minecraft-setup.exe

The executable minecraft-setup.exe has been detected as malware by 1 anti-virus scanner. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from launcher.pixelmon.pl.
MD5:
d0066353d80e8029e19153293a516866

SHA-1:
bf587f8bda155a57717cff2bc8790797fbffb02f

SHA-256:
30e5dc353f58a6089259a4a01b1884b475bf531efb03823029fc803675559dde

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
1/6/2025 5:46:35 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
16.7.20.6

File size:
475.9 KB (487,342 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\minecraft-setup.exe

File PE Metadata
Compilation timestamp:
4/8/2014 6:52:20 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:FNXg2PTt7b+egbN7nZea6HCk1t8epsVFNj5OST8fdVF5:FNXfPTtX+dZZ6HbtaNUST8fdd

Entry address:
0x2C4E2

Entry point:
E8, F7, 8F, 00, 00, E9, 7F, FE, FF, FF, E8, 30, 65, 00, 00, 8B, D0, 8B, 42, 6C, 3B, 05, 94, 47, 45, 00, 74, 10, 8B, 0D, 58, 48, 45, 00, 85, 4A, 70, 75, 05, E8, D7, 62, 00, 00, 8B, 40, 04, C3, E8, 0A, 65, 00, 00, 8B, D0, 8B, 42, 6C, 3B, 05, 94, 47, 45, 00, 74, 10, 8B, 0D, 58, 48, 45, 00, 85, 4A, 70, 75, 05, E8, B1, 62, 00, 00, 05, A0, 00, 00, 00, C3, E8, E2, 64, 00, 00, 8B, D0, 8B, 42, 6C, 3B, 05, 94, 47, 45, 00, 74, 10, 8B, 0D, 58, 48, 45, 00, 85, 4A, 70, 75, 05, E8, 89, 62, 00, 00, 8B, 40, 74, C3, 55, 8B...
 
[+]

Code size:
270.5 KB (276,992 bytes)

The file minecraft-setup.exe has been seen being distributed by the following URL.

Remove minecraft-setup.exe - Powered by Reason Core Security