Is meteor-plus-1.21.11_1.0.9.5.jar safe?
No antivirus engine identified malware, but one sandbox mapped three offensive techniques and left five dropped files without conclusive child verdicts.
All 75 antivirus engines avoided flagging this JAR, including the tier-1 engines that completed analysis, and no curated threat-intelligence source matched it. However, one sandbox mapped process injection, service persistence, and defense impairment, while five dropped files remain unclassified, so execution should be limited to an isolated environment.
fdea11019467b08de6…8c2123cd0d1ff1Recommended next actions
Before opening or running
Do not open or run it until the source and publisher can be verified independently.
If you already opened or ran it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the publisher's official site and verify its exact hash when possible.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 75 antivirus engines avoided flagging this JAR, including the tier-1 engines that completed analysis, and no curated threat-intelligence source matched it. However, one sandbox mapped process injection, service persistence, and defense impairment, while five dropped files remain unclassified, so execution should be limited to an isolated environment.
The strongest reassuring evidence is that 0 of 75 engines reported a detection, with 12 tier-1 engines explicitly returning no detection. Curated intelligence checks also produced no known-malware or YARA matches. One completed sandbox nevertheless mapped T1055, T1543.002, and T1562.001, although it did not issue a malicious sandbox verdict or record persistence indicators. The five inspected child hashes were not identified as malicious, but all remain unclassified and therefore cannot be treated as benign. No complete contacted-host reputation result is available, though that sandbox recorded no network contacts.
What We Detected
None of 75 antivirus engines flagged the JAR, and 12 tier-1 engines completed analysis without a detection. CIRCL, MalwareBazaar, and YARAify supplied no matching threat intelligence or rules.
Threat Behavior
One completed sandbox mapped activity to T1055 (Process Injection), T1543.002 (Systemd Service), and T1562.001 (Impair Defenses). These mappings are concerning, but the sandbox did not produce a malicious verdict, record persistence indicators, or observe network contacts. Five dropped files were inspected without a malicious result, although each child remains unclassified. A complete contacted-host reputation cross-check was not available.
What To Do Now
Verify the JAR against the developer's official release hash and source before running it. If validation is unavailable, test it only in an isolated virtual machine while keeping endpoint protection enabled, and monitor child processes, file creation, service changes, and defense-related activity.
Where this verdict could be wrong4 caveats
- The MalwareTips.Synth.ProcessInjection heuristic fired from the T1055 mapping; the stored evidence does not establish the injection method or intent.
- T1543.002 and T1562.001 are offensive-use mappings that merit caution despite the absence of an explicit malicious sandbox verdict.
- All 5 inspected dropped children have unknown verdicts, so droppedChildren.hasMaliciousChild=false is not equivalent to proving those files benign.
- contactedHosts=null leaves host-reputation coverage unavailable, although the completed sandbox recorded no contacted domains, IPs, or URLs.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0 of 75 antivirus engines reported a detection
- 12 tier-1 engines completed analysis without detecting malware
- No malicious sandbox verdict was recorded
- No malicious dropped child was identified
- CIRCL, MalwareBazaar, and YARAify returned no threat matches
- Sandbox mapping to T1055 process injection
- Sandbox mapping to T1543.002 service persistence
- Sandbox mapping to T1562.001 defense impairment
- Five dropped child hashes remain unclassified
- No applicable publisher-signing assurance for this JAR
- Complete contacted-host reputation coverage is unavailable
Confirm the SHA-256 with the project's official distribution before use. Otherwise, run it only in an isolated environment with endpoint protection enabled and investigate any service changes, process injection, or security-control interference.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
Complete1 signature or behavior rule matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 15MITRE ATT&CK techniques
- 11spawned processes
- 0network contacts
- 11filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Created or modified a system service, which can keep code running.
High concern: Attempted to impair or bypass security controls.
Moderate concern: Runs hidden system commands (script or shell).
Moderate concern: Transferred a file over the network; malware can use this to fetch additional payloads.
Moderate concern: Checks which security software you have installed.
Note: Collects details about your system.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
meteor-plus-1.21.11_1.0.9.5.jar
fdea11019467b08de6830b9da71f91585aff792f616d0465508c2123cd0d1ff1
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Program Files\Java\jre-1.8\bin\javaw.exe" -jar "C:\Users\<USER>\Desktop\sample.jar"
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
4132
C:\Users\<USER>\AppData\Local\Temp\hsperfdata_<USER>\4132
04Isolated runtime analysis - Written fileObserved
3903daac9bc4a3b7.timestamp
C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestamp
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
5 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- C:\Users\<USER>\AppData\Local\Temp\hsperfdata_<USER>\4132
- C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestamp
- C:\ProgramData\Oracle\Java\.oracle_jre_usage\17dfc292991c8786.timestamp
- C:\Users\user\AppData\Local\Temp\hsperfdata_user
- C:\Users\user\AppData\Local\Temp\hsperfdata_user\1528
- C:\Users\user\AppData\Local\Temp\hsperfdata_user\3800
- /tmp/hsperfdata_root/3544
Files this sample writes at runtime
This file drops 5 children at runtime. None are currently flagged malicious in our cache.
- d701ff006c0e73cf1bf4…fb451aNever scannednever seen before
- d18d3d4f8aad9a564a5d…beee2fNever scannednever seen before
- 901beca1ff86cd9380ff…694069Never scannednever seen before
- b468bf508c1b034631c5…457d6eNever scannednever seen before
- d87c5f3cdfb5b7c0510e…1ade9eNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 1rule hit recorded
- 0 / 75engines flagged
- 65sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
0 of 75 antivirus engines flagged the file.
ProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has been submitted 79 times from 65 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: meteor-plus-1.21.11_1.0.9.5.jar — fdea11019467b08de6830b9da71f91585aff792f616d0465508c2123cd0d1ff1
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Program Files\Java\jre-1.8\bin\javaw.exe" -jar "C:\Users\<USER>\Desktop\sample.jar"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: 4132 — C:\Users\<USER>\AppData\Local\Temp\hsperfdata_<USER>\4132
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: 3903daac9bc4a3b7.timestamp — C:\ProgramData\Oracle\Java\.oracle_jre_usage\3903daac9bc4a3b7.timestamp
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
Evidence"C:\Program Files\Java\jre-1.8\bin\javaw.exe" -jar "C:\Users\<USER>\Desktop\sample.jar"
0 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- meteor-plus-1.21.11_1.0.9.5.jar
- Format
- JAR
- Code signing
- Not applicable to this file type
- Size
- 584.7 KB
- Last analyzed
- Sep 8, 2026, 3:55 PM UTC
fdea11019467b08de6830b9da71f91585aff792f616d0465508c2123cd0d1ff1Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't open or run it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this Java file and use a fresh copy from a trusted source. Get a fresh copy from the publisher's official site and verify its exact hash when possible.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is meteor-plus-1.21.11_1.0.9.5.jar safe, or is it malware?
What is meteor-plus-1.21.11_1.0.9.5.jar?
How many antivirus engines detected meteor-plus-1.21.11_1.0.9.5.jar?
I already downloaded and opened or ran meteor-plus-1.21.11_1.0.9.5.jar — what should I do?
How do I remove meteor-plus-1.21.11_1.0.9.5.jar?
What is the SHA-256 hash of meteor-plus-1.21.11_1.0.9.5.jar?
How up to date is this analysis of meteor-plus-1.21.11_1.0.9.5.jar?
Community
Member reviews and reports for this exact file hash.