File verdict·Decided by the MT AI Engine
Our call

Safe

Legitimate OptiFine Minecraft mod JAR with zero detections across 60 engines, strong tier-1 clean consensus, and medium prevalence from thousands of submissions.

Trust score92High trust
MT AI confidence · 95%
OptiFine_1.21.11_HD_U_J9.jar
7.7 MB
63a60c48b3370920e9be668d3903
Antivirus engines
0 of 75 flagged
Code signing
Unsigned
Age
First seen 4mo ago
MT AI Engine · our arbiter

The verdict, reasoned out.

Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.

95%Confidence
Very high
Reasoning

Zero malicious detections from good coverage (60/75 engines), including full tier-1 clean signals, rules out malware. Medium prevalence and filename point to popular Minecraft OptiFine mod. Offensive MITRE tags appear but lack malicious sandbox confirmation or dropped threats, consistent with Java app norms like process handling. No external intel, heuristics, or feedback raises concerns. Unsigned status is common for open-source mods without impacting clean profile.

Key signals · 4

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. 17/17 tier1 engines clean (Avast, BitDefender, ESET-NOD32, Kaspersky, Microsoft)

  2. prevalence: 3899 submissions / 2950 unique sources (medium)

  3. fileName='OptiFine_1.21.11_HD_U_J9.jar' (Minecraft mod)

  4. 0 malicious sandbox verdicts, 0/8 droppedChildren malicious

Points in its favour
  • 17 tier-1 engines clean
  • Medium prevalence, no threat labels
  • Matches known Minecraft mod filename
  • No malicious children or sandbox hits
  • No heuristics or external intel flags
Points against
  • Unsigned executable
  • Offensive MITRE techniques in behaviour (T1543.002, T1562.001)
What to do

This is a safe OptiFine Minecraft optimization mod. Download from official sources (optifine.net) and scan periodically as mods evolve.

Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
7

Adversary techniques mapped to the MITRE ATT&CK framework.

T1064T1082T1083T1518.001T1543.002T1562.001T1564.001
Spawned processes
15
$(unnamed)
"C:\Program Files\Java\jre-1.8\bin\java.exe" -jar "C:\Users\<USER>\Desktop\download.jar"
$(unnamed)
C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M
$(unnamed)
C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Program Files\Java\jre1.8.0_441\bin\java.exe" -javaagent:"C:\Users\user\AppData\Local\Temp\jartracer.jar" -jar "C:\Users\user\Desktop\runtime.jar"" >> C:\cmdlinestart.log 2>&1
$(unnamed)
C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
$(unnamed)
"C:\Program Files\Java\jre1.8.0_441\bin\java.exe" -javaagent:"C:\Users\user\AppData\Local\Temp\jartracer.jar" -jar "C:\Users\user\Desktop\runtime.jar"
$(unnamed)
/bin/sh sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/syslog
$(unnamed)
/usr/lib/rsyslog/rsyslog-rotate
$(unnamed)
/usr/bin/systemctl systemctl kill -s HUP rsyslog.service
+7 more processes captured.
Filesystem & mutexes
15
Files written14
  • C:\Users\<USER>\AppData\Local\Temp\hsperfdata_<USER>\3720
  • C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestamp
  • C:\ProgramData\Oracle\Java\.oracle_jre_usage\17dfc292991c8786.timestamp
  • C:\Users\user\AppData\Local\Temp\hsperfdata_user
  • C:\Users\user\AppData\Local\Temp\hsperfdata_user\7164
+9 more
Files deleted1
  • C:\Users\user\AppData\Local\Temp\hsperfdata_user\3484
Dropped payload

Files this sample writes at runtime

This file drops 8 children at runtime. None are currently flagged malicious in our cache.

8 unseen
  • db65a1c9cae09215c80543321bNever scanned
    never seen before
  • 7b7364406fc3be34c265b422c8Never scanned
    never seen before
  • e31dba7b57e069034269780edbNever scanned
    never seen before
  • d87c5f3cdfb5b7c0510e1ade9eNever scanned
    never seen before
  • ed2124b2226efa886282187042Never scanned
    never seen before
  • 2423ea593d6f112e07290c58b2Never scanned
    never seen before
  • 44a3bab2c338e3bca24cd3b9e7Never scanned
    never seen before
  • ac941ead01d5451a7a9f253227Never scanned
    never seen before
No researcher-database hits
External threat-intel sources were not collected for this scan.
Antivirus engine breakdown

0 detections across 75 engines

0 malicious0 suspicious75 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-238 engines
0flag
Mainstream engines with mixed FP rates
Low-trust20 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 75 engines report this file as clean.
Hash 63a60c48b337… cross-referenced against 75 AV engines via our AV network.
Prevalence

How often this file shows up in the wild

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
2,950
Hundreds of people have uploaded this — common.
Total submissions
3,899
Includes repeat uploads by the same source.
First seen by VT
4mo ago
Feb 5, 2026
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
2/5/2026, 1:30:33 PM
First seen (MalwareBazaar)
Last analysis (VT)
4/30/2026, 12:50:43 PM
Scanned here
4/30/2026, 9:20:16 PM
File name
OptiFine_1.21.11_HD_U_J9.jar
Size
7.67 MB
MIME type
(unknown)
Detected type
JAR
SHA-256
63a60c48b3370920e96d4c32570d7154d17b3a86654c4f1d1df418be668d3903
MD5
a1ce0d17ef1fc016582a82234cccf2f1
SHA-1
8e48c7d31cf08d8908d692fa8beea865ff2c16ac
First seen (VT)
2/5/2026, 1:30:33 PM
Last analysis (VT)
4/30/2026, 12:50:43 PM
First scan (MalwareTips)
4/30/2026, 9:20:16 PM
Last scan (MalwareTips)
4/30/2026, 9:20:16 PM
Behavior tags
detect-debug-environmentjarsets-process-namechecks-cpu-name
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.