minecraft.exe

The application minecraft.exe has been detected as a potentially unwanted program by 15 anti-malware scanners. According to Microsoft Security Essentials, the software includes a bundle of the DealPly adware which is installed on a user's PC during setup using the InstallCore platform. The file has been seen being downloaded from downloader.downloadinfo.co a known adware distribution point operated by Downloadinfo.
MD5:
6fa34ba67705f545053fa46f8ebbfb57

SHA-1:
ff17474d978d3d40b25e55d01b72af83b803c542

SHA-256:
526de8a16ff12e909f5474c345086f99b27d43f6d2a2d0f811789c0d96a3d877

Scanner detections:
15 / 68

Status:
Potentially unwanted

Explanation:
This software bundler installs other potentially unwanted software, including DealPly. Which includes offers in a user's web browser which state they are "Powered by DealPly".

Analysis date:
4/24/2024 11:04:11 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Packed/Win32.InstallCore
2013.02.17

Avira AntiVirus
7.11.61.114

Baidu Antivirus
Malware.Win32.Adware
4.0.3.1534

Comodo Security
UnclassifiedMalware
15272

Dr.Web
Adware.InstallCore.86
9.0.1.063

ESET NOD32
Win32/InstallCore.AZ (variant)
9.8018

F-Prot
W32/InstallCore.S.gen
v6.4.7.1.166

K7 AntiVirus
Unwanted-Program
13.164.8548

McAfee
Artemis!F01CFFC90ED5
5600.6837

Microsoft Security Essentials
1.163.1557.0

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.15302

Sophos
Install Core
4.93

Trend Micro House Call
TROJ_GEN.F47V0118
7.2.63

Trend Micro
TROJ_GEN.RCBCOCO
10.465.04

VIPRE Antivirus
Trojan.Win32.Generic
15580

File size:
1.1 MB (1,203,848 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\minecraft.exe

File PE Metadata
Compilation timestamp:
6/19/1992 4:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:OVUoZA0BgSpdjVwc8APvNkTvG0wEYur8xG6vuTkdTisspiMO7:yZTBgSpHKAeTvG0dYur8xciTis

Entry address:
0xD6810

Entry point:
55, 8B, EC, 83, C4, F0, B8, B8, FD, 41, 00, E8, 29, F4, FF, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.7122

Developed / compiled with:
Microsoft Visual C++

Code size:
869.5 KB (890,368 bytes)

The file minecraft.exe has been seen being distributed by the following URL.

Remove minecraft.exe - Powered by Reason Core Security