Is catlean_1.21.11.jar safe?
Unsigned Java application with zero malicious engine detections, medium prevalence, and benign runtime behaviour consistent with legitimate Java lifecycle management.
This JAR file shows no malicious detections across 65 antivirus engines, including 16 tier-1 vendors (Kaspersky, BitDefender, Microsoft, ESET-NOD32, Fortinet, F-Secure, Emsisoft, Avira, DrWeb, GData, AVG, Avast). Runtime behaviour exhibits anti-analysis and process-management techniques typical of Java applications managing their own lifecycle. Medium prevalence (3,325 submitters, 5,429 submissions) and community researcher consensus ('Clean') reinforce the benign classification.
d15e0afafc2ecbbc38…33fadaeb003f4cRecommended next actions
Before opening or running
Open or run it only when its publisher and download source have been independently verified.
If you already opened or ran it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
This JAR file shows no malicious detections across 65 antivirus engines, including 16 tier-1 vendors (Kaspersky, BitDefender, Microsoft, ESET-NOD32, Fortinet, F-Secure, Emsisoft, Avira, DrWeb, GData, AVG, Avast). Runtime behaviour exhibits anti-analysis and process-management techniques typical of Java applications managing their own lifecycle. Medium prevalence (3,325 submitters, 5,429 submissions) and community researcher consensus ('Clean') reinforce the benign classification.
The evidence converges strongly on a benign Java application. Zero malicious detections from 65 engines, with 16 tier-1 vendors reporting clean, establishes a robust consensus. The offensive MITRE techniques (T1543.002, T1562.001) are paired with 8 ambient techniques (scripting, system discovery, execution, logging suppression) that are routine in Java runtime management, not indicative of malware command-and-control or data exfiltration. The file's medium prevalence across 3,325 submitters over 118 days indicates established, distributed use. No external intelligence (CIRCL, YARAify, MalwareBazaar) flagged the sample. Dropped children (6 inspected, 0 malicious) and contacted hosts (none in malicious cache) show no secondary malicious activity. The unsigned status is unremarkable for Java applications. Community researcher annotation explicitly states 'Clean' with score 0/100, aligning with the engine consensus.
What We Detected
A Java application (catlean_1.21.11.jar, 11.1 MB) submitted 118 days ago with medium prevalence (3,325 unique submitters, 5,429 total submissions). Zero malicious detections across 65 antivirus engines, including 16 tier-1 vendors (Kaspersky, BitDefender, Microsoft, ESET-NOD32, Fortinet, F-Secure, Emsisoft, Avira, DrWeb, GData, AVG, Avast). File is unsigned and contains version metadata (1.21.11).
Threat Behavior
Sandbox analysis identified 10 MITRE techniques: 2 classified as offensive (T1543.002 'Create or Modify System Process', T1562.001 'Disable or Modify Tools') and 8 ambient (T1064 scripting, T1082 system info discovery, T1106 execution, T1202 indirect command execution, T1518.001 software discovery, T1564 hide artifacts, T1564.001 hidden files, T1564.003 hidden window). These techniques are consistent with Java runtime process lifecycle management and logging suppression — common in legitimate Java applications. Six dropped child files were inspected; none were verdicted malicious. No contacted hosts matched our malicious cache. No external intelligence (CIRCL, YARAify, MalwareBazaar) corroborated malicious activity.
What To Do Now
No action required. The file exhibits clean engine consensus, benign runtime behaviour, and established prevalence. If you encounter this file in your environment, it is safe to allow execution. Monitor for any unusual network activity or process spawning, but the current evidence does not indicate malicious intent.
Where this verdict could be wrong3 caveats
- The file exhibits anti-analysis tags (detect-debug-environment, checks-cpu-name) and uses process-name manipulation (T1543.002) and tool-disabling (T1562.001), which could indicate evasion intent. However, these techniques are routine in Java applications that need to manage their own process lifecycle and suppress verbose logging in production environments.
- Six dropped children remain unanalysed (verdict=null). If any of these children were later verdicted malicious, the parent's safety assessment could shift. Current data shows 0 malicious children, but incomplete analysis of dropped files introduces residual uncertainty.
- The file is unsigned, which removes cryptographic assurance of origin. However, unsigned JAR files are common in open-source and internal Java projects, and the absence of a signature is not evidence of malice when paired with clean engine consensus and medium prevalence.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- Zero malicious detections across 65 engines; 16 tier-1 vendors (Kaspersky, BitDefender, Microsoft, ESET-NOD32, Fortinet, F-Secure, Emsisoft, Avira, DrWeb, GData, AVG, Avast) all undetected
- Medium prevalence: 3,325 unique submitters, 5,429 submissions over 118 days — established distribution history
- Dropped children: 6 inspected, 0 malicious; contacted hosts: none in malicious cache
- Community researcher annotation: 'Verdict: Clean Score: 0/100'
- Runtime behaviour consistent with Java lifecycle management (process creation, logging suppression) — not C2 or exfiltration patterns
This file is safe to use. The zero-malicious consensus from 65 engines, including 16 tier-1 vendors, combined with medium prevalence and benign runtime behaviour, confirms a legitimate Java application. No further analysis or quarantine is necessary.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
CompleteRule evaluation completed with no recorded matches.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 10MITRE ATT&CK techniques
- 11spawned processes
- 0network contacts
- 13filesystem & mutex artifacts
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- C:\Users\<USER>\AppData\Local\Temp\hsperfdata_<USER>\3612
- C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestamp
- C:\ProgramData\Oracle\Java\.oracle_jre_usage\17dfc292991c8786.timestamp
- C:\Users\user\AppData\Local\Temp\hsperfdata_user
- C:\Users\user\AppData\Local\Temp\hsperfdata_user\6488
- C:\Users\user\AppData\Local\Temp\hsperfdata_user\6916
- /tmp/hsperfdata_root/4981
Files this sample writes at runtime
This file drops 6 children at runtime. None are currently flagged malicious in our cache.
- 5e76fed3307ad1abcb78…f40a42Never scannednever seen before
- 5cbba3e6adaa6f7e78f6…78036eNever scannednever seen before
- c1de3a9376fdaef0ba6a…308b70Never scannednever seen before
- d87c5f3cdfb5b7c0510e…1ade9eNever scannednever seen before
- 44a3bab2c338e3bca24c…d3b9e7Never scannednever seen before
- ac941ead01d5451a7a9f…253227Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 0rule hits recorded
- 0 / 74engines flagged
- 3,325sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 74 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 5,429 times from 3,325 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 03
Scanned file: catlean_1.21.11.jar — d15e0afafc2ecbbc3883d3a1369542c16dfc3ed395e13e9de233fadaeb003f4c
ProvenanceObservedSourceUploaded fileObserved at - 04
Observed process — "C:\Program Files\Java\jre-1.8\bin\java.exe" -jar "C:\Users\<USER>\Desktop\runtime.jar"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 05
Observed process — C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
File written: 3612 — C:\Users\<USER>\AppData\Local\Temp\hsperfdata_<USER>\3612
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: 3903daac9bc4a3b7.timestamp — C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestamp
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
YARA rules
No matchesThe rule pass completed without a saved public match.
0 of 74 engines flagged this file
View all 74 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- catlean_1.21.11.jar
- Format
- JAR
- Code signing
- Not applicable to this file type
- Size
- 10.6 MB
- Last analyzed
- Jun 30, 2026, 7:46 PM UTC
d15e0afafc2ecbbc3883d3a1369542c16dfc3ed395e13e9de233fadaeb003f4cSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Open or run it only when its publisher and download source have been independently verified.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is catlean_1.21.11.jar safe?
What is catlean_1.21.11.jar?
How many antivirus engines detected catlean_1.21.11.jar?
What is the SHA-256 hash of catlean_1.21.11.jar?
Is it safe to open or run catlean_1.21.11.jar?
How up to date is this analysis of catlean_1.21.11.jar?
Community
Member reviews and reports for this exact file hash.