| download: | /IrisV3rm/Roblox-Asset-Scraper/releases/download/4.0.5/MassRobloxAssetStealer.exe |
| Full analysis: | https://app.any.run/tasks/39b7f3d1-29a6-40de-b108-3123de6d1030 |
| Verdict: | Malicious activity |
| Analysis date: | November 03, 2023, 19:42:11 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| MD5: | 65D55C589932CA85D4D07795C63C6E12 |
| SHA1: | 3332AF273F98C7B3F390C520D3E76DEB499B721B |
| SHA256: | 01E872E959381DFDB6A4CEB3E92DB29DAD7D767D2FA6A4DDC8F2109B0DAEAA21 |
| SSDEEP: | 98304:G8Svfx9vEqwYnDWNpK65DBoIBajEHyVy9YBPUHexnMO93WGY:wY |
| .exe | | | Generic CIL Executable (.NET, Mono, etc.) (63.1) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (23.8) |
| .dll | | | Win32 Dynamic Link Library (generic) (5.6) |
| .exe | | | Win32 Executable (generic) (3.8) |
| .exe | | | Generic Win/DOS Executable (1.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2084:07:10 22:59:49+02:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 48 |
| CodeSize: | 1522688 |
| InitializedDataSize: | 272896 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x175bee |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | - |
| CompanyName: | - |
| FileDescription: | MassRobloxAssetStealer |
| FileVersion: | 1.0.0.0 |
| InternalName: | MassRobloxAssetStealer.exe |
| LegalCopyright: | Copyright © 2020 |
| LegalTrademarks: | - |
| OriginalFileName: | MassRobloxAssetStealer.exe |
| ProductName: | MassRobloxAssetStealer |
| ProductVersion: | 1.0.0.0 |
| AssemblyVersion: | 1.0.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3308 | "C:\Users\admin\AppData\Local\Temp\MassRobloxAssetStealer.exe" | C:\Users\admin\AppData\Local\Temp\MassRobloxAssetStealer.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: MassRobloxAssetStealer Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3512 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3308) MassRobloxAssetStealer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3308) MassRobloxAssetStealer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | Browse For Folder Width |
Value: 318 | |||
| (PID) Process: | (3308) MassRobloxAssetStealer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | Browse For Folder Height |
Value: 288 | |||
| (PID) Process: | (3512) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{80312084-547A-42F1-AD60-98B17B700032}\{0096301B-622E-43BE-AFC4-0BA08DE5BDCD} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3512) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{80312084-547A-42F1-AD60-98B17B700032} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3512) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{4C66A10C-7ED5-455B-8A1E-8865147F1F98} |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3308 | MassRobloxAssetStealer.exe | C:\Users\admin\Desktop\Audio\Horror.mp3 | binary | |
MD5:628869E03A0C5BB08DC6EEE5950B79DA | SHA256:49AB9D92F4CB437F6AAA10CD51343C8F31E88609485EC5D6A1EDC00CEF332249 | |||
| 3308 | MassRobloxAssetStealer.exe | C:\Users\admin\Desktop\Audio\Neighborhood Birds 2 (SFX).mp3 | binary | |
MD5:11BC9179DB4BDDB79A0D4DC729FA4C90 | SHA256:9249D4A5F7ABC27BC25399673CA5FC53FB53D3167979669AEDFBF6912B9C4F14 | |||
| 3308 | MassRobloxAssetStealer.exe | C:\Users\admin\Desktop\Audio\door_open.mp3 | binary | |
MD5:258EA33347B5791F828F397E88B2BDC9 | SHA256:BB29B2F0A9B61D9758A3B0E8BAC86C42E8CD7278708AE011F499AEB260CBDA67 | |||
| 3308 | MassRobloxAssetStealer.exe | C:\Users\admin\AppData\Local\Temp\fe18e516-f12f-4073-bf13-52a839118bfb\GunaDotNetRT.dll | executable | |
MD5:9AF5EB006BB0BAB7F226272D82C896C7 | SHA256:77DC05A6BDA90757F66552EE3F469B09F1E00732B4EDCA0F542872FB591ED9DB | |||
| 3308 | MassRobloxAssetStealer.exe | C:\Users\admin\Desktop\Audio\fart meme.mp3 | binary | |
MD5:F27E27BF890011409771B320342C7E01 | SHA256:7B2BAE1FEEB834BFDAE9B914ABEF458F677D5D2F25C3E4E3434B5946A65D37D3 | |||
| 3308 | MassRobloxAssetStealer.exe | C:\Users\admin\Desktop\Audio\Gods Wind Spooky Eerie 2 (SFX).mp3 | binary | |
MD5:A2B81ECC754E1B4777351AF019A3156C | SHA256:4B5B5A9D60758123C31EC267FB526B3C71D00DC0697273B3EE5C373D381EA1E7 | |||
| 3308 | MassRobloxAssetStealer.exe | C:\Users\admin\Desktop\Audio\The Backrooms (but i fixed volume).mp3 | binary | |
MD5:D0E7D2F43F4B079E918DF5C7FF710ACA | SHA256:C42E8C074900693FC7E7AFF526840611A97D10E96794168B52A126862E38E531 | |||
| 3308 | MassRobloxAssetStealer.exe | C:\Users\admin\Desktop\Audio\Chaos.mp3 | binary | |
MD5:3243969BB4F4CB22B4A1864D1FEDC798 | SHA256:CA7680AF7241EB0DFBB7994F0E213F1674FF6B060EFF7E5504646C8F729468E8 | |||
| 3308 | MassRobloxAssetStealer.exe | C:\Users\admin\Desktop\Audio\Clair De Lune.mp3 | — | |
MD5:— | SHA256:— | |||
| 3308 | MassRobloxAssetStealer.exe | C:\Users\admin\Desktop\Audio\Paradise Falls.mp3 | binary | |
MD5:DBA1251FE38C313F38AD10587B4AEBC4 | SHA256:1DDEB739B65F863BEACAEDD30D0C08DCCBC51F4DFB9399947034747E4E22B25C | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
868 | svchost.exe | 95.101.148.135:80 | — | Akamai International B.V. | NL | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
868 | svchost.exe | 88.221.124.138:80 | armmf.adobe.com | AKAMAI-AS | DE | unknown |
3308 | MassRobloxAssetStealer.exe | 104.21.16.76:443 | api.irisapp.ca | CLOUDFLARENET | — | unknown |
3308 | MassRobloxAssetStealer.exe | 205.185.216.42:443 | c7.rbxcdn.com | STACKPATH-CDN | US | whitelisted |
3308 | MassRobloxAssetStealer.exe | 205.185.216.10:443 | c7.rbxcdn.com | STACKPATH-CDN | US | whitelisted |
3308 | MassRobloxAssetStealer.exe | 2.16.164.115:443 | c1.rbxcdn.com | Akamai International B.V. | NL | unknown |
3308 | MassRobloxAssetStealer.exe | 2.16.164.104:443 | c5.rbxcdn.com | Akamai International B.V. | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
armmf.adobe.com |
| whitelisted |
api.irisapp.ca |
| unknown |
c7.rbxcdn.com |
| whitelisted |
c3.rbxcdn.com |
| whitelisted |
c6.rbxcdn.com |
| whitelisted |
c1.rbxcdn.com |
| whitelisted |
c5.rbxcdn.com |
| whitelisted |
c2.rbxcdn.com |
| whitelisted |
c4.rbxcdn.com |
| whitelisted |
c0.rbxcdn.com |
| whitelisted |