Is meteor-client-1.21.11-63.jar safe?
No antivirus engine detected this established JAR, and its completed sandbox run produced no malicious verdict despite two behavior-level cautions.
The sample received no detections from 75 antivirus engines, including no tier-1 flags, and it has broad historical prevalence. One sandbox run found no malicious outcome, though two offensive-technique mappings and six children lacking definitive classifications warrant normal source verification.
89cac8433696328841…efa1bcb26f15a3Recommended next actions
Before opening or running
Open or run it only when its publisher and download source have been independently verified.
If you already opened or ran it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The sample received no detections from 75 antivirus engines, including no tier-1 flags, and it has broad historical prevalence. One sandbox run found no malicious outcome, though two offensive-technique mappings and six children lacking definitive classifications warrant normal source verification.
Static scanning produced 0 detections among 75 engines, with 16 tier-1 products reporting no detection. The file is established across 1,588 sources and 1,793 submissions, which weighs against a newly distributed payload. A completed sandbox run did not produce a malicious assessment, and neither curated external intelligence nor inspected domains supplied corroborating threat evidence. T1543.002 and T1562.001 remain cautionary behavioral mappings, but they are not supported by engine detections, persistence indicators, malicious children, or known-bad domain results. Six written children remain unclassified, and reputation coverage for the observed IP is not clearly complete, so the conclusion is strong but not absolute.
What We Detected
The JAR received 0 malicious or suspicious detections from 75 antivirus engines. Sixteen tier-1 engines reported no detection, while external intelligence returned no MalwareBazaar, CIRCL, or YARAify match. The sample is also well established, appearing across 1,588 sources and 1,793 submissions.
Threat Behavior
One completed sandbox run produced no malicious verdict. It mapped activity to T1543.002 and T1562.001, which can be associated with service persistence and impairment of defenses, but no persistence indicators or malicious child files were established. Both listed domains were checked without a malicious or suspicious reputation result; however, complete reputation coverage for the additional observed IP is not documented. All six written children remain unclassified.
What To Do Now
Obtain the JAR from the project's official release channel and verify its SHA-256 hash before running it. Keep endpoint protection enabled, and use an isolated profile or sandbox if the download source cannot be confirmed.
Where this verdict could be wrong4 caveats
- behaviour.offensiveTechniques includes T1543.002 and T1562.001, which can indicate service-related persistence and impairment of defenses, although the completed sandbox did not issue a malicious verdict.
- droppedChildren.rollup reports six unknown child verdicts, so hasMaliciousChild=false does not establish that every written child is benign.
- behaviour.contactedIps lists 162.159.36.2, while contactedHosts.inspected=2 appears to cover only the two domains; complete reputation coverage for every observed contact is therefore unavailable.
- One communityComments entry alleges multiple threat categories, but it has zero votes and conflicts with 0/75 engine detections and the completed sandbox result.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/75 antivirus engines reported a malicious or suspicious detection.
- tier1Malicious=0 with 16 tier-1 engines reporting no detection.
- One completed sandbox produced no malicious verdict.
- The file has 1,588 unique sources and 1,793 submissions.
- No MalwareBazaar, CIRCL, or YARAify hit was found.
- Runtime mappings include T1543.002 and T1562.001.
- Six dropped or written child hashes have unknown verdicts.
- Complete host-reputation coverage for contacted IP 162.159.36.2 is not documented.
- JAR signing is not applicable in this evidence, so publisher identity is not cryptographically established here.
Use a copy obtained from the official project channel and verify SHA-256 89cac84336963288413e3d8394ae1307461a0cca378deaeca5efa1bcb26f15a3. Keep endpoint protection enabled and isolate execution if provenance is uncertain.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial2 of 3 contacted hosts were cross-checked; coverage is incomplete.
YARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 13MITRE ATT&CK techniques
- 15spawned processes
- 3network contacts
- 15filesystem & mutex artifacts
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- svc.ha-teams.office.com
- svc.ms-acdc-teams.office.com
- 162.159.36.2
- C:\Users\<USER>\AppData\Local\Temp\hsperfdata_<USER>\6896
- C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestamp
- C:\ProgramData\Oracle\Java\.oracle_jre_usage\17dfc292991c8786.timestamp
- C:\Users\user\AppData\Local\Temp\hsperfdata_user
- C:\Users\user\AppData\Local\Temp\hsperfdata_user\592
- C:\Users\user\AppData\Local\Temp\hsperfdata_user\6920
Files this sample writes at runtime
This file drops 6 children at runtime. None are currently flagged malicious in our cache.
- 3047d36f89b63b469053…7c2787Never scannednever seen before
- 7a94a908d352d1f35105…d85f3fNever scannednever seen before
- d87c5f3cdfb5b7c0510e…1ade9eNever scannednever seen before
- 91a1db19eda207805311…b1571eNever scannednever seen before
- fd9eff45f85e23bc37b1…f6a9c8Never scannednever seen before
- 44a3bab2c338e3bca24c…d3b9e7Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 0 / 75engines flagged
- 1,588sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 75 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has a long, established submission history across 1,588 sources.
Verdict inputView chapterProvenanceDerivedSourceSubmission historyObserved at - 03
The hash has been submitted 1,793 times from 1,588 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: meteor-client-1.21.11-63.jar — 89cac84336963288413e3d8394ae1307461a0cca378deaeca5efa1bcb26f15a3
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Program Files\Java\jre-1.8\bin\java.exe" -jar "C:\Users\<USER>\Desktop\runtime.jar"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: 6896 — C:\Users\<USER>\AppData\Local\Temp\hsperfdata_<USER>\6896
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: 3903daac9bc4a3b7.timestamp — C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestamp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: svc.ha-teams.office.com — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: svc.ms-acdc-teams.office.com — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
0 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- meteor-client-1.21.11-63.jar
- Format
- JAR
- Code signing
- Not applicable to this file type
- Size
- 4.6 MB
- Last analyzed
- Sep 29, 2026, 9:22 AM UTC
89cac84336963288413e3d8394ae1307461a0cca378deaeca5efa1bcb26f15a3Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Open or run it only when its publisher and download source have been independently verified.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is meteor-client-1.21.11-63.jar safe?
What is meteor-client-1.21.11-63.jar?
How many antivirus engines detected meteor-client-1.21.11-63.jar?
What is the SHA-256 hash of meteor-client-1.21.11-63.jar?
Is it safe to open or run meteor-client-1.21.11-63.jar?
How up to date is this analysis of meteor-client-1.21.11-63.jar?
Community
Member reviews and reports for this exact file hash.