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1348"C:\Users\admin\AppData\Local\Temp\modloader-for-minecraft-1.4.7-installer_VEmbG-2.exe" /SPAWNWND=$17013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\modloader-for-minecraft-1.4.7-installer_VEmbG-2.exe
modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
Softonic International SA
Version:
4.12.3.1231
Modules
Images
c:\users\admin\appdata\local\temp\modloader-for-minecraft-1.4.7-installer_vembg-2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
1496"C:\Users\admin\AppData\Local\Temp\is-O2UG3.tmp\modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp" /SL5="$F01B6,837550,832512,C:\Users\admin\AppData\Local\Temp\modloader-for-minecraft-1.4.7-installer_VEmbG-2.exe" /SPAWNWND=$17013E /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\is-O2UG3.tmp\modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp
modloader-for-minecraft-1.4.7-installer_VEmbG-2.exe
User:
admin
Company:
Integrity Level:
HIGH
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-o2ug3.tmp\modloader-for-minecraft-1.4.7-installer_vembg-2.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1836"C:\Users\admin\AppData\Local\Temp\modloader-for-minecraft-1.4.7-installer_VEmbG-2.exe" C:\Users\admin\AppData\Local\Temp\modloader-for-minecraft-1.4.7-installer_VEmbG-2.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Softonic International SA
Version:
4.12.3.1231
Modules
Images
c:\users\admin\appdata\local\temp\modloader-for-minecraft-1.4.7-installer_vembg-2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
1900C:\Windows\Temp\asw-0dd65e27-8c31-427b-a0a9-b9059bb9b7d2\common\icarus.exe /icarus-info-path:C:\Windows\Temp\asw-0dd65e27-8c31-427b-a0a9-b9059bb9b7d2\icarus-info.xml /install /silent /ws /psh:92pTu5fa4JWbGFKW91XI57KRx0swxicKbMu1ZmLUPTz7Flx2yEntGh6VkODS8Dy5VvYMpcxWXCIBls /cookie:mmm_irs_ppi_902_451_o /edat_dir:C:\Windows\Temp\asw.94257389ba877463 /track-guid:03ae8095-b575-4628-8279-1eaa2cc76133C:\Windows\Temp\asw-0dd65e27-8c31-427b-a0a9-b9059bb9b7d2\common\icarus.exe
avg_antivirus_free_online_setup.exe
User:
admin
Company:
AVG Technologies
Integrity Level:
HIGH
Description:
AVG Installer
Version:
24.3.7200.0
Modules
Images
c:\windows\temp\asw-0dd65e27-8c31-427b-a0a9-b9059bb9b7d2\common\icarus.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\webio.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
2580"C:\Users\admin\AppData\Local\Temp\is-MUSV5.tmp\modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp" /SL5="$E0170,837550,832512,C:\Users\admin\AppData\Local\Temp\modloader-for-minecraft-1.4.7-installer_VEmbG-2.exe" C:\Users\admin\AppData\Local\Temp\is-MUSV5.tmp\modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmpmodloader-for-minecraft-1.4.7-installer_VEmbG-2.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-musv5.tmp\modloader-for-minecraft-1.4.7-installer_vembg-2.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3544C:\Windows\Temp\asw-0dd65e27-8c31-427b-a0a9-b9059bb9b7d2\avg-av-vps\icarus.exe /silent /ws /psh:92pTu5fa4JWbGFKW91XI57KRx0swxicKbMu1ZmLUPTz7Flx2yEntGh6VkODS8Dy5VvYMpcxWXCIBls /cookie:mmm_irs_ppi_902_451_o /edat_dir:C:\Windows\Temp\asw.94257389ba877463 /track-guid:03ae8095-b575-4628-8279-1eaa2cc76133 /er_master:master_ep_89554cbd-4f29-47e7-be49-0f51f6e74bab /er_ui:ui_ep_daa74b11-e372-4002-88e5-582968cbf11e /er_slave:avg-av-vps_slave_ep_4754e995-fbd7-4126-a855-45545b0016c8 /slave:avg-av-vpsC:\Windows\Temp\asw-0dd65e27-8c31-427b-a0a9-b9059bb9b7d2\avg-av-vps\icarus.exeicarus.exe
User:
admin
Company:
AVG Technologies
Integrity Level:
HIGH
Description:
AVG Installer
Version:
24.3.7200.0
Modules
Images
c:\windows\temp\asw-0dd65e27-8c31-427b-a0a9-b9059bb9b7d2\avg-av-vps\icarus.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\webio.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3684"C:\Users\admin\AppData\Local\Temp\is-PJOG5.tmp\component0_extract\avg_antivirus_free_setup.exe" /silent /ws /psh:92pTu5fa4JWbGFKW91XI57KRx0swxicKbMu1ZmLUPTz7Flx2yEntGh6VkODS8Dy5VvYMpcxWXCIBlsC:\Users\admin\AppData\Local\Temp\is-PJOG5.tmp\component0_extract\avg_antivirus_free_setup.exe
modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp
User:
admin
Company:
AVG Technologies CZ, s.r.o.
Integrity Level:
HIGH
Description:
AVG Installer
Version:
2.1.99.0
Modules
Images
c:\users\admin\appdata\local\temp\is-pjog5.tmp\component0_extract\avg_antivirus_free_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3776"C:\Windows\Temp\asw.94257389ba877463\avg_antivirus_free_online_setup.exe" /silent /ws /psh:92pTu5fa4JWbGFKW91XI57KRx0swxicKbMu1ZmLUPTz7Flx2yEntGh6VkODS8Dy5VvYMpcxWXCIBls /cookie:mmm_irs_ppi_902_451_o /ga_clientid:03ae8095-b575-4628-8279-1eaa2cc76133 /edat_dir:C:\Windows\Temp\asw.94257389ba877463C:\Windows\Temp\asw.94257389ba877463\avg_antivirus_free_online_setup.exe
avg_antivirus_free_setup.exe
User:
admin
Company:
AVG Technologies
Integrity Level:
HIGH
Description:
AVG Self-Extract Package
Version:
24.3.7200.0
Modules
Images
c:\windows\temp\asw.94257389ba877463\avg_antivirus_free_online_setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
18 416
Read events
18 307
Write events
95
Delete events
14

Modification events

(PID) Process:(1496) modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
D8050000420081C98589DA01
(PID) Process:(1496) modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
2C226149401C1B4AB0C579A770421E3B5E1D66C5DF3CD8874792CE265EB2D8E1
(PID) Process:(1496) modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(1496) modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1496) modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates
Operation:delete valueName:9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Value:
(PID) Process:(1496) modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
0F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D80300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB6200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(1496) modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
1400000001000000140000005D6CA352CEFC713CBBC5E21F663C3639FD19D4D70300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB60F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D8200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(1496) modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
190000000100000010000000BCC80DAA2F98A4692805BFF4CBB372EB0F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D80300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB61400000001000000140000005D6CA352CEFC713CBBC5E21F663C3639FD19D4D7200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(1496) modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates
Operation:delete valueName:CABD2A79A1076A31F21D253635CB039D4329A5E8
Value:
(PID) Process:(1496) modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\CABD2A79A1076A31F21D253635CB039D4329A5E8
Operation:writeName:Blob
Value:
0400000001000000100000000CD2F9E0DA1773E9ED864DA5E370E74E0F00000001000000200000003F0411EDE9C4477057D57E57883B1F205B20CDC0F3263129B1EE0269A2678F63030000000100000014000000CABD2A79A1076A31F21D253635CB039D4329A5E809000000010000000C000000300A06082B060105050703011D000000010000001000000073B6876195F5D18E048510422AEF04E314000000010000001400000079B459E67BB6E5E40173800888C81A58F6E99B6E0B000000010000001A0000004900530052004700200052006F006F007400200058003100000062000000010000002000000096BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C61900000001000000100000002FE1F70BB05D7C92335BC5E05B984DA620000000010000006F0500003082056B30820353A0030201020211008210CFB0D240E3594463E0BB63828B00300D06092A864886F70D01010B0500304F310B300906035504061302555331293027060355040A1320496E7465726E65742053656375726974792052657365617263682047726F7570311530130603550403130C4953524720526F6F74205831301E170D3135303630343131303433385A170D3335303630343131303433385A304F310B300906035504061302555331293027060355040A1320496E7465726E65742053656375726974792052657365617263682047726F7570311530130603550403130C4953524720526F6F7420583130820222300D06092A864886F70D01010105000382020F003082020A0282020100ADE82473F41437F39B9E2B57281C87BEDCB7DF38908C6E3CE657A078F775C2A2FEF56A6EF6004F28DBDE68866C4493B6B163FD14126BBF1FD2EA319B217ED1333CBA48F5DD79DFB3B8FF12F1219A4BC18A8671694A66666C8F7E3C70BFAD292206F3E4C0E680AEE24B8FB7997E94039FD347977C99482353E838AE4F0A6F832ED149578C8074B6DA2FD0388D7B0370211B75F2303CFA8FAEDDDA63ABEB164FC28E114B7ECF0BE8FFB5772EF4B27B4AE04C12250C708D0329A0E15324EC13D9EE19BF10B34A8C3F89A36151DEAC870794F46371EC2EE26F5B9881E1895C34796C76EF3B906279E6DBA49A2F26C5D010E10EDED9108E16FBB7F7A8F7C7E50207988F360895E7E237960D36759EFB0E72B11D9BBC03F94905D881DD05B42AD641E9AC0176950A0FD8DFD5BD121F352F28176CD298C1A80964776E4737BACEAC595E689D7F72D689C50641293E593EDD26F524C911A75AA34C401F46A199B5A73A516E863B9E7D72A712057859ED3E5178150B038F8DD02F05B23E7B4A1C4B730512FCC6EAE050137C439374B3CA74E78E1F0108D030D45B7136B407BAC130305C48B7823B98A67D608AA2A32982CCBABD83041BA2830341A1D605F11BC2B6F0A87C863B46A8482A88DC769A76BF1F6AA53D198FEB38F364DEC82B0D0A28FFF7DBE21542D422D0275DE179FE18E77088AD4EE6D98B3AC6DD27516EFFBC64F533434F0203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E0416041479B459E67BB6E5E40173800888C81A58F6E99B6E300D06092A864886F70D01010B05000382020100551F58A9BCB2A850D00CB1D81A6920272908AC61755C8A6EF882E5692FD5F6564BB9B8731059D321977EE74C71FBB2D260AD39A80BEA17215685F1500E59EBCEE059E9BAC915EF869D8F8480F6E4E99190DC179B621B45F06695D27C6FC2EA3BEF1FCFCBD6AE27F1A9B0C8AEFD7D7E9AFA2204EBFFD97FEA912B22B1170E8FF28A345B58D8FC01C954B9B826CC8A8833894C2D843C82DFEE965705BA2CBBF7C4B7C74E3B82BE31C822737392D1C280A43939103323824C3C9F86B255981DBE29868C229B9EE26B3B573A82704DDC09C789CB0A074D6CE85D8EC9EFCEABC7BBB52B4E45D64AD026CCE572CA086AA595E315A1F7A4EDC92C5FA5FBFFAC28022EBED77BBBE3717B9016D3075E46537C3707428CD3C4969CD599B52AE0951A8048AE4C3907CECC47A452952BBAB8FBADD233537DE51D4D6DD5A1B1C7426FE64027355CA328B7078DE78D3390E7239FFB509C796C46D5B415B3966E7E9B0C963AB8522D3FD65BE1FB08C284FE24A8A389DAAC6AE1182AB1A843615BD31FDC3B8D76F22DE88D75DF17336C3D53FB7BCB415FFFDCA2D06138E196B8AC5D8B37D775D533C09911AE9D41C1727584BE0241425F67244894D19B27BE073FB9B84F817451E17AB7ED9D23E2BEE0D52804133C31039EDD7A6C8FC60718C67FDE478E3F289E0406CFA5543477BDEC899BE91743DF5BDB5FFE8E1E57A2CD409D7E6222DADE1827
Executable files
31
Suspicious files
20
Text files
36
Unknown types
5

Dropped files

PID
Process
Filename
Type
1836modloader-for-minecraft-1.4.7-installer_VEmbG-2.exeC:\Users\admin\AppData\Local\Temp\is-MUSV5.tmp\modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmpexecutable
MD5:
SHA256:
1348modloader-for-minecraft-1.4.7-installer_VEmbG-2.exeC:\Users\admin\AppData\Local\Temp\is-O2UG3.tmp\modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmpexecutable
MD5:
SHA256:
1496modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmpC:\Users\admin\AppData\Local\Temp\is-PJOG5.tmp\is-6I8EI.tmpimage
MD5:
SHA256:
1496modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmpC:\Users\admin\AppData\Local\Temp\is-PJOG5.tmp\AVG_AV.pngimage
MD5:
SHA256:
1496modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmpC:\Users\admin\AppData\Local\Temp\is-PJOG5.tmp\is-0AR8M.tmpimage
MD5:
SHA256:
1496modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmpC:\Users\admin\AppData\Local\Temp\is-PJOG5.tmp\mainlogo.pngimage
MD5:
SHA256:
1496modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmpC:\Users\admin\AppData\Local\Temp\is-PJOG5.tmp\v.pngimage
MD5:
SHA256:
1496modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmpC:\Users\admin\AppData\Local\Temp\is-PJOG5.tmp\x.pngimage
MD5:
SHA256:
1496modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmpC:\Users\admin\AppData\Local\Temp\is-PJOG5.tmp\is-H41JI.tmpcompressed
MD5:
SHA256:
1496modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmpC:\Users\admin\AppData\Local\Temp\is-PJOG5.tmp\modloader-for-minecraft-1.4.7-installer.execompressed
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
29
DNS requests
34
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3684
avg_antivirus_free_setup.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
unknown
unknown
3684
avg_antivirus_free_setup.exe
POST
200
142.250.185.78:80
http://www.google-analytics.com/collect
unknown
unknown
3684
avg_antivirus_free_setup.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
unknown
unknown
3684
avg_antivirus_free_setup.exe
POST
200
142.250.185.78:80
http://www.google-analytics.com/collect
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
1496
modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp
13.33.216.89:443
d2cxd1qpd0dh21.cloudfront.net
US
unknown
1496
modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp
104.89.84.42:443
images.sftcdn.net
AKAMAI-AS
GB
unknown
1496
modloader-for-minecraft-1.4.7-installer_VEmbG-2.tmp
199.232.194.133:443
gsf-fl.softonic.com
FASTLY
US
unknown
3684
avg_antivirus_free_setup.exe
142.250.185.78:80
www.google-analytics.com
GOOGLE
US
whitelisted
3684
avg_antivirus_free_setup.exe
92.122.197.76:443
honzik.avcdn.net
AKAMAI-AS
GB
whitelisted
3684
avg_antivirus_free_setup.exe
34.117.223.223:80
v7event.stats.avast.com
GOOGLE-CLOUD-PLATFORM
US
unknown
3776
avg_antivirus_free_online_setup.exe
34.117.223.223:443
v7event.stats.avast.com
GOOGLE-CLOUD-PLATFORM
US
unknown

DNS requests

Domain
IP
Reputation
d2cxd1qpd0dh21.cloudfront.net
  • 13.33.216.89
  • 13.33.216.108
  • 13.33.216.227
  • 13.33.216.57
unknown
images.sftcdn.net
  • 104.89.84.42
whitelisted
gsf-fl.softonic.com
  • 199.232.194.133
  • 199.232.198.133
whitelisted
honzik.avcdn.net
  • 92.122.197.76
  • 2a02:26f0:3500:f92::240d
  • 2a02:26f0:3500:f9c::240d
unknown
www.google-analytics.com
  • 142.250.185.78
whitelisted
v7event.stats.avast.com
  • 34.117.223.223
whitelisted
analytics.avcdn.net
  • 34.117.223.223
unknown
shepherd.avcdn.net
  • 34.160.176.28
whitelisted

Threats

No threats detected
No debug info