Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Razr

167
Global rank
174 infographic chevron month
Month rank
164
Week rank
0
IOCs

Razr is a destructive ransomware that infiltrates systems to encrypt files, rendering them inaccessible to users. It appends the ".razr" extension to the encrypted files and drops a ransom note, typically named "README.txt," instructing victims on how to pay the ransom to obtain the decryption key. The malware often spreads through phishing emails with malicious attachments or by exploiting vulnerabilities in software and operating systems. Razr employs strong encryption algorithms, making it challenging to decrypt files without the attackers' key.

Ransomware
Type
Unknown
Origin
1 August, 2024
First seen
19 June, 2026
Last seen

How to analyze Razr with ANY.RUN

Type
Unknown
Origin
1 August, 2024
First seen
19 June, 2026
Last seen

IOCs

IP addresses
142.251.110.97
163.171.242.128
8.8.8.8
20.157.18.26
150.171.109.100
23.48.23.156
48.209.138.189
95.101.9.205
163.171.242.126
142.251.20.95
52.123.243.76
20.190.160.20
23.11.40.157
23.216.77.61
142.251.13.155
23.48.23.145
142.251.13.138
150.171.28.11
47.236.88.244
2.23.227.215
Hashes
5e9a7996fe94d7be10595d7133748760bf8348198b71b7a50fd8affaa980ac61
e0acaced3f5686390c4c2ed8d3b447c725660252d1a20a71fdab5110a435c463
fa72d60328d27b0890f46243843f563847b9d0baa162d0a771b4376d69ea231d
6028bd681dbf11a0a58dde8a0cd884115c04caa59d080ba51bde1b086ce0079d
9c70f766d3b84fc2bb298efa37cc9191f28bec336329cc11468cfadbc3b137f4
f7b24f2eb3d5eb0550527490395d2f61c3d2fe74bb9cb345197dad81b58b5fed
fbcfe23a2ecb82b7100c50811691dde0a33aa3da8d176be9882a9db485dc0f2d
0f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
359b1c4b99bcaf83ccefe6935c1e58d03e1780c81b1784d44f301f531e4d0860
f9e4da319fe1f5a7d497c452421f4648a24ec7588f309ebea0f0cd61a6251eef
5f734b84215c50d8493a0f8bc5abd56307dff02c8be2d15fe082707d490a119e
362ce33aa715a7ba30cb6670f4f052b38ab8f329c7f09b07918b1000a5e62cd1
85b2167f5850412940625c80c1a0fbabce43a5e34afa22005cd0bb7d154b7a0d
1d075239a73d2ad0c930452b06b94d76158f18e2ce7586bdeb7db37d0f9e75f1
6ed76614f5e413c4b87ac6c4f98bfbca85c5a0d0caaffe5cb1d89ad1e05ecd13
df16916420f19b575159f99a513cf352edbd62f9c7c82d84513ae4163f0e1a1f
c2deceb5b4f379eb05eb4bb1c66d728a74d9744cb80a38c01bf6c86b3c3a2e51
fdc37d258fb80b7fac0f54776d18039db8edbbedc66b1f4f8cbc1e6f01a075ad
523fec7efccf69a09adc271d0a086454d821467ac3e949481334c9b15c3f2b54
d49982e7a5949f4e0e0c87547589704e16a02315258488dc5222d90775882761
Domains
www.msftconnecttest.com
nexusrules.officeapps.live.com
ocsp.digicert.com
slscr.update.microsoft.com
client.wns.windows.com
self.events.data.microsoft.com
oneocsp.microsoft.com
settings-win.data.microsoft.com
fe3cr.delivery.mp.microsoft.com
www.microsoft.com
activation-v2.sls.microsoft.com
google.com
crl.microsoft.com
www.bing.com
login.live.com
ad.doubleclick.net
cdn.btloader.com
script-api.ccgateway.net
www.google-analytics.com
cdn.api.btloader.com
URLs
http://www.msftconnecttest.com/connecttest.txt
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a6c557ad0c3e27c4
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:wscgznaq-iki7rcdesth6d_b0iumm3nlg4gfhhlkudw&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.26100&devicefamily=server&installdate=1761899409&clientversion=141.0.3537.99&experimentationmode=1&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://www.bing.com/bloomfilterfiles/expandeddomainsfilterglobal.json
https://config.edge.skype.com/config/v1/edge/141.0.3537.99?clientid=-8107584157342487295&agents=edgeconfig%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&osarch=x86_64&osver=10.0.26100&wu=1&devicefamily=server&soobedate=1761899407&uma=1&sessionid=9&mngd=1&installdate=1761899409&edu=0&vm=0&bphint=0&fg=1&lbfgdate=1762963124&lafgdate=0&aad=1&ad=2&cm=0
https://www.mi.com/global
https://slscr.update.microsoft.com/sls/%7b8b24b027-1dee-babb-9a95-3517dfb9c552%7d/x64/10.0.26100.6905/0?ch=833&l=en-us&p=&pt=0x7&wua=1450.2508.27012.0&mk=qemu&md=standard+pc+(q35+%2b+ich9%2c+2009)
https://config.edge.skype.com/config/v1/edge/141.0.3537.99?clientid=-8107584157342487295&agents=edgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&osarch=x86_64&osver=10.0.26100&wu=1&devicefamily=server&soobedate=1761899407&uma=1&sessionid=9&mngd=1&installdate=1761899409&edu=0&vm=0&bphint=0&fg=1&lbfgdate=1781834775&lafgdate=0&aad=1&ad=2&cm=0
https://www.mi.com/sgp/spps_files/store/0.55.109/css/global/index.css
https://www.mi.com/sgp/spps_files/store/0.55.109/css/editable.chunk.css
https://www.mi.com/sgp/spps_files/store/0.55.109/css/57477.chunk.css
https://www.mi.com/sgp/spps_files/store/0.55.109/css/carousel-banner.chunk.css
https://www.mi.com/sgp/spps_files/store/0.55.109/css/explore-xiaomi.chunk.css
https://www.mi.com/sgp/spps_files/store/0.55.109/css/featured-tabs.chunk.css
https://www.mi.com/sgp/spps_files/store/0.55.109/css/support-web-home.chunk.css
https://www.mi.com/sgp/spps_files/store/0.55.109/js/64807.chunk.js
https://www.mi.com/sgp/spps_files/store/0.55.109/js/45375.chunk.js
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2227
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 6651
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10099
comments 0

What is Razr ransomware?

Razr ransomware is a recent and sophisticated strain of ransomware that surfaced in 2024, targeting systems by encrypting essential files and demanding ransom payments from victims.

The malware has made headlines due to its unique use of cloud-based platforms, like PythonAnywhere, as part of its distribution strategy, leveraging these services to host malicious files and bypass security defenses.

Known for appending the ".raz" extension to locked files, Razr delivers a ransom note typically titled “README.txt” with instructions for payment.

Razr ransom note in ANY.RUN sandbox Ransom note displayed inside ANY.RUN sandbox

This behavior and ransom note can be easily seen inside ANY.RUN’s interactive sandbox following analysis session: View analysis session

Razr’s rapid spread and its use of AES-256 encryption make it difficult for victims to regain access without paying the ransom, placing it among the newer threats that exploit trusted platforms for distribution.

Razr ransomware technical details

The primary functionality of Razr is to exfiltrate sensitive data from infected systems. Its key features include:

  • Uses AES-256 encryption to securely lock files on the infected system.
  • Collects and transmits sensitive data from the infected device to a command-and-control (C2) server, giving attackers access to valuable information.
  • Employs various techniques to conceal its code and activities, including hiding in legitimate processes and encoding its payloads.
  • Maintains communication with a remote C2 server, allowing attackers to manage the malware, send commands, and retrieve exfiltrated data remotely.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Razr ransomware execution process

To see how Razr ransomware operates, let’s upload its sample to the ANY.RUN sandbox.

Razr ransomware typically gains access to systems through several attack vectors. Common methods include malicious email attachments or links that trick users into executing the ransomware, as well as attackers exploiting known software or operating system vulnerabilities to infiltrate networks. In some cases, compromised credentials enable attackers to access systems directly. Once inside, the ransomware establishes a foothold on the infected system.

After gaining access, Razr executes its payload by dropping and running a malicious binary that initiates the encryption process. It scans the system for valuable files, including documents, images, and databases, prioritizing those critical for operations. Razr may also exploit vulnerabilities to spread across the network, targeting other connected devices and servers.

Razr graph in ANY.RUN sandbox Process graph of Razr ransomware inside ANY.RUN sandbox

Razr's core functionality is file encryption, using the AES-256 algorithm in CBC mode. The ransomware is engineered to avoid encrypting system-critical files to ensure the operating system remains functional, thereby prolonging the attack’s effectiveness.

Once encryption is complete, Razr presents its ransom demand. Typically, it changes the desktop background or creates text files in each encrypted directory with instructions for paying the ransom.

Razr sandbox in ANY.RUN sandbox Ransom note displayed inside sandbox

The ransom is generally requested in cryptocurrency, which makes transactions difficult to trace. Victims are often given a limited time frame, such as 24 to 48 hours, to pay before facing permanent data loss.

Some ransomware variants also threaten to leak sensitive data if the ransom is unpaid, increasing pressure on victims to comply. Without backups—or if backups are also encrypted—victims face significant challenges in recovering their data without paying the ransom.

Razr ransomware distribution methods

Razr ransomware employs several distribution methods to infiltrate target systems:

  • Phishing emails with malicious attachments or links: Attackers send emails containing harmful attachments or links that, when opened, download the Razr payload.
  • Exploitation of Cloud platforms: Razr has been observed leveraging legitimate cloud services, such as PythonAnywhere, to host and distribute its malicious files, thereby evading detection by security systems.
  • Drive-by downloads: Users visiting compromised or malicious websites may inadvertently download and execute the Razr ransomware without any direct interaction.

Gathering Threat Intelligence on Razr Ransomware

To gather the latest intelligence on Razr ransomware, use the Threat Intelligence Lookup feature in ANY.RUN.

This service provides access to a comprehensive database with insights from millions of malware analysis sessions conducted in the ANY.RUN sandbox. With over 40 customizable search filters, users can locate data on threats like IPs, domains, file names, and process artifacts tied to Razr.

Razr TI Lookup results in ANY.RUN sandbox Search results for Razr in Threat Intelligence Lookup

For instance, to collect information on Razr, you can search for its threat name or a related artifact. Entering a query such as threatName:"Razr" AND domainName:"" will generate a list of files, events, domain names, and other data extracted from Lumma samples along with sandbox sessions that you can explore in detail to gain comprehensive insights into this malware’s behavior.

Try a 14-day free trial of Threat Intelligence Lookup with the ANY.RUN sandbox for hands-on intelligence gathering.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Razr ransomware is dangerous due to its strong encryption, cloud-based delivery, and ability to evade detection. Using tools like ANY.RUN is essential for proactively analyzing suspicious files and URLs, enabling early detection.

ANY.RUN offers real-time threat analysis in a sandboxed environment, providing insights into malware behavior visual tracking and other advanced features.

Sign up for a free ANY.RUN account today and start analyzing emerging threats with no limits!

HAVE A LOOK AT

Tycoon 2FA screenshot
Tycoon 2FA
tycoon
Tycoon 2FA is a phishing-as-a-service (PhaaS) platform designed to bypass multi-factor authentication (MFA) protections, particularly targeting Microsoft 365 and Gmail accounts. Its advanced evasion techniques and modular architecture make it a significant threat to organizations relying on MFA for security.
Read More
CastleLoader screenshot
CastleLoader
castleloader
CastleLoader is a modern malware loader designed to quietly establish initial access and deliver follow-up payloads such as stealers, RATs, and ransomware. It focuses on stealth, flexibility, and rapid payload rotation, making it an effective tool for financially motivated threat actors and a persistent problem for enterprise defenders.
Read More
BTMOB RAT screenshot
BTMOB RAT
btmob
BTMOB RAT is a remote access Trojan (RAT) designed to give attackers full control over infected devices. It targets Windows and Android endpoints. Its modular structure allows operators to tailor capabilities, making it suitable for espionage, credential theft, financial fraud, and establishing long-term footholds in corporate networks.
Read More
Latrodectus screenshot
Latrodectus
latrodectus
Latrodectus is a malicious loader that is used by threat actors to gain a foothold on compromised devices and deploy additional malware. It has been associated with the IcedID trojan and has been used by APT groups in targeted attacks. The malware can gather system information, launch executables, and detect sandbox environments. It uses encryption and obfuscation to evade detection and can establish persistence on the infected device.
Read More
Greatness screenshot
Greatness is a Phishing-as-a-Service (PhaaS) platform that enables cybercriminals, even those with limited technical skills, to launch sophisticated phishing attacks primarily targeting Microsoft 365 (M365) credentials. It acts as a man-in-the-middle (MitM) proxy, facilitating credential theft and MFA bypass while providing affiliates with easy-to-use tools like attachment builders and Telegram notifications.
Read More
VanHelsing Ransomware screenshot
VanHelsing is a sophisticated ransomware strain that appeared in early 2025, operating via the Ransomware-as-a-Service (RaaS) model and targeting primarily USA and France. It threatens mostly Windows systems but has variants for Linux, BSD, ARM, and ESXi, making it a multi-platform malware. It is also notable for its advanced evasion techniques, double extortion tactics, and rapid evolution.
Read More