1.8 5zig mod download - recommend you
The 5zig Mod v3.12.5 for Minecraft 1.8.9.jar
This report is generated from a file or URL submitted to this webservice on March 17th 2019 11:12:35 (UTC)
Guest System: Windows 7 64 bit, Professional, 6.1 (build 7601), Service Pack 1
Report generated by Falcon Sandbox v8.30 © Hybrid Analysis
Indicators
Not all malicious and suspicious indicators are displayed. Get your own cloud service or the full version to view all details.
Suspicious Indicators 5
- Anti-Reverse Engineering
- Environment Awareness
- Possibly tries to implement anti-virtualization techniques
- details
- "2017-12-11 20:24:00, Info DISM API: PID=2796 TID=2828 Input parameters: Session: 2, DriverPath: %WINDIR%\System32\DriverStore\FileRepository\vboxvideo.inf_amd64_neutral_282ccc1684d6e163\vboxvideo.inf - DismGetDriverInfoInternal" (Indicator: "vbox")
"2017-12-11 20:24:00, Info DISM DISM Driver Manager: PID=1172 Driver C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_12eb69aba9e5025e\vboxguest.inf is boot-critical. - CDriverPackage::FillInPackageDetails" (Indicator: "vbox")
"2017-12-11 20:24:00, Info DISM DISM Driver Manager: PID=1172 Driver C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_12eb69aba9e5025e\vboxguest.inf is boot-critical. - CDriverPackage::FillInPackageDetails" (Indicator: "vboxguest")
"2017-12-11 20:24:00, Info IsDriverPackageSigned: File [C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_12eb69aba9e5025e\vboxguest.inf] is signed by a catalog [C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_12eb69aba9e5025e\VBoxGuest.cat]" (Indicator: "vbox")
"2017-12-11 20:24:00, Info IsDriverPackageSigned: File [C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_12eb69aba9e5025e\vboxguest.inf] is signed by a catalog [C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_12eb69aba9e5025e\VBoxGuest.cat]" (Indicator: "vboxguest")
"2017-12-11 20:24:00, Info DISM DISM Driver Manager: PID=1172 Signature status of driver C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_12eb69aba9e5025e\vboxguest.inf is: SIGNED - CDriverPackage::InitSignatureStatus" (Indicator: "vbox")
"2017-12-11 20:24:00, Info DISM DISM Driver Manager: PID=1172 Signature status of driver C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_12eb69aba9e5025e\vboxguest.inf is: SIGNED - CDriverPackage::InitSignatureStatus" (Indicator: "vboxguest")
"2017-12-11 20:24:00, Info DISM API: PID=2796 TID=2828 Input parameters: Session: 2, DriverPath: C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_12eb69aba9e5025e\vboxguest.inf - DismGetDriverInfoInternal" (Indicator: "vbox")
"2017-12-11 20:24:00, Info DISM API: PID=2796 TID=2828 Input parameters: Session: 2, DriverPath: C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_12eb69aba9e5025e\vboxguest.inf - DismGetDriverInfoInternal" (Indicator: "vboxguest")
"2018-02-20 09:38:55, Info DISM API: PID=1720 TID=1964 Input parameters: Session: 2, DriverPath: C:\Windows\System32\DriverStore\FileRepository\vboxvideo.inf_amd64_neutral_bc42bb1917d1bc65\vboxvideo.inf - DismGetDriverInfoInternal" (Indicator: "vbox")
"2018-02-20 09:38:55, Info DISM DISM Driver Manager: PID=3012 Driver C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_9fc262b6119df1ee\vboxguest.inf is boot-critical. - CDriverPackage::FillInPackageDetails" (Indicator: "vbox")
"2018-02-20 09:38:55, Info DISM DISM Driver Manager: PID=3012 Driver C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_9fc262b6119df1ee\vboxguest.inf is boot-critical. - CDriverPackage::FillInPackageDetails" (Indicator: "vboxguest")
"2018-02-20 09:38:55, Info IsDriverPackageSigned: File [C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_9fc262b6119df1ee\vboxguest.inf] is signed by a catalog [C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_9fc262b6119df1ee\VBoxGuest.cat]" (Indicator: "vbox")
"2018-02-20 09:38:55, Info IsDriverPackageSigned: File [C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_9fc262b6119df1ee\vboxguest.inf] is signed by a catalog [C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_9fc262b6119df1ee\VBoxGuest.cat]" (Indicator: "vboxguest")
"2018-02-20 09:38:55, Info DISM DISM Driver Manager: PID=3012 Signature status of driver C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_9fc262b6119df1ee\vboxguest.inf is: SIGNED - CDriverPackage::InitSignatureStatus" (Indicator: "vbox")
"2018-02-20 09:38:55, Info DISM DISM Driver Manager: PID=3012 Signature status of driver C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_9fc262b6119df1ee\vboxguest.inf is: SIGNED - CDriverPackage::InitSignatureStatus" (Indicator: "vboxguest")
"2018-02-20 09:38:55, Info DISM API: PID=1720 TID=1964 Input parameters: Session: 2, DriverPath: C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_9fc262b6119df1ee\vboxguest.inf - DismGetDriverInfoInternal" (Indicator: "vbox")
"2018-02-20 09:38:55, Info DISM API: PID=1720 TID=1964 Input parameters: Session: 2, DriverPath: C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_9fc262b6119df1ee\vboxguest.inf - DismGetDriverInfoInternal" (Indicator: "vboxguest")
"2019-01-03 17:11:42, Info DISM API: PID=2008 TID=2408 Input parameters: Session: 2, DriverPath: C:\Windows\System32\DriverStore\FileRepository\vboxvideo.inf_amd64_neutral_e9f3789e40cc2499\vboxvideo.inf - DismGetDriverInfoInternal" (Indicator: "vbox")
"2019-01-03 17:11:42, Info DISM DISM Driver Manager: PID=1456 Driver C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_cf01905bf05ff6d6\vboxguest.inf is boot-critical. - CDriverPackage::FillInPackageDetails" (Indicator: "vbox")
"2019-01-03 17:11:42, Info DISM DISM Driver Manager: PID=1456 Driver C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_cf01905bf05ff6d6\vboxguest.inf is boot-critical. - CDriverPackage::FillInPackageDetails" (Indicator: "vboxguest")
"2019-01-03 17:11:42, Info IsDriverPackageSigned: File [C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_cf01905bf05ff6d6\vboxguest.inf] is signed by a catalog [C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_cf01905bf05ff6d6\VBoxGuest.cat]" (Indicator: "vbox")
"2019-01-03 17:11:42, Info IsDriverPackageSigned: File [C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_cf01905bf05ff6d6\vboxguest.inf] is signed by a catalog [C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_cf01905bf05ff6d6\VBoxGuest.cat]" (Indicator: "vboxguest")
"2019-01-03 17:11:42, Info DISM DISM Driver Manager: PID=1456 Signature status of driver C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_cf01905bf05ff6d6\vboxguest.inf is: SIGNED - CDriverPackage::InitSignatureStatus" (Indicator: "vbox")
"2019-01-03 17:11:42, Info DISM DISM Driver Manager: PID=1456 Signature status of driver C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_cf01905bf05ff6d6\vboxguest.inf is: SIGNED - CDriverPackage::InitSignatureStatus" (Indicator: "vboxguest")
"2019-01-03 17:11:43, Info DISM API: PID=2008 TID=2408 Input parameters: Session: 2, DriverPath: C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_cf01905bf05ff6d6\vboxguest.inf - DismGetDriverInfoInternal" (Indicator: "vbox")
"2019-01-03 17:11:43, Info DISM API: PID=2008 TID=2408 Input parameters: Session: 2, DriverPath: C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_cf01905bf05ff6d6\vboxguest.inf - DismGetDriverInfoInternal" (Indicator: "vboxguest")
"2019-01-03 17:11:43, Info DISM DISM Driver Manager: PID=1456 Driver C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_cf01905bf05ff6d6\vboxguest.inf is boot-critical. - CDriverPackage::FillInPackageDetails" (Indicator: "vbox")
"2019-01-03 17:11:43, Info DISM DISM Driver Manager: PID=1456 Driver C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_cf01905bf05ff6d6\vboxguest.inf is boot-critical. - CDriverPackage::FillInPackageDetails" (Indicator: "vboxguest")
"2019-01-03 17:11:43, Info IsDriverPackageSigned: File [C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_cf01905bf05ff6d6\vboxguest.inf] is signed by a catalog [C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_cf01905bf05ff6d6\VBoxGuest.cat]" (Indicator: "vbox")
"2019-01-03 17:11:43, Info IsDriverPackageSigned: File [C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_cf01905bf05ff6d6\vboxguest.inf] is signed by a catalog [C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_cf01905bf05ff6d6\VBoxGuest.cat]" (Indicator: "vboxguest")
"2019-01-03 17:11:43, Info DISM DISM Driver Manager: PID=1456 Signature status of driver C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_cf01905bf05ff6d6\vboxguest.inf is: SIGNED - CDriverPackage::InitSignatureStatus" (Indicator: "vbox")
"2019-01-03 17:11:43, Info DISM DISM Driver Manager: PID=1456 Signature status of driver C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_cf01905bf05ff6d6\vboxguest.inf is: SIGNED - CDriverPackage::InitSignatureStatus" (Indicator: "vboxguest")
"2019-03-17 12:18:13, Error DISM DISM Driver Manager: PID=3028 Failed opening driver package for x86: INF Name='C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_ad82ab6f57da5f72\vboxguest.inf' - CDriverPackage::OpenDmiDriverPackages(hr:0x80070003)" (Indicator: "vbox")
"2019-03-17 12:18:13, Error DISM DISM Driver Manager: PID=3028 Failed opening driver package for x86: INF Name='C:\Windows\System32\DriverStore\FileRepository\vboxguest.inf_amd64_neutral_ad82ab6f57da5f72\vboxguest.inf' - CDriverPackage::OpenDmiDriverPackages(hr:0x80070003)" (Indicator: "vboxguest") - source
- String
- relevance
- 4/10
- Possibly tries to implement anti-virtualization techniques
- General
- Installation/Persistance
- Drops executable files
- details
- "DISMHOST.EXE.5C8E3AAF.bin" has type "PE32+ executable (GUI) x86-64 for MS Windows"
- source
- Extracted File
- relevance
- 10/10
- Drops executable files
- Network Related
- Contains ability to listen for incoming connections
- details
- getListener@The5zigMod at f1ed823a001f111da8eda5cdd6798e71-10d
EventListener at f1ed823a001f111da8eda5cdd6798e71-1f69
GenericFutureListener at f1ed823a001f111da8eda5cdd6798e71-2162
GenericFutureListener at f1ed823a001f111da8eda5cdd6798e71-2b8e
GenericFutureListener at f1ed823a001f111da8eda5cdd6798e71-2c1f
GenericFutureListener at f1ed823a001f111da8eda5cdd6798e71-2eae
GenericFutureListener at f1ed823a001f111da8eda5cdd6798e71-317c
GenericFutureListener at f1ed823a001f111da8eda5cdd6798e71-337c
GenericFutureListener at f1ed823a001f111da8eda5cdd6798e71-3534
GenericFutureListener at f1ed823a001f111da8eda5cdd6798e71-3747
GenericFutureListener at f1ed823a001f111da8eda5cdd6798e71-3814
ChannelFutureListener at f1ed823a001f111da8eda5cdd6798e71-3a20
GenericFutureListener at f1ed823a001f111da8eda5cdd6798e71-3b9d
ChannelFutureListener at f1ed823a001f111da8eda5cdd6798e71-3c2b
GenericFutureListener at f1ed823a001f111da8eda5cdd6798e71-3e8b
GenericFutureListener at f1ed823a001f111da8eda5cdd6798e71-3ff9
GenericFutureListener at f1ed823a001f111da8eda5cdd6798e71-414c
GenericFutureListener at f1ed823a001f111da8eda5cdd6798e71-4903
GenericFutureListener at f1ed823a001f111da8eda5cdd6798e71-4c3c
GenericFutureListener at f1ed823a001f111da8eda5cdd6798e71-4cf9 - source
- Hybrid Analysis Technology
- relevance
- 5/10
- Contains ability to listen for incoming connections
Informative 16
- Anti-Reverse Engineering
- Environment Awareness
- Contains ability to query the machine version
- details
- getVersionName@InstallerNew at f1ed823a001f111da8eda5cdd6798e71-747c
getVersion@Constants at f1ed823a001f111da8eda5cdd6798e71-1307e
getVersion@Row at f1ed823a001f111da8eda5cdd6798e71-14356
getVersion@Map at f1ed823a001f111da8eda5cdd6798e71-18761
getVersion@Row at f1ed823a001f111da8eda5cdd6798e71-1ad6a
getVersion@Row at f1ed823a001f111da8eda5cdd6798e71-1ae9a
GetVersionExW@KERNEL32.DLL at 00014088-00003028-13696-285--00B723C0
GetVersionExA@KERNEL32.DLL at 00014088-00003028-13696-437--00B71246
GetVersionExW@KERNEL32.dll (Show Stream)
GetVersionExA@KERNEL32.dll (Show Stream) - source
- Hybrid Analysis Technology
- relevance
- 1/10
- Makes a code branch decision directly after an API that is environment aware
- details
- Found API call GetVersionExA@KERNEL32.DLL directly followed by "cmp dword ptr [rsp+30h], 02h" and "jne FFFFFFFFFF48EDEBh" at 00014088-00003028-13696-437--00B71246
Found API call GetVersionExA@KERNEL32.dll directly followed by "cmp dword ptr [rsp+30h], 02h" and "jne 000000010000EDEBh" (Show Stream) - source
- Hybrid Analysis Technology
- relevance
- 10/10
- Possibly tries to detect the presence of a debugger
- details
- GetProcessHeap@KERNEL32.DLL at 00014088-00003028-13696-322--00B729E8
GetProcessHeap@KERNEL32.dll (Show Stream)
GetProcessHeap@KERNEL32.dll (Show Stream)
GetProcessHeap@KERNEL32.dll (Show Stream) - source
- Hybrid Analysis Technology
- relevance
- 1/10
- Contains ability to query the machine version
- External Systems
- General
- Contains PDB pathways
- details
- "dismhost.pdb"
- source
- String
- relevance
- 1/10
- Creates a writable file in a temporary directory
- details
- "javaw.exe" created file "%TEMP%\hsperfdata_Sk3KsC7\3592"
- source
- API Call
- relevance
- 1/10
- Creates mutants
- details
- "\Sessions\1\BaseNamedObjects\Local\__DDrawExclMode__"
"\Sessions\1\BaseNamedObjects\Local\__DDrawCheckExclMode__"
"Local\__DDrawExclMode__"
"Local\__DDrawCheckExclMode__"
"\BaseNamedObjects\DBWinMutex"
"\BaseNamedObjects\Global\WdsSetupLogInit"
"\BaseNamedObjects\Global\SetupLog" - source
- Created Mutant
- relevance
- 3/10
- Drops files marked as clean
- details
- Antivirus vendors marked dropped file "DISMHOST.EXE.5C8E3AAF.bin" as clean (type is "PE32+ executable (GUI) x86-64 for MS Windows")
- source
- Extracted File
- relevance
- 10/10
- Process launched with changed environment
- details
- Process "DismHost.exe" (Show Process) was launched with modified environment variables: "CommonProgramFiles, Path, LOCALAPPDATA, USERDOMAIN, PROCESSOR_ARCHITECTURE, TEMP, APPDATA, USERPROFILE, TMP, ProgramFiles"
Process "DismHost.exe" (Show Process) was launched with missing environment variables: "PROCESSOR_ARCHITEW6432, LOGONSERVER, PROMPT, VXDIR, HOMEPATH, HOMEDRIVE" - source
- Monitored Target
- relevance
- 10/10
- Spawns new processes
- details
- Spawned process "DismHost.exe" with commandline "{699FED25-6413-41DE-B887-E98091165104}" (Show Process)
- source
- Monitored Target
- relevance
- 3/10
- Spawns new processes that are not known child processes
- details
- Spawned process "DismHost.exe" with commandline "{699FED25-6413-41DE-B887-E98091165104}" (Show Process)
- source
- Monitored Target
- relevance
- 3/10
- Contains PDB pathways
- Installation/Persistance
- Contains ability to lookup the windows account name
- details
- BOLD) + this.getUsername@ChatColor at f1ed823a001f111da8eda5cdd6798e71-317c
this.friend.getUsername@GuiFriendProfile at f1ed823a001f111da8eda5cdd6798e71-5445
getUsername@Row at f1ed823a001f111da8eda5cdd6798e71-5611 - source
- Hybrid Analysis Technology
- relevance
- 5/10
- Dropped files
- details
- "DISMHOST.EXE.5C8E3AAF.bin" has type "PE32+ executable (GUI) x86-64 for MS Windows"
"17dfc292991c7c62.timestamp" has type "ASCII text with CRLF line terminators"
"dism.log" has type "UTF-8 Unicode (with BOM) text with very long lines with CRLF line terminators" - source
- Extracted File
- relevance
- 3/10
- Touches files in the Windows directory
- details
- "javaw.exe" touched file "%WINDIR%\System32\tzres.dll"
"javaw.exe" touched file "%WINDIR%\Globalization\Sorting\SortDefault.nls"
"javaw.exe" touched file "%WINDIR%\System32\en-US\kernel32.dll.mui"
"javaw.exe" touched file "%WINDIR%\System32\en-US\KernelBase.dll.mui"
"javaw.exe" touched file "%WINDIR%\Fonts\tahoma.ttf"
"javaw.exe" touched file "%WINDIR%\Fonts\tahomabd.ttf"
"javaw.exe" touched file "%WINDIR%\Fonts\aparajbi.ttf"
"javaw.exe" touched file "%WINDIR%\Fonts\utsaahbi.ttf"
"javaw.exe" touched file "%WINDIR%\Fonts\kokilabi.ttf"
"javaw.exe" touched file "%WINDIR%\Fonts\iskpotab.ttf"
"javaw.exe" touched file "%WINDIR%\Fonts\cour.ttf"
"javaw.exe" touched file "%WINDIR%\Fonts\simsun.ttc"
"javaw.exe" touched file "%WINDIR%\Fonts\msmincho.ttc"
"javaw.exe" touched file "%WINDIR%\Fonts\simsunb.ttf"
"javaw.exe" touched file "%WINDIR%\Fonts\timesi.ttf"
"javaw.exe" touched file "%WINDIR%\Fonts\ariali.ttf"
"javaw.exe" touched file "%WINDIR%\Fonts\arialbi.ttf" - source
- API Call
- relevance
- 7/10
- Contains ability to lookup the windows account name
- Network Related
- Found potential URL in binary/memory
- details
- Heuristic match: "rwXcs.KE"
Heuristic match: "5zig.eu.equalsIgnoreCase(host) && !5zig.net"
Heuristic match: "jacob.dll.name"
Heuristic match: "chat.audio.name"
Heuristic match: "localhost : 5zig.net"
Heuristic match: "badlion.net) || host.toLowerCase(Locale.ROOT).endsWith(minesane.net"
Heuristic match: "bergwerklabs.de"
Heuristic match: "cytooxien.de"
Heuristic match: "dustmc.de"
Heuristic match: "gommehd.net) || host.toLowerCase(Locale.ROOT).endsWith(gommehd.de) || host.toLowerCase(Locale.ROOT).endsWith(gommehd.tk"
Heuristic match: "hivemc.eu) || host.toLowerCase(Locale.ROOT).endsWith(hivemc.us) || host.toLowerCase(Locale.ROOT).endsWith(hivemc.com"
Heuristic match: "mc.hypixel.net"
Heuristic match: "mineplex.com) || host.toLowerCase(Locale.ROOT).endsWith(mineplex.eu) || host.toLowerCase(Locale.ROOT).endsWith(mineplex.us"
Heuristic match: "playminity.com"
Heuristic match: "rewinside.tv"
Heuristic match: "timolia.de"
Heuristic match: "[%s], I18n.translate(group.info))), 10, String.format([%s], I18n.translate(group.info"
Heuristic match: "group.create.name"
Heuristic match: "chat_filter.edit.name"
Heuristic match: "server.hypixel.stats.info"
Heuristic match: "%s%s: %s#%s, new Object[]{ChatColor.YELLOW, I18n.translate(profile.id"
Heuristic match: "%s%s: %s, new Object[]{ChatColor.YELLOW, I18n.translate(profile.name"
Heuristic match: "teamspeak.auth.info"
Heuristic match: "Supports Servers like timolia.de, gommehd.net, mc.hypixel.net"
Heuristic match: "gui.no"
Heuristic match: "teamspeak.ban_client.name"
Heuristic match: "teamspeak.create_channel.name"
Heuristic match: "channel.name"
Heuristic match: "mcmod.info"
Heuristic match: ".spotilocal.com"
Heuristic match: "hypixel.net"
Heuristic match: "Bergwerklabs.de"
Heuristic match: "GommeHD.net"
Heuristic match: "Hypixel.net"
Heuristic match: "mcctf.com"
Heuristic match: "mc-hg.com) || this.getServerType().equals(mc-sabotage.com"
Heuristic match: "hub.mcpvp.com"
Heuristic match: "vip.mcpvp.com"
Heuristic match: "mvp.mcpvp.com"
Heuristic match: "pro.mcpvp.com"
Heuristic match: "mc-hg.com"
Heuristic match: "nosoup.mc-hg.com"
Heuristic match: "raid.mcpvp.com"
Heuristic match: "kitpvp.us"
Heuristic match: "mc-sabotage.com"
Heuristic match: "mcheadshot.com"
Heuristic match: "mc-maze.com"
Heuristic match: "minecraftbuild.com"
Heuristic match: "parkour.mcpvp.com"
Heuristic match: "hub.pvpdojo.com"
Heuristic match: "mcsiege.com"
Heuristic match: "Mineplex.com"
Heuristic match: "PlayMinity.com"
Heuristic match: "simplehg.com) || host.toLowerCase(Locale.ROOT).endsWith(simplehg.net) || host.toLowerCase(Locale.ROOT).endsWith(simplehg.eu) || host.toLowerCase(Locale.ROOT).endsWith(simplehg.de) || host.toLowerCase(Locale.ROOT).endsWith(simplegalaxy.net"
Heuristic match: "Timolia.de"
Heuristic match: "Venicraft.at"
Heuristic match: "venicraft.at"
Heuristic match: "session.minecraft.net, sessionserver.mojang.com"
Heuristic match: "account.mojang.com"
Heuristic match: "auth.mojang.com, authserver.mojang.com"
Heuristic match: "skins.minecraft.net"
Heuristic match: "_htt_s:JJ_.5Zi_.net" - source
- String
- relevance
- 10/10
- Found potential URL in binary/memory
File Details
Screenshots
Loading content, please wait...
Hybrid Analysis
Tip: Click an analysed process below to view more details.
Analysed 2 processes in total (System Resource Monitor).
-