Safe
Official Fabric mod loader installer; 16 tier-1 engines silent, 17,720 submissions, legitimate infrastructure contact.
488b5f4f1d5e422212…7e107de263The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The file exhibits a clean engine profile: zero malicious detections across 70 reporting engines, including all major tier-1 vendors (BitDefender, Kaspersky, ESET-NOD32, Avast, Fortinet, F-Secure, Emsisoft, GData, Avira, AVG, DrWeb). The high prevalence (3,711 unique submitters, 17,720 submissions) and 182-day age indicate a widely-known, established file. Community researchers confirm this is the legitimate Fabric installer; one explicitly rates it 'Clean' with score 4/100. The triggered heuristic (DirectIpC2) reflects the installer contacting Cloudflare and Google infrastructure for CDN delivery and certificate validation — standard installer behaviour, not malware C2. No malicious children, no malicious contacted hosts, and no external intelligence hits further support a benign classification.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines: 0/70 malicious; tier1Malicious=0; tier1ReportedClean=16 (BitDefender, Kaspersky, ESET-NOD32, Avast, Fortinet, F-Secure, Emsisoft, GData, Avira, AVG, DrWeb all silent)
prevalence.classification=common_old; 3,711 unique submitters, 17,720 submissions over 182 days — widely distributed, established file
behaviour.contactedIps=[172.67.151.177 (Cloudflare), 8.8.8.8 (Google DNS), 104.21.33.240 (Cloudflare), 162.159.36.2 (Cloudflare)]; behaviour.contactedUrls include meta.fabricmc.net (legitimate Fabric metadata) and Microsoft CRL endpoints
community comments identify file as official Fabric mod loader v1.1.1 from fabricmc.net, compiled via GitHub Actions; one researcher verdict 'Clean' score 4/100
triggeredHeuristics: MalwareTips.Synth.DirectIpC2 fired (medium) but evidence shows legitimate CDN + CRL queries, not C2 beacons
- Zero malicious detections across 70 engines; 16 tier-1 engines silent
- High prevalence: 17,720 submissions, 182-day history, 3,711 unique submitters
- Community researchers confirm official Fabric mod loader v1.1.1
- Contacted hosts are legitimate infrastructure (Cloudflare, Google, Microsoft)
- No malicious dropped children, no malicious contacted hosts
- File is unsigned (common for community-maintained open-source projects)
- Heuristic alert on direct-IP contact (resolved as normal CDN/CRL queries, not C2)
This file is safe. It is the official Fabric mod loader installer for Minecraft. Download it from fabricmc.net or the official GitHub repository with confidence.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 172.67.151.177
- 8.8.8.8
- 104.21.33.240
- 162.159.36.2
- https://meta.fabricmc.net:443/v2/versions/loader
- https://meta.fabricmc.net:443/v2/versions/game
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl
- http://crl.microsoft.com/pki/crl/products/WinPCA.crl
- C:\Users\<USER>\AppData\Local\Temp\fabric-installer-1768853646.log
- C:\Users\<USER>\AppData\Local\Temp\hsperfdata_<USER>\6380
- C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestamp
- C:\Users\<USER>\AppData\Local\Temp\hsperfdata_<USER>\2588
- C:\Users\<USER>\AppData\Local\Temp\/fabric-installer-1766360824.log
- C:\Users\<USER>\AppData\Local\Temp\hsperfdata_azure\664
- C:\Users\<USER>\AppData\Local\Temp\hsperfdata_azure\1232
- C:\Users\<USER>\AppData\Local\Temp\hsperfdata_azure\1932
- C:\Users\<USER>\AppData\Local\Temp\hsperfdata_azure\2688
- C:\Users\<USER>\AppData\Local\Temp\hsperfdata_azure\2480
- \BaseNamedObjects\Local\SM0:6984:304:WilStaging_02
- \BaseNamedObjects\Local\SM0:6984:120:WilError_03
- \BaseNamedObjects\Local\ZonesCacheCounterMutex
- \BaseNamedObjects\Local\ZonesLockedCacheCounterMutex
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- a1fb74983ba0d8eb876f…e6c89eNever scannednever seen before
- 496b7e3eb96bbee721bb…89f05bNever scannednever seen before
- e023fa87c837b886129f…0f7857Never scannednever seen before
- 21fa4f4955149fec0211…fedb7aNever scannednever seen before
- 272b33c3084aced9af31…fe767aNever scannednever seen before
- 735af26ec0393eeacbe1…e040c8Never scannednever seen before
- c2ff442ed3370e8527e0…01f9bcNever scannednever seen before
- eb619a81792dce1ad412…ef968cNever scannednever seen before
- cf11b1011221084ecb6c…8db27fNever scannednever seen before
- 14bcaf6f1373db5b314d…121201Never scannednever seen before
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 4 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence172.67.151.177 · 8.8.8.8 · 104.21.33.240
0 detections across 74 engines
Section entropy & packers
Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.
How often this file shows up in the wild
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Forensic fingerprint
- File name
- fabric-installer-native-bootstrap.exe
- Size
- 472.2 KB
- MIME type
- (unknown)
- Detected type
- Win32 EXE
- SHA-256
- 488b5f4f1d5e422212c445978be256e2d1f7b96e882c750efc2a1c7e107de263
- MD5
- 70709bdda089257bab80d006dba5db2a
- SHA-1
- 9aa0b255a8672cc831261a92ce9c7498dbbcdb88
- PE imphash
- 44250d281af5f92757fa094a25d1d797
- First seen (VT)
- 12/22/2025, 6:31:19 AM
- Last analysis (VT)
- 6/21/2026, 3:30:03 PM
- First scan (MalwareTips)
- 6/22/2026, 2:57:21 PM
- Last scan (MalwareTips)
- 6/22/2026, 2:57:21 PM
- Community reputation
- +12trusted
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.