Safe
Legitimate OptiFine Minecraft mod JAR with zero detections across 60 engines, strong tier-1 clean consensus, and medium prevalence from thousands of submissions.
63a60c48b3370920e9…be668d3903The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
Zero malicious detections from good coverage (60/75 engines), including full tier-1 clean signals, rules out malware. Medium prevalence and filename point to popular Minecraft OptiFine mod. Offensive MITRE tags appear but lack malicious sandbox confirmation or dropped threats, consistent with Java app norms like process handling. No external intel, heuristics, or feedback raises concerns. Unsigned status is common for open-source mods without impacting clean profile.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
17/17 tier1 engines clean (Avast, BitDefender, ESET-NOD32, Kaspersky, Microsoft)
prevalence: 3899 submissions / 2950 unique sources (medium)
fileName='OptiFine_1.21.11_HD_U_J9.jar' (Minecraft mod)
0 malicious sandbox verdicts, 0/8 droppedChildren malicious
- 17 tier-1 engines clean
- Medium prevalence, no threat labels
- Matches known Minecraft mod filename
- No malicious children or sandbox hits
- No heuristics or external intel flags
- Unsigned executable
- Offensive MITRE techniques in behaviour (T1543.002, T1562.001)
This is a safe OptiFine Minecraft optimization mod. Download from official sources (optifine.net) and scan periodically as mods evolve.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- C:\Users\<USER>\AppData\Local\Temp\hsperfdata_<USER>\3720
- C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestamp
- C:\ProgramData\Oracle\Java\.oracle_jre_usage\17dfc292991c8786.timestamp
- C:\Users\user\AppData\Local\Temp\hsperfdata_user
- C:\Users\user\AppData\Local\Temp\hsperfdata_user\7164
- C:\Users\user\AppData\Local\Temp\hsperfdata_user\3484
Files this sample writes at runtime
This file drops 8 children at runtime. None are currently flagged malicious in our cache.
- db65a1c9cae09215c805…43321bNever scannednever seen before
- 7b7364406fc3be34c265…b422c8Never scannednever seen before
- e31dba7b57e069034269…780edbNever scannednever seen before
- d87c5f3cdfb5b7c0510e…1ade9eNever scannednever seen before
- ed2124b2226efa886282…187042Never scannednever seen before
- 2423ea593d6f112e0729…0c58b2Never scannednever seen before
- 44a3bab2c338e3bca24c…d3b9e7Never scannednever seen before
- ac941ead01d5451a7a9f…253227Never scannednever seen before
0 detections across 75 engines
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- OptiFine_1.21.11_HD_U_J9.jar
- Size
- 7.67 MB
- MIME type
- (unknown)
- Detected type
- JAR
- SHA-256
- 63a60c48b3370920e96d4c32570d7154d17b3a86654c4f1d1df418be668d3903
- MD5
- a1ce0d17ef1fc016582a82234cccf2f1
- SHA-1
- 8e48c7d31cf08d8908d692fa8beea865ff2c16ac
- First seen (VT)
- 2/5/2026, 1:30:33 PM
- Last analysis (VT)
- 4/30/2026, 12:50:43 PM
- First scan (MalwareTips)
- 4/30/2026, 9:20:16 PM
- Last scan (MalwareTips)
- 4/30/2026, 9:20:16 PM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.