Safe
Widely-distributed Minecraft Forge modding JAR with zero tier-1 detections, common prevalence, and benign sandbox behaviour.
ee9fcb4977064a6ebf…74ec12a709The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The evidence strongly supports a benign classification. Zero malicious detections across 64 reporting engines, with 16 tier-1 engines (Avast, BitDefender, Kaspersky, Microsoft, ESET-NOD32, Fortinet, F-Secure, Emsisoft, Avira, AVG, DrWeb, GData) all reporting the file clean. The file's prevalence is common_old with nearly 47,000 submissions over three years, indicating it is a well-known, widely-distributed legitimate application. Sandbox analysis shows benign behaviour: no malicious verdicts, no malicious dropped children (0/10), and no contacted hosts in our malicious cache. The DirectIpC2 heuristic, while flagged as medium severity, is a feature rather than a verdict; Java modding frameworks routinely use direct IPs for resource delivery and updates. Community analysis from FileScan.IO independently confirms NO_THREAT status with 100% confidence. The filename is consistent with Minecraft Forge 1.12.2, a legitimate open-source modding framework.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines: 0/64 malicious; tier1Malicious=0; tier1ReportedClean=16 (Avast, BitDefender, Kaspersky, Microsoft, ESET-NOD32, Fortinet, F-Secure, Emsisoft, Avira, AVG, DrWeb, GData all undetected)
prevalence.classification=common_old; 3694 unique submitters, 46,455 submissions since 2023-04-14 — widely distributed legitimate file
behaviour: 2 offensive MITRE (T1543.002, T1562.001) + 18 ambient; hasMaliciousSandboxVerdict=false; droppedChildren.hasMaliciousChild=false; contactedHosts.maliciousHosts=none
triggeredHeuristics: MalwareTips.Synth.DirectIpC2 fired (medium) on direct-IP contact, but no malicious sandbox verdict or malicious host cache hits contradict C2 hypothesis
communityComments: FileScan.IO NO_THREAT (100% confidence, 2 independent reports); filename consistent with Minecraft Forge 1.12.2 modding framework
- 16 tier-1 antivirus engines report clean (Avast, BitDefender, Kaspersky, Microsoft, ESET-NOD32, Fortinet, F-Secure, Emsisoft, Avira, AVG, DrWeb, GData)
- common_old prevalence: 46,455 submissions from 3,694 sources since 2023-04-14
- Zero malicious sandbox verdicts; zero malicious dropped children (0/10)
- Zero contacted hosts in malicious cache
- FileScan.IO independent NO_THREAT verdicts (100% confidence, 2 reports)
This file is safe. It is a well-known, widely-distributed Minecraft Forge modding framework with zero tier-1 detections and benign sandbox behaviour. No action is required unless you have specific concerns about the source from which you obtained it.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 23.195.81.59
- 150.171.22.17
- C:\Users\<USER>\AppData\Local\Temp\hsperfdata_<USER>\6564
- C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestamp
- C:\ProgramData\Oracle
- C:\ProgramData\Oracle\Java
- C:\ProgramData\Oracle\Java\.oracle_jre_usage
- C:\Users\user\AppData\Local\Temp\hsperfdata_user\5036
- C:\Users\user\AppData\Local\Temp\hsperfdata_user\6892
- C:\Users\user\AppData\Local\Temp\hsperfdata_user\7024
- C:\Users\user\AppData\Local\Temp\hsperfdata_user\6584
- C:\Users\user\AppData\Local\Temp\hsperfdata_user\6912
- \Sessions\1\BaseNamedObjects\Local\SessionImmersiveColorMutex
- \BaseNamedObjects\Local\SM0:4168:304:WilStaging_02
- \BaseNamedObjects\Local\SM0:4168:120:WilError_03
- \BaseNamedObjects\Local\ZonesCacheCounterMutex
- \BaseNamedObjects\Local\ZonesLockedCacheCounterMutex
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- 53c4ef1169aa6eeb87c9…858ed1Never scannednever seen before
- f3dbcc8b5add836d8bdf…f557a8Never scannednever seen before
- 9f350a76d634ac04fb2b…b7372aNever scannednever seen before
- 1df029c587de27803b8e…1093a0Never scannednever seen before
- 3f8096f14540c8e18e4e…ad10b8Never scannednever seen before
- de1de8cef3fc585338a3…029bfbNever scannednever seen before
- b468bf508c1b034631c5…457d6eNever scannednever seen before
- 0b74f23a8a59c66aa653…5654a7Never scannednever seen before
- c1de3a9376fdaef0ba6a…308b70Never scannednever seen before
- 70323fd1a61586d53c5d…46244aNever scannednever seen before
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 2 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence23.195.81.59 · 150.171.22.17
0 detections across 75 engines
How often this file shows up in the wild
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Forensic fingerprint
- File name
- Bia-Girl-Mod-Forge-1.12.2.jar
- Size
- 42.57 MB
- MIME type
- (unknown)
- Detected type
- JAR
- SHA-256
- ee9fcb4977064a6ebfadb81b1e33e806c96c6256e7f49a474f91d974ec12a709
- MD5
- 9055ee21e25c501d68d16cca6f15d482
- SHA-1
- 5c310dac45d3a6039a9e182f948f1569af4683e2
- First seen (VT)
- 4/13/2023, 9:40:50 PM
- Last analysis (VT)
- 6/27/2026, 4:53:20 PM
- First scan (MalwareTips)
- 6/27/2026, 11:58:50 PM
- Last scan (MalwareTips)
- 6/27/2026, 11:58:50 PM
- Community reputation
- +13trusted
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.