Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Razr

174
Global rank
181 infographic chevron month
Month rank
168 infographic chevron week
Week rank
0
IOCs

Razr is a destructive ransomware that infiltrates systems to encrypt files, rendering them inaccessible to users. It appends the ".razr" extension to the encrypted files and drops a ransom note, typically named "README.txt," instructing victims on how to pay the ransom to obtain the decryption key. The malware often spreads through phishing emails with malicious attachments or by exploiting vulnerabilities in software and operating systems. Razr employs strong encryption algorithms, making it challenging to decrypt files without the attackers' key.

Ransomware
Type
Unknown
Origin
1 August, 2024
First seen
19 June, 2026
Last seen

How to analyze Razr with ANY.RUN

Type
Unknown
Origin
1 August, 2024
First seen
19 June, 2026
Last seen

IOCs

IP addresses
142.251.110.97
163.171.242.128
8.8.8.8
20.157.18.26
150.171.109.100
23.48.23.156
48.209.138.189
95.101.9.205
163.171.242.126
142.251.20.95
52.123.243.76
20.190.160.20
23.11.40.157
23.216.77.61
142.251.13.155
23.48.23.145
142.251.13.138
150.171.28.11
47.236.88.244
2.23.227.215
Hashes
5e9a7996fe94d7be10595d7133748760bf8348198b71b7a50fd8affaa980ac61
e0acaced3f5686390c4c2ed8d3b447c725660252d1a20a71fdab5110a435c463
fa72d60328d27b0890f46243843f563847b9d0baa162d0a771b4376d69ea231d
6028bd681dbf11a0a58dde8a0cd884115c04caa59d080ba51bde1b086ce0079d
9c70f766d3b84fc2bb298efa37cc9191f28bec336329cc11468cfadbc3b137f4
f7b24f2eb3d5eb0550527490395d2f61c3d2fe74bb9cb345197dad81b58b5fed
fbcfe23a2ecb82b7100c50811691dde0a33aa3da8d176be9882a9db485dc0f2d
0f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
359b1c4b99bcaf83ccefe6935c1e58d03e1780c81b1784d44f301f531e4d0860
f9e4da319fe1f5a7d497c452421f4648a24ec7588f309ebea0f0cd61a6251eef
5f734b84215c50d8493a0f8bc5abd56307dff02c8be2d15fe082707d490a119e
362ce33aa715a7ba30cb6670f4f052b38ab8f329c7f09b07918b1000a5e62cd1
85b2167f5850412940625c80c1a0fbabce43a5e34afa22005cd0bb7d154b7a0d
1d075239a73d2ad0c930452b06b94d76158f18e2ce7586bdeb7db37d0f9e75f1
6ed76614f5e413c4b87ac6c4f98bfbca85c5a0d0caaffe5cb1d89ad1e05ecd13
df16916420f19b575159f99a513cf352edbd62f9c7c82d84513ae4163f0e1a1f
c2deceb5b4f379eb05eb4bb1c66d728a74d9744cb80a38c01bf6c86b3c3a2e51
fdc37d258fb80b7fac0f54776d18039db8edbbedc66b1f4f8cbc1e6f01a075ad
523fec7efccf69a09adc271d0a086454d821467ac3e949481334c9b15c3f2b54
d49982e7a5949f4e0e0c87547589704e16a02315258488dc5222d90775882761
Domains
www.msftconnecttest.com
nexusrules.officeapps.live.com
ocsp.digicert.com
slscr.update.microsoft.com
client.wns.windows.com
self.events.data.microsoft.com
oneocsp.microsoft.com
settings-win.data.microsoft.com
fe3cr.delivery.mp.microsoft.com
www.microsoft.com
activation-v2.sls.microsoft.com
google.com
crl.microsoft.com
www.bing.com
login.live.com
ad.doubleclick.net
cdn.btloader.com
script-api.ccgateway.net
www.google-analytics.com
cdn.api.btloader.com
URLs
http://www.msftconnecttest.com/connecttest.txt
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a6c557ad0c3e27c4
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:wscgznaq-iki7rcdesth6d_b0iumm3nlg4gfhhlkudw&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.26100&devicefamily=server&installdate=1761899409&clientversion=141.0.3537.99&experimentationmode=1&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://www.bing.com/bloomfilterfiles/expandeddomainsfilterglobal.json
https://config.edge.skype.com/config/v1/edge/141.0.3537.99?clientid=-8107584157342487295&agents=edgeconfig%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&osarch=x86_64&osver=10.0.26100&wu=1&devicefamily=server&soobedate=1761899407&uma=1&sessionid=9&mngd=1&installdate=1761899409&edu=0&vm=0&bphint=0&fg=1&lbfgdate=1762963124&lafgdate=0&aad=1&ad=2&cm=0
https://www.mi.com/global
https://slscr.update.microsoft.com/sls/%7b8b24b027-1dee-babb-9a95-3517dfb9c552%7d/x64/10.0.26100.6905/0?ch=833&l=en-us&p=&pt=0x7&wua=1450.2508.27012.0&mk=qemu&md=standard+pc+(q35+%2b+ich9%2c+2009)
https://config.edge.skype.com/config/v1/edge/141.0.3537.99?clientid=-8107584157342487295&agents=edgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&osarch=x86_64&osver=10.0.26100&wu=1&devicefamily=server&soobedate=1761899407&uma=1&sessionid=9&mngd=1&installdate=1761899409&edu=0&vm=0&bphint=0&fg=1&lbfgdate=1781834775&lafgdate=0&aad=1&ad=2&cm=0
https://www.mi.com/sgp/spps_files/store/0.55.109/css/global/index.css
https://www.mi.com/sgp/spps_files/store/0.55.109/css/editable.chunk.css
https://www.mi.com/sgp/spps_files/store/0.55.109/css/57477.chunk.css
https://www.mi.com/sgp/spps_files/store/0.55.109/css/carousel-banner.chunk.css
https://www.mi.com/sgp/spps_files/store/0.55.109/css/explore-xiaomi.chunk.css
https://www.mi.com/sgp/spps_files/store/0.55.109/css/featured-tabs.chunk.css
https://www.mi.com/sgp/spps_files/store/0.55.109/css/support-web-home.chunk.css
https://www.mi.com/sgp/spps_files/store/0.55.109/js/64807.chunk.js
https://www.mi.com/sgp/spps_files/store/0.55.109/js/45375.chunk.js
Last Seen at

Recent blog posts

post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 4744
comments 0
post image
15 Minutes Saved Per Alert: How a Lean German...
watchers 9543
comments 0
post image
HVNC Backdoor Targets LATAM Organizations wit...
watchers 11471
comments 0

What is Razr ransomware?

Razr ransomware is a recent and sophisticated strain of ransomware that surfaced in 2024, targeting systems by encrypting essential files and demanding ransom payments from victims.

The malware has made headlines due to its unique use of cloud-based platforms, like PythonAnywhere, as part of its distribution strategy, leveraging these services to host malicious files and bypass security defenses.

Known for appending the ".raz" extension to locked files, Razr delivers a ransom note typically titled “README.txt” with instructions for payment.

Razr ransom note in ANY.RUN sandbox Ransom note displayed inside ANY.RUN sandbox

This behavior and ransom note can be easily seen inside ANY.RUN’s interactive sandbox following analysis session: View analysis session

Razr’s rapid spread and its use of AES-256 encryption make it difficult for victims to regain access without paying the ransom, placing it among the newer threats that exploit trusted platforms for distribution.

Razr ransomware technical details

The primary functionality of Razr is to exfiltrate sensitive data from infected systems. Its key features include:

  • Uses AES-256 encryption to securely lock files on the infected system.
  • Collects and transmits sensitive data from the infected device to a command-and-control (C2) server, giving attackers access to valuable information.
  • Employs various techniques to conceal its code and activities, including hiding in legitimate processes and encoding its payloads.
  • Maintains communication with a remote C2 server, allowing attackers to manage the malware, send commands, and retrieve exfiltrated data remotely.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Razr ransomware execution process

To see how Razr ransomware operates, let’s upload its sample to the ANY.RUN sandbox.

Razr ransomware typically gains access to systems through several attack vectors. Common methods include malicious email attachments or links that trick users into executing the ransomware, as well as attackers exploiting known software or operating system vulnerabilities to infiltrate networks. In some cases, compromised credentials enable attackers to access systems directly. Once inside, the ransomware establishes a foothold on the infected system.

After gaining access, Razr executes its payload by dropping and running a malicious binary that initiates the encryption process. It scans the system for valuable files, including documents, images, and databases, prioritizing those critical for operations. Razr may also exploit vulnerabilities to spread across the network, targeting other connected devices and servers.

Razr graph in ANY.RUN sandbox Process graph of Razr ransomware inside ANY.RUN sandbox

Razr's core functionality is file encryption, using the AES-256 algorithm in CBC mode. The ransomware is engineered to avoid encrypting system-critical files to ensure the operating system remains functional, thereby prolonging the attack’s effectiveness.

Once encryption is complete, Razr presents its ransom demand. Typically, it changes the desktop background or creates text files in each encrypted directory with instructions for paying the ransom.

Razr sandbox in ANY.RUN sandbox Ransom note displayed inside sandbox

The ransom is generally requested in cryptocurrency, which makes transactions difficult to trace. Victims are often given a limited time frame, such as 24 to 48 hours, to pay before facing permanent data loss.

Some ransomware variants also threaten to leak sensitive data if the ransom is unpaid, increasing pressure on victims to comply. Without backups—or if backups are also encrypted—victims face significant challenges in recovering their data without paying the ransom.

Razr ransomware distribution methods

Razr ransomware employs several distribution methods to infiltrate target systems:

  • Phishing emails with malicious attachments or links: Attackers send emails containing harmful attachments or links that, when opened, download the Razr payload.
  • Exploitation of Cloud platforms: Razr has been observed leveraging legitimate cloud services, such as PythonAnywhere, to host and distribute its malicious files, thereby evading detection by security systems.
  • Drive-by downloads: Users visiting compromised or malicious websites may inadvertently download and execute the Razr ransomware without any direct interaction.

Gathering Threat Intelligence on Razr Ransomware

To gather the latest intelligence on Razr ransomware, use the Threat Intelligence Lookup feature in ANY.RUN.

This service provides access to a comprehensive database with insights from millions of malware analysis sessions conducted in the ANY.RUN sandbox. With over 40 customizable search filters, users can locate data on threats like IPs, domains, file names, and process artifacts tied to Razr.

Razr TI Lookup results in ANY.RUN sandbox Search results for Razr in Threat Intelligence Lookup

For instance, to collect information on Razr, you can search for its threat name or a related artifact. Entering a query such as threatName:"Razr" AND domainName:"" will generate a list of files, events, domain names, and other data extracted from Lumma samples along with sandbox sessions that you can explore in detail to gain comprehensive insights into this malware’s behavior.

Try a 14-day free trial of Threat Intelligence Lookup with the ANY.RUN sandbox for hands-on intelligence gathering.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Razr ransomware is dangerous due to its strong encryption, cloud-based delivery, and ability to evade detection. Using tools like ANY.RUN is essential for proactively analyzing suspicious files and URLs, enabling early detection.

ANY.RUN offers real-time threat analysis in a sandboxed environment, providing insights into malware behavior visual tracking and other advanced features.

Sign up for a free ANY.RUN account today and start analyzing emerging threats with no limits!

HAVE A LOOK AT

Salty 2FA screenshot
Salty 2FA
salty2fa
Salty 2FA is a sophisticated Phishing-as-a-Service (PhaaS) framework tailored to hijack user sessions, steal credentials, and gain unauthorized access to corporate systems. Delivered primarily via targeted emails, this kit employs multi-stage evasion tactics, making it a stealthy tool for cybercriminals aiming at high-value enterprise accounts.
Read More
ValleyRAT screenshot
ValleyRAT
valleyrat
ValleyRAT is a classic remote access trojan first documented in 2023, targeting mainly Windows systems. It is used by threat actors to gain persistent access to infected devices, steal data, and control compromised machines. ValleyRAT is notable for its relatively advanced evasion techniques and its connections to a prominent Chinese APT group.
Read More
Cerber screenshot
Cerber
cerber
Cerber is a Ransomware-as-a-Service (RaaS) that appeared in 2016, spread quickly and has been evolving since. It became well-known for its file encryption, offline capabilities, and sophisticated evasion techniques. It primarily targets enterprises, financial institutions, and government entities, encrypting their data and demanding ransom payments in Bitcoin. It also targets everyday users encrypting personal files (photos, documents) with the risk of their permanent loss.
Read More
SolarisLoader screenshot
SolarisLoader
solaris
SolarisLoader is a malware loader designed to neutralize security infrastructure before deploying high-risk secondary payloads. It utilizes a "Bring Your Own Vulnerable Driver" technique to gain kernel-level access and terminate antivirus processes. To remain undetected, the malware patches internal Windows monitoring interfaces and isolates the machine from security updates. Finally, it establishes a resilient three-layer persistence mechanism involving scheduled tasks, registry backups, and a watchdog component.
Read More
Phishing kit screenshot
Phishing kit
tycoon evilproxy sneaky2fa
Phishing kits are pre-packaged sets of malicious tools designed to make it easy for cybercriminals to launch phishing attacks. These kits replicate legitimate websites, steal credentials, and often include backend infrastructure for managing stolen data.
Read More
Crypto malware screenshot
Crypto malware
miner xmrig jsminer
Crypto mining malware is a resource-intensive threat that infiltrates computers with the purpose of mining cryptocurrencies. This type of threat can be deployed either on an infected machine or a compromised website. In both cases the miner will utilize the computing power of the device and its network bandwidth.
Read More