minecraft windows.exe

Shiginima Launcher SE v3.100

The executable minecraft windows.exe has been detected as malware by 11 anti-virus scanners. This is a setup program which is used to install the application. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from mc96.net.
Product:
Shiginima Launcher SE v3.100

Version:
3.1.0.0

MD5:
249f5cb94da6fbb064be7d5fca08c680

SHA-1:
4ecf9568fff596d2aa2c15286d499c97416950b1

SHA-256:
5cfd05fa91bfc74a078ae18bf09f5edd91eb863919593792ede0da5c4e2536b6

Scanner detections:
11 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
12/26/2024 1:26:00 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Kukacka
160326-0

AVG
Win32/Sality
2015.0.4563

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.15.96

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.219.354.0

Norman
Win32.Sality.3
02.04.2016 17:35:19

File size:
3.6 MB (3,723,908 bytes)

Product version:
3.1.0.0

Copyright:
Shiginima, Mojang

Original file name:
Shiginima Launcher SE v3.100.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\My documents\downloads\minecraft windows.exe

File PE Metadata
Compilation timestamp:
2/24/2016 2:32:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
49152:0YSCqk/lsT+qCUsXwmlkbLdfObF2QlcSMEl7AqMrEugj5jPmxga1ntjkdXO2+pkK:5SCr/PKpOJ2T0mqIEuWW1xt6X6lpV

Entry address:
0x1290

Entry point:
60, 11, CE, 8B, C9, 0F, A5, FF, C1, C5, B7, 0F, AF, CA, B6, 36, 0F, CB, C1, C9, B5, 81, D3, 2A, 74, C5, B7, 0F, BD, F0, 3B, FA, 0F, B7, C9, 0F, A5, DF, 0F, BA, FE, 15, F7, D7, 0F, BA, E7, AA, C0, E1, 34, F6, C5, 71, 89, EF, 8A, CB, E8, 46, 00, 00, 00, 0F, B6, EA, F6, C7, 52, F2, F7, D8, 89, FD, 0F, BA, E0, 0A, 3D, 8A, 5F, 9D, A2, F7, C2, A0, 53, 9D, DB, 0F, C1, CD, 81, E3, A7, 62, 73, 3B, 84, D9, 52, D0, F9, 58, F3, C1, F9, B9, 8D, 38, 85, FE, 0F, BA, E3, C8, 86, E3, 18, D8, 49, 2B, D7, F7, C3, B9, CC, C6...
 
[+]

Entropy:
7.8680  (probably packed)

Code size:
18 KB (18,432 bytes)

The file minecraft windows.exe has been seen being distributed by the following URL.

Remove minecraft windows.exe - Powered by Reason Core Security