| URL: | https://www.mediafire.com/file/lp3enicl2uf6osp/Rz_Laun_v_6.3.57.rar/file |
| Full analysis: | https://app.any.run/tasks/679d98e6-e479-41f6-9ac7-7eeb4e1c6d4b |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | October 25, 2024, 13:34:27 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 10BE6136CDE3885EC245D5F068555DEF |
| SHA1: | A2092B51018F4F41E79B8721F651E14399827FE9 |
| SHA256: | A888ED2436D43321C398C0A531B5C1F0979DE8EEA9590ED3E341780A3AFCB9D3 |
| SSDEEP: | 3:N8DSLw3eGUoT9XaVKipQTBk4lDIA:2OLw3eGH+pQFvaA |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 696 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIa7556.14971\Rz_launcher Setup1.zip" | C:\Program Files\WinRAR\WinRAR.exe | WinRAR.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 1176 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5756 --field-trial-handle=2304,i,8855102346848530185,17265467204513401944,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 | |||||||||||||||
| 1196 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://www.mediafire.com/file/lp3enicl2uf6osp/Rz_Laun_v_6.3.57.rar/file" | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 4294967295 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1500 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=6464 --field-trial-handle=2304,i,8855102346848530185,17265467204513401944,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1712 | C:\WINDOWS\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding | C:\Windows\explorer.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Version: 10.0.19041.3758 (WinBuild.160101.0800) | |||||||||||||||
| 2056 | "C:\Users\admin\Downloads\Rzlauncher Setup.exe" | C:\Users\admin\Downloads\Rzlauncher Setup.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 2236 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5736 --field-trial-handle=2304,i,8855102346848530185,17265467204513401944,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2312 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=7324 --field-trial-handle=2304,i,8855102346848530185,17265467204513401944,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2632 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | ZjlhNjhkYzY5Y2NhOTk2YTYzNTM5NDczNGRlOGU5NGE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) | |||||||||||||||
| 2660 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4812 --field-trial-handle=2304,i,8855102346848530185,17265467204513401944,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 | |||||||||||||||
| (PID) Process: | (1196) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (1196) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (1196) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (1196) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (1196) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault |
| Operation: | write | Name: | S-1-5-21-1693682860-607145093-2874071422-1001 |
Value: C5B28776E3832F00 | |||
| (PID) Process: | (1196) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault |
| Operation: | write | Name: | S-1-5-21-1693682860-607145093-2874071422-1001 |
Value: 1BA39176E3832F00 | |||
| (PID) Process: | (1196) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328328 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {B03D7748-CFB5-4AB3-9372-B17EAA82D99C} | |||
| (PID) Process: | (1196) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328328 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {6F0D0F26-F1D7-4BC5-BA7C-9B6816F73660} | |||
| (PID) Process: | (1196) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328328 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {405AD73F-3B41-4F28-9963-FBB6686610E6} | |||
| (PID) Process: | (1196) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328328 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {E3C042EC-8E10-4EF5-B7CA-2520EBF06BBA} | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1196 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF8c0b9.TMP | — | |
MD5:— | SHA256:— | |||
| 1196 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 1196 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF8c0f7.TMP | — | |
MD5:— | SHA256:— | |||
| 1196 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 1196 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF8c0b9.TMP | — | |
MD5:— | SHA256:— | |||
| 1196 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF8c136.TMP | — | |
MD5:— | SHA256:— | |||
| 1196 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old | — | |
MD5:— | SHA256:— | |||
| 1196 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF8c145.TMP | — | |
MD5:— | SHA256:— | |||
| 1196 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old | — | |
MD5:— | SHA256:— | |||
| 1196 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3728 | SIHClient.exe | GET | 200 | 23.200.189.225:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7632 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
4004 | svchost.exe | HEAD | 200 | 23.32.239.73:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a081ba6e-045a-42ea-b073-95dd0653279b?P1=1730342558&P2=404&P3=2&P4=UUfC7EHwg9kSIDMIpEaT%2bWW%2fysstse3yLmeP%2bi3rCpUKy3DrDB1a2IHzA5NyLWEWROPbIcPWU4WdSfJlyIV2Bg%3d%3d | unknown | — | — | whitelisted |
3728 | SIHClient.exe | GET | 200 | 23.200.189.225:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
4004 | svchost.exe | GET | 206 | 23.32.239.73:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a081ba6e-045a-42ea-b073-95dd0653279b?P1=1730342558&P2=404&P3=2&P4=UUfC7EHwg9kSIDMIpEaT%2bWW%2fysstse3yLmeP%2bi3rCpUKy3DrDB1a2IHzA5NyLWEWROPbIcPWU4WdSfJlyIV2Bg%3d%3d | unknown | — | — | whitelisted |
4004 | svchost.exe | GET | 206 | 23.32.239.73:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a081ba6e-045a-42ea-b073-95dd0653279b?P1=1730342558&P2=404&P3=2&P4=UUfC7EHwg9kSIDMIpEaT%2bWW%2fysstse3yLmeP%2bi3rCpUKy3DrDB1a2IHzA5NyLWEWROPbIcPWU4WdSfJlyIV2Bg%3d%3d | unknown | — | — | whitelisted |
4004 | svchost.exe | GET | 206 | 23.32.239.73:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a081ba6e-045a-42ea-b073-95dd0653279b?P1=1730342558&P2=404&P3=2&P4=UUfC7EHwg9kSIDMIpEaT%2bWW%2fysstse3yLmeP%2bi3rCpUKy3DrDB1a2IHzA5NyLWEWROPbIcPWU4WdSfJlyIV2Bg%3d%3d | unknown | — | — | whitelisted |
4004 | svchost.exe | GET | 206 | 23.32.239.73:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a081ba6e-045a-42ea-b073-95dd0653279b?P1=1730342558&P2=404&P3=2&P4=UUfC7EHwg9kSIDMIpEaT%2bWW%2fysstse3yLmeP%2bi3rCpUKy3DrDB1a2IHzA5NyLWEWROPbIcPWU4WdSfJlyIV2Bg%3d%3d | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.16.164.9:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
6944 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5488 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 2.16.164.9:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
— | — | 88.221.169.152:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1196 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
5944 | msedge.exe | 104.17.150.117:443 | www.mediafire.com | — | — | shared |
5944 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
www.mediafire.com |
| shared |
edge.microsoft.com |
| whitelisted |
edge-mobile-static.azureedge.net |
| whitelisted |
business.bing.com |
| whitelisted |
bzib.nelreports.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
5944 | msedge.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
5944 | msedge.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup |
5944 | msedge.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com) |
5944 | msedge.exe | Potentially Bad Traffic | ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com) |
5944 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare Network Error Logging (NEL) |
5944 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare Network Error Logging (NEL) |
— | — | Misc activity | ET INFO Observed Telegram Domain (t .me in TLS SNI) |
— | — | Potentially Bad Traffic | ET POLICY Vulnerable Java Version 1.8.x Detected |
— | — | Misc activity | ET HUNTING Suspicious EXE requested with Java UA |
— | — | Potentially Bad Traffic | ET INFO Executable Download from dotted-quad Host |