minecraft.exe

The executable minecraft.exe has been detected as malware by 5 anti-virus scanners. The file has been seen being downloaded from www.bulkstockupdate.com.
MD5:
d94c9ce79dc506f30bbaa13ab3a96576

SHA-1:
c5c1712b6443c62fff653445f2ef8b9f5efd72e5

SHA-256:
f62d187668d4ba85025815ab8ffdc21093db36e6809452fc801a03eab6ad3375

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
11/27/2024 2:38:12 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Kukacka
160518-2

AVG
Win32/Sality
2015.0.4604

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.E.gen
4.6.5.141

Microsoft Security Essentials
Threat.Undefined
1.225.2402.0

File size:
736.1 KB (753,812 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\minecraft.exe

File PE Metadata
Compilation timestamp:
7/12/2013 2:31:36 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
12288:j3M40bnUrq8Pc3rbQjnVCEwtMvZaLZwpYKkbH24vp:j3M40bUrqpkkDtMvZaypY1/B

Entry address:
0x1290

Entry point:
60, 1A, EF, 69, EA, 02, CC, D9, 39, F7, C6, AE, 19, 08, 29, 74, 03, 0F, BF, D8, 88, F8, 50, 57, 38, D9, 83, E6, 00, 87, EF, 8D, 1D, C6, 7E, D4, 9E, 8D, 2D, 15, C8, 9B, 45, 85, EB, 8D, 0D, 88, 08, 2A, 72, FE, CE, 81, C6, 79, F9, FF, FF, 0F, B7, FD, 3C, 17, 1A, E7, 81, C6, 88, 06, 00, 00, 0F, B6, E9, F2, 48, 71, 01, 49, FF, C5, 81, FE, 7C, 09, 00, 00, 0F, 82, BF, FF, FF, FF, FF, C5, 81, D8, 7C, 9F, A5, 6B, 0F, B6, FE, E8, 00, 00, 00, 00, 3D, 54, AB, 48, E3, 1D, 36, CE, 2F, E3, 34, 10, 86, D6, F7, C1, B2, 66...
 
[+]

Entropy:
6.9433

Code size:
17.5 KB (17,920 bytes)

The file minecraft.exe has been seen being distributed by the following URL.

Remove minecraft.exe - Powered by Reason Core Security