minecraft.exe

The executable minecraft.exe has been detected as malware by 9 anti-virus scanners. The file has been seen being downloaded from www.pobieraj.org.
MD5:
11c1b3903fde74f2d68f41c831409be4

SHA-1:
281d1e5a6e93338cecdc5827254df93b658d0a60

SHA-256:
691eab8aa25402f2f75a6c35c7d0a77e53ac0fc24050827fe0faa73f18ea4bd2

Scanner detections:
9 / 68

Status:
Malware

Analysis date:
12/25/2024 5:45:27 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Agent.1210431.1
7.11.205.14

avast!
Win32:Malware-gen
2014.9-160203

Dr.Web
FDOS.Atomix.origin
9.0.1.034

G Data
Win32.Trojan.Agent.0NWWX6
16.2.24

IKARUS anti.virus
Trojan.Agent
t3scan.1.8.6.0

McAfee
Artemis!11C1B3903FDE
5600.6500

Norman
Agent.BMNRM
11.20160203

Qihoo 360 Security
HEUR/QVM41.1.Malware.Gen
1.0.0.1015

Trend Micro House Call
TROJ_GEN.R002H05AG15
7.2.34

File size:
1.2 MB (1,210,431 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\minecraft.exe

File PE Metadata
Compilation timestamp:
8/27/2014 5:41:00 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:/F6kcnUQT9ZbbaN2w2jC8YXeHPe8rmIFTq0BTlPMQNgpMXVJLC:ULvLaN2w2jfYXfxY+O7fO

Entry address:
0x10BBA

Entry point:
E8, 11, 65, 00, 00, E9, 78, FE, FF, FF, 55, 8B, EC, 83, EC, 04, 89, 7D, FC, 8B, 7D, 08, 8B, 4D, 0C, C1, E9, 07, 66, 0F, EF, C0, EB, 08, 8D, A4, 24, 00, 00, 00, 00, 90, 66, 0F, 7F, 07, 66, 0F, 7F, 47, 10, 66, 0F, 7F, 47, 20, 66, 0F, 7F, 47, 30, 66, 0F, 7F, 47, 40, 66, 0F, 7F, 47, 50, 66, 0F, 7F, 47, 60, 66, 0F, 7F, 47, 70, 8D, BF, 80, 00, 00, 00, 49, 75, D0, 8B, 7D, FC, 8B, E5, 5D, C3, 55, 8B, EC, 83, EC, 10, 89, 7D, FC, 8B, 45, 08, 99, 8B, F8, 33, FA, 2B, FA, 83, E7, 0F, 33, FA, 2B, FA, 85, FF, 75, 3C, 8B...
 
[+]

Entropy:
7.3377

Code size:
112 KB (114,688 bytes)

The file minecraft.exe has been seen being distributed by the following URL.

Remove minecraft.exe - Powered by Reason Core Security