| download: | /IrisV3rm/Roblox-Asset-Scraper/releases/download/4.0.5/MassRobloxAssetStealer.exe |
| Full analysis: | https://app.any.run/tasks/39b7f3d1-29a6-40de-b108-3123de6d1030 |
| Verdict: | Malicious activity |
| Analysis date: | November 03, 2023, 19:42:11 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| MD5: | 65D55C589932CA85D4D07795C63C6E12 |
| SHA1: | 3332AF273F98C7B3F390C520D3E76DEB499B721B |
| SHA256: | 01E872E959381DFDB6A4CEB3E92DB29DAD7D767D2FA6A4DDC8F2109B0DAEAA21 |
| SSDEEP: | 98304:G8Svfx9vEqwYnDWNpK65DBoIBajEHyVy9YBPUHexnMO93WGY:wY |
| .exe | | | Generic CIL Executable (.NET, Mono, etc.) (63.1) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (23.8) |
| .dll | | | Win32 Dynamic Link Library (generic) (5.6) |
| .exe | | | Win32 Executable (generic) (3.8) |
| .exe | | | Generic Win/DOS Executable (1.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2084:07:10 22:59:49+02:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 48 |
| CodeSize: | 1522688 |
| InitializedDataSize: | 272896 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x175bee |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | - |
| CompanyName: | - |
| FileDescription: | MassRobloxAssetStealer |
| FileVersion: | 1.0.0.0 |
| InternalName: | MassRobloxAssetStealer.exe |
| LegalCopyright: | Copyright © 2020 |
| LegalTrademarks: | - |
| OriginalFileName: | MassRobloxAssetStealer.exe |
| ProductName: | MassRobloxAssetStealer |
| ProductVersion: | 1.0.0.0 |
| AssemblyVersion: | 1.0.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3308 | "C:\Users\admin\AppData\Local\Temp\MassRobloxAssetStealer.exe" | C:\Users\admin\AppData\Local\Temp\MassRobloxAssetStealer.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: MassRobloxAssetStealer Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 3512 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3308) MassRobloxAssetStealer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3308) MassRobloxAssetStealer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | Browse For Folder Width |
Value: 318 | |||
| (PID) Process: | (3308) MassRobloxAssetStealer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | Browse For Folder Height |
Value: 288 | |||
| (PID) Process: | (3512) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{80312084-547A-42F1-AD60-98B17B700032}\{0096301B-622E-43BE-AFC4-0BA08DE5BDCD} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3512) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{80312084-547A-42F1-AD60-98B17B700032} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3512) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{4C66A10C-7ED5-455B-8A1E-8865147F1F98} |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3308 | MassRobloxAssetStealer.exe | C:\Users\admin\Desktop\Audio\door_open.mp3 | binary | |
MD5:258EA33347B5791F828F397E88B2BDC9 | SHA256:BB29B2F0A9B61D9758A3B0E8BAC86C42E8CD7278708AE011F499AEB260CBDA67 | |||
| 3308 | MassRobloxAssetStealer.exe | C:\Users\admin\Desktop\Audio\Horror.mp3 | binary | |
MD5:628869E03A0C5BB08DC6EEE5950B79DA | SHA256:49AB9D92F4CB437F6AAA10CD51343C8F31E88609485EC5D6A1EDC00CEF332249 | |||
| 3308 | MassRobloxAssetStealer.exe | C:\Users\admin\Desktop\Audio\Relaxed Scene.mp3 | binary | |
MD5:E6300BEEF2785118308344B75090A18A | SHA256:0F4DABECA50CC52486145D1652B96B39FCA0678CFC0555E6A0A07ACFEE149312 | |||
| 3308 | MassRobloxAssetStealer.exe | C:\Users\admin\Desktop\Audio\fart meme.mp3 | binary | |
MD5:F27E27BF890011409771B320342C7E01 | SHA256:7B2BAE1FEEB834BFDAE9B914ABEF458F677D5D2F25C3E4E3434B5946A65D37D3 | |||
| 3308 | MassRobloxAssetStealer.exe | C:\Users\admin\Desktop\Audio\City Night Ambience 1 (SFX).mp3 | binary | |
MD5:91A616C4CDBFC73BF389A859D5C14A67 | SHA256:6041DCF7826F7E2DDB37C06EAA1D8A88E199D8258A54CEB6568DDA77571A2AAF | |||
| 3308 | MassRobloxAssetStealer.exe | C:\Users\admin\AppData\Local\Temp\fe18e516-f12f-4073-bf13-52a839118bfb\GunaDotNetRT.dll | executable | |
MD5:9AF5EB006BB0BAB7F226272D82C896C7 | SHA256:77DC05A6BDA90757F66552EE3F469B09F1E00732B4EDCA0F542872FB591ED9DB | |||
| 3308 | MassRobloxAssetStealer.exe | C:\Users\admin\Desktop\Audio\Gun Shot.mp3 | binary | |
MD5:2A0D8A469ED04649A944666DDA99DFE3 | SHA256:5D0638C85CDA049C0879EBC529226E80E4B7D16CE95641C45842945E1EB12BE8 | |||
| 3308 | MassRobloxAssetStealer.exe | C:\Users\admin\Desktop\Audio\Hospital Horror Roars Booms 2 (SFX).mp3 | binary | |
MD5:33F6910FB55B1F3AF8F304BB1BBF556F | SHA256:787D8339971DAA27E374770D485F7774CDD2B4C040AA93DC8BDE07F4F5BF203F | |||
| 3308 | MassRobloxAssetStealer.exe | C:\Users\admin\Desktop\Audio\Clair De Lune.mp3 | — | |
MD5:— | SHA256:— | |||
| 3308 | MassRobloxAssetStealer.exe | C:\Users\admin\Desktop\Audio\Paradise Falls.mp3 | binary | |
MD5:DBA1251FE38C313F38AD10587B4AEBC4 | SHA256:1DDEB739B65F863BEACAEDD30D0C08DCCBC51F4DFB9399947034747E4E22B25C | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
868 | svchost.exe | 95.101.148.135:80 | — | Akamai International B.V. | NL | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
868 | svchost.exe | 88.221.124.138:80 | armmf.adobe.com | AKAMAI-AS | DE | unknown |
3308 | MassRobloxAssetStealer.exe | 104.21.16.76:443 | api.irisapp.ca | CLOUDFLARENET | — | unknown |
3308 | MassRobloxAssetStealer.exe | 205.185.216.42:443 | c7.rbxcdn.com | STACKPATH-CDN | US | whitelisted |
3308 | MassRobloxAssetStealer.exe | 205.185.216.10:443 | c7.rbxcdn.com | STACKPATH-CDN | US | whitelisted |
3308 | MassRobloxAssetStealer.exe | 2.16.164.115:443 | c1.rbxcdn.com | Akamai International B.V. | NL | unknown |
3308 | MassRobloxAssetStealer.exe | 2.16.164.104:443 | c5.rbxcdn.com | Akamai International B.V. | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
armmf.adobe.com |
| whitelisted |
api.irisapp.ca |
| unknown |
c7.rbxcdn.com |
| whitelisted |
c3.rbxcdn.com |
| whitelisted |
c6.rbxcdn.com |
| whitelisted |
c1.rbxcdn.com |
| whitelisted |
c5.rbxcdn.com |
| whitelisted |
c2.rbxcdn.com |
| whitelisted |
c4.rbxcdn.com |
| whitelisted |
c0.rbxcdn.com |
| whitelisted |