minecraft force op.exe

Minecraft Force OP

Toshiba

The executable minecraft force op.exe has been detected as malware by 5 anti-virus scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from download1483.mediafire.com and multiple other hosts.
Publisher:
Toshiba

Product:
Minecraft Force OP

Version:
1.0.0.0

MD5:
2b795f289e1792824e0879027dc5a665

SHA-1:
71f341552bc34ba6c45497df74f6cf028f02f7f7

SHA-256:
009d804e494d8c79d05fb60539f299a422d4ae166ab1736ab9686d7c8b0c289b

Scanner detections:
5 / 68

Status:
Malware

Analysis date:
4/19/2024 11:38:59 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.Gen
7.11.176.244

avast!
Win32:Malware-gen
2014.9-141013

IKARUS anti.virus
Trojan.Dropper
t3scan.1.7.8.0

Malwarebytes
Trojan.MSIL
v2014.10.13.12

Norman
Suspicious_Gen4.EETVN
11.20141013

File size:
795.1 KB (814,229 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Purps 2013

Original file name:
Lastlogin Stub.exe

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
1/12/2013 11:12:34 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:IoCprlAd1XioemSr/Nm0FH0Pd2OSK0awBdsZTYOlAd1XioemSr/Nm0FH0Pd2OSKz:IZpSLAH64lasiZTqLAH64lc

Entry address:
0x6DA0E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
431 KB (441,344 bytes)

The file minecraft force op.exe has been seen being distributed by the following 8 URLs.

Remove minecraft force op.exe - Powered by Reason Core Security