Hello, some minutes ago a friend downloaded forge installer and mccaffe blocked it aswell as norton from another friend. We looked into it and found out there is something not right.
Pls check if our suspicious are right or if it a false positive.
https://www.virustotal.com/gui/file/6d3755e87a4070f370c1e3491188d4f6785743e8d43d3d00be246b594fe8344f/behavior
This is the link to virustotal with the behaviour of the .jar after it gets opened.
And we check the file hosts in system32 and it added some lines.