minecraft_1.8.7-torrent.exe

ESET Smart Security

Force LLC

The application minecraft_1.8.7-torrent.exe, “Eset GUI Installer” by Force has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from doc-14-50-docs.googleusercontent.com.
Publisher:
ESET  (signed by Force LLC)

Product:
ESET Smart Security

Description:
Eset GUI Installer

Version:
3.0.695

MD5:
fd732cd9a489812bc74009277386f90f

SHA-1:
62913bf2173321655bd69c6cb5273ced8de6b8cc

SHA-256:
0e3a6af6536e3ec8d01242d8ed6eb50091b9dd08140731e0e017c737edf74dd6

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 1:27:09 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Force.Installer (M)
16.3.30.1

File size:
1.2 MB (1,212,112 bytes)

Product version:
3.0.695

Copyright:
Copyright (c) Eset 1992-2009. All rights reserved.

Trademarks:
NOD, NOD32, AMON, ESET are registered trademarks of ESET.

Original file name:
egui.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\minecraft_1.8.7-torrent.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/5/2015 3:00:00 AM

Valid to:
5/5/2016 2:59:59 AM

Subject:
CN=Force LLC, O=Force LLC, POBox=119331, STREET=Vernandskogo 29, L=Moscow, S=Moscow, PostalCode=119331, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
7F1FBFEC9EBD89CCB543E7C5811DE223

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:Oqgt6g5yjjn9eW5Qtg1VdP/si8tqvmQ6DlfM0d+1q+1t0ia8jQGgydtot:O16gQ2gTdP/si5v36pfv+UqVjQGgy

Entry address:
0xF5D03

Entry point:
60, 60, C7, 44, 24, 3C, 3A, FB, 4E, 00, FF, 34, 24, 66, C7, 44, 24, 04, 30, 02, 9C, E9, EA, 2E, 00, 00, 3B, AF, FC, 45, CD, 17, 28, 06, 63, 5D, 14, FC, 80, B4, 48, F8, 40, 6C, A3, 76, FB, 35, EF, 4A, 76, 56, BA, 36, 77, 29, 20, B0, D5, FB, CA, 1A, 7B, 0E, A7, 1A, 97, E1, E5, BC, 70, 61, A0, A4, 99, C1, FF, 57, 67, B2, B0, DE, 4D, 14, CB, 17, 50, 11, 4B, DE, 45, A2, EE, FA, 3F, 59, 6E, 14, 67, 66, DB, 58, AF, 1F, CE, AC, 74, 1C, 8D, 9C, 3C, AF, 31, F2, A8, F5, FC, 98, 34, 6E, 9C, 29, 00, A6, A5, E0, C6, 62...
 
[+]

Code size:
649 KB (664,576 bytes)

The file minecraft_1.8.7-torrent.exe has been seen being distributed by the following URL.

Remove minecraft_1.8.7-torrent.exe - Powered by Reason Core Security