Safe
Zero malicious detections across 75 engines; 16 tier-1 vendors report clean; Java mod with benign system integration behaviour.
7290e6f3ca1ad9b2e5…26c573245cThe verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The file is a small (9.5 KB) Java JAR archive with embedded HTML/JavaScript, identified as a Minecraft mod variant (Fapcraft). No antivirus engine flags it as malicious; tier-1 vendors unanimously report clean or undetected status. The sandbox behaviour shows Java process execution and system service restart attempts (cups service), which are typical of legitimate installers or mods, not malware command-and-control or persistence mechanisms. The four dropped children are unverdicted but not flagged as malicious. No external intelligence (CIRCL, MalwareBazaar, YARAify) corroborates a threat. The file is unsigned and rare (1 submission), but the absence of detections across such a broad and high-trust engine set strongly indicates benign intent.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
tier1ReportedClean=16 (Avast, BitDefender, Kaspersky, Microsoft, ESET-NOD32, Fortinet, Emsisoft, F-Secure, GData, Avira, AVG, DrWeb) — all major vendors report clean or undetected.
engines.malicious=0/61 reporting; tier1Malicious=0 — zero high-trust detections across 75 total engines.
behaviour.offensiveTechniques=[T1543.002] in context of Java process execution and cups service restart — consistent with legitimate installer/mod, not malware C2.
droppedChildren.hasMaliciousChild=false; all 4 dropped hashes verdict=null — no confirmed malicious payload extraction.
prevalence.classification=rare_new; externalIntel all negative (CIRCL, MalwareBazaar, YARAify) — no researcher corroboration of threat.
- Zero malicious detections across 75 antivirus engines.
- 16 tier-1 vendors (Microsoft, Kaspersky, BitDefender, ESET-NOD32, Fortinet, Emsisoft, F-Secure, GData, Avira, AVG, DrWeb, Avast) report clean or undetected.
- No external intelligence corroboration (CIRCL, MalwareBazaar, YARAify all negative).
- No malicious dropped children; no malicious network contact.
- System process activity consistent with legitimate Java application or mod installer.
This file is safe to use. It is a Minecraft mod with no malicious indicators across our antivirus network. If you obtained it from a trusted source, proceed with confidence.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- /var/log/auth.log.1.gz
- /var/log/dpkg.log.1.gz
- /var/log/kern.log.1.gz
- /var/log/syslog.1.gz
Files this sample writes at runtime
This file drops 4 children at runtime. None are currently flagged malicious in our cache.
- 61625fd8b084f70f242d…55abd2Never scannednever seen before
- 50c82f36208ed8040447…2d7843Never scannednever seen before
- 8e8711854186c68e2368…4a3c7cNever scannednever seen before
- 759aafcfa2395ce1b800…2af0f7Never scannednever seen before
0 detections across 75 engines
How often this file shows up in the wild
Barely seen in the wild and first surfaced recently. This is the footprint of targeted malware the AV industry hasn't signatured yet — extra scrutiny is warranted.
Forensic fingerprint
- File name
- Fapcraft 1.12.2 v1.1.jar
- Size
- 9.3 KB
- MIME type
- (unknown)
- Detected type
- HTML
- SHA-256
- 7290e6f3ca1ad9b2e5200f8821bc2eb866485e55d45cf1e1c6ab4126c573245c
- MD5
- 0796c62894263a1b4ec9c1ff97e8f5b8
- SHA-1
- 928dc46a5b8c2a29796ed450e92640571efe2eaf
- First seen (VT)
- 6/24/2026, 3:42:11 PM
- Last analysis (VT)
- 6/24/2026, 3:42:11 PM
- First scan (MalwareTips)
- 6/24/2026, 3:47:20 PM
- Last scan (MalwareTips)
- 6/24/2026, 3:47:20 PM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.