| File name: | XB36Hazards Launcher.exe |
| Full analysis: | https://app.any.run/tasks/14ea65b6-9a12-4886-8b6a-9df03378fa4b |
| Verdict: | Malicious activity |
| Analysis date: | May 16, 2025, 14:22:18 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections |
| MD5: | D7FA5514B7DB10A7E7B6241747D59694 |
| SHA1: | C09D7316A52E63577D9819BFE699BF25EFD073AE |
| SHA256: | 31D054B969F3A7824714CB7A9D346B2758E17EB556D8DDE49DD00E6D2A94C232 |
| SSDEEP: | 98304:fRlrxS1ngLfwQH9faVuskghQ+F4Cj5k+biapSEYhxISDfnH63g1+D7m6Z7mnL:fRVxEnhe9izkEQXCj5z8p6wCm6ZqL |
| .exe | | | Generic CIL Executable (.NET, Mono, etc.) (56.7) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (21.3) |
| .scr | | | Windows screen saver (10.1) |
| .dll | | | Win32 Dynamic Link Library (generic) (5) |
| .exe | | | Win32 Executable (generic) (3.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2022:05:11 06:11:36+00:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, Large address aware |
| PEType: | PE32 |
| LinkerVersion: | 80 |
| CodeSize: | 4671488 |
| InitializedDataSize: | 4724224 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x47662e |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 4.0.0.0 |
| ProductVersionNumber: | 4.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | XB36Hazard's Launcher |
| CompanyName: | XB36Hazard |
| FileDescription: | XB36Hazard's Launcher |
| FileVersion: | 4.0.0.0 |
| InternalName: | XB36Hazards Launcher.exe |
| LegalCopyright: | Copyright © XB36Hazard 2022 |
| LegalTrademarks: | XB36Hazard |
| OriginalFileName: | XB36Hazards Launcher.exe |
| ProductName: | XB36Hazard's Launcher |
| ProductVersion: | 4.0.0.0 |
| AssemblyVersion: | 4.0.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 300 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=788 -childID 18 -isForBrowser -prefsHandle 7340 -prefMapHandle 6548 -prefsLen 31645 -prefMapSize 244583 -jsInitHandle 1520 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {a1a89657-da99-4e7a-85d9-5356373a7e85} 5428 "\\.\pipe\gecko-crash-server-pipe.5428" 20b5869c310 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1168 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5308 -childID 5 -isForBrowser -prefsHandle 5392 -prefMapHandle 5388 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1520 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {7a318b65-ee2b-4a9c-97f4-1466404b0d1b} 5428 "\\.\pipe\gecko-crash-server-pipe.5428" 20b5af3aa10 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1628 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1904 -parentBuildID 20240213221259 -prefsHandle 1840 -prefMapHandle 1832 -prefsLen 31031 -prefMapSize 244583 -appDir "C:\Program Files\Mozilla Firefox\browser" - {a9afed93-dbca-46a7-983b-248b37aea0c2} 5428 "\\.\pipe\gecko-crash-server-pipe.5428" 20b4f8edb10 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 2028 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5556 -childID 26 -isForBrowser -prefsHandle 7772 -prefMapHandle 6428 -prefsLen 31823 -prefMapSize 244583 -jsInitHandle 1520 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {dab8ad40-c63c-4efe-82ee-f19d96f3a563} 5428 "\\.\pipe\gecko-crash-server-pipe.5428" 20b5869ca10 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 2064 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4992 -childID 19 -isForBrowser -prefsHandle 7660 -prefMapHandle 6744 -prefsLen 31645 -prefMapSize 244583 -jsInitHandle 1520 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {c9ed9474-b9a1-409a-852e-06f4c12aec2c} 5428 "\\.\pipe\gecko-crash-server-pipe.5428" 20b567e74d0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 2196 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3028 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=7412 -childID 22 -isForBrowser -prefsHandle 7028 -prefMapHandle 7184 -prefsLen 31687 -prefMapSize 244583 -jsInitHandle 1520 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {76ec0964-05ce-46ef-b0d5-c323d312cc52} 5428 "\\.\pipe\gecko-crash-server-pipe.5428" 20b658804d0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 3140 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5148 -childID 4 -isForBrowser -prefsHandle 5124 -prefMapHandle 4976 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1520 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {d90b9c35-7272-48b3-b42d-bb15192b9baf} 5428 "\\.\pipe\gecko-crash-server-pipe.5428" 20b5a8a74d0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 3176 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=7224 -childID 15 -isForBrowser -prefsHandle 7316 -prefMapHandle 7312 -prefsLen 31567 -prefMapSize 244583 -jsInitHandle 1520 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {07793eeb-2d9e-4fe7-b1c1-215bc75dc71e} 5428 "\\.\pipe\gecko-crash-server-pipe.5428" 20b652ea150 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 3992 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=8148 -childID 24 -isForBrowser -prefsHandle 8160 -prefMapHandle 8156 -prefsLen 31823 -prefMapSize 244583 -jsInitHandle 1520 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {a34ec067-60d0-4b04-8509-207392f1a64a} 5428 "\\.\pipe\gecko-crash-server-pipe.5428" 20b58986150 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| (PID) Process: | (7728) XB36Hazards Launcher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\XB36Hazards Launcher_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (7728) XB36Hazards Launcher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\XB36Hazards Launcher_RASAPI32 |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
| (PID) Process: | (7728) XB36Hazards Launcher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\XB36Hazards Launcher_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (7728) XB36Hazards Launcher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\XB36Hazards Launcher_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (7728) XB36Hazards Launcher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\XB36Hazards Launcher_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
| (PID) Process: | (7728) XB36Hazards Launcher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\XB36Hazards Launcher_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (7728) XB36Hazards Launcher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\XB36Hazards Launcher_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
| (PID) Process: | (7728) XB36Hazards Launcher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\XB36Hazards Launcher_RASMANCS |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (7728) XB36Hazards Launcher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\XB36Hazards Launcher_RASMANCS |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
| (PID) Process: | (7728) XB36Hazards Launcher.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\XB36Hazards Launcher_RASMANCS |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7728 | XB36Hazards Launcher.exe | C:\Users\admin\AppData\Local\XB36Hazard\Launcher\C73033648103E4502642DA634FEF262CF642BE9F.XIF | — | |
MD5:— | SHA256:— | |||
| 7728 | XB36Hazards Launcher.exe | C:\Users\admin\AppData\Local\Temp\tmp5A65.tmp | — | |
MD5:— | SHA256:— | |||
| 5428 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 7728 | XB36Hazards Launcher.exe | C:\Users\admin\AppData\Local\Temp\tmp732.tmp | binary | |
MD5:55A54008AD1BA589AA210D2629C1DF41 | SHA256:4BF5122F344554C53BDE2EBB8CD2B7E3D1600AD631C385A5D7CCE23C7785459A | |||
| 7728 | XB36Hazards Launcher.exe | C:\Users\admin\AppData\Local\Temp\tmpE021.tmp | binary | |
MD5:55A54008AD1BA589AA210D2629C1DF41 | SHA256:4BF5122F344554C53BDE2EBB8CD2B7E3D1600AD631C385A5D7CCE23C7785459A | |||
| 7728 | XB36Hazards Launcher.exe | C:\Users\admin\AppData\Local\Temp\tmp6497.tmp | image | |
MD5:5B1F5601A221827734997B69396F1F07 | SHA256:2B91AD4C27B967D18BEC80D6D815EDED7EE93B4C6DF9F89CB8E9EF4EB59A4265 | |||
| 5428 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-child-current.bin | binary | |
MD5:C95DDC2B1A525D1A243E4C294DA2F326 | SHA256:3A5919E086BFB31E36110CF636D2D5109EB51F2C410B107F126126AB25D67363 | |||
| 7728 | XB36Hazards Launcher.exe | C:\Program Files (x86)\XB36Hazard\GTA V Save Editor\uninstall.exe | executable | |
MD5:B6E8D92C45D78B531C585D143DA08697 | SHA256:BF2C67918EADE9ABA6247E0E8789C68E526E02FC4D3DFC516A9734C085961848 | |||
| 5428 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 7728 | XB36Hazards Launcher.exe | C:\Program Files (x86)\XB36Hazard\GTA V Save Editor\GTA V Save Editor.Ico | image | |
MD5:18BBDF1700D1D894B51FAA0D476FD2FB | SHA256:9E8CE5BA677AA3FCF555DC8ABE672EC6366E3F11721E843FDDCAC11E74C08D42 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5428 | firefox.exe | POST | 200 | 184.24.77.52:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
5428 | firefox.exe | POST | 200 | 184.24.77.52:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
5428 | firefox.exe | POST | 200 | 172.217.16.195:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
5428 | firefox.exe | POST | 200 | 184.24.77.79:80 | http://r10.o.lencr.org/ | unknown | — | — | whitelisted |
5428 | firefox.exe | POST | 200 | 184.24.77.52:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
5428 | firefox.exe | POST | 200 | 184.24.77.52:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
5428 | firefox.exe | POST | 200 | 184.24.77.79:80 | http://r10.o.lencr.org/ | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.16.164.120:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.16.164.120:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
5496 | MoUsoCoreWorker.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
2104 | svchost.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2112 | svchost.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3216 | svchost.exe | 172.211.123.248:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
7728 | XB36Hazards Launcher.exe | 162.125.66.18:443 | www.dropbox.com | DROPBOX | DE | whitelisted |
7728 | XB36Hazards Launcher.exe | 162.125.66.15:443 | uc71ac5ef774844ecc1b4c15793b.dl.dropboxusercontent.com | DROPBOX | DE | whitelisted |
6544 | svchost.exe | 20.190.160.5:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
www.dropbox.com |
| whitelisted |
uc71ac5ef774844ecc1b4c15793b.dl.dropboxusercontent.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
uc2c393a453617072a6bf98f89da.dl.dropboxusercontent.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
7728 | XB36Hazards Launcher.exe | Potential Corporate Privacy Violation | ET INFO Dropbox.com Offsite File Backup in Use |
2196 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
2196 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
2196 | svchost.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com) |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
2196 | svchost.exe | Potentially Bad Traffic | ET FILE_SHARING File Sharing Related Domain in DNS Lookup (download .mediafire .com) |
2196 | svchost.exe | Potentially Bad Traffic | ET FILE_SHARING File Sharing Related Domain in DNS Lookup (download .mediafire .com) |