| File name: | ryujinx-1.3.2-win_x64.zip |
| Full analysis: | https://app.any.run/tasks/6676c405-670b-4db6-a50d-761efc48b74c |
| Verdict: | Malicious activity |
| Analysis date: | August 09, 2025, 21:12:33 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v2.0 to extract, compression method=store |
| MD5: | 0912F130874EA795C33B2D5BDA7A3168 |
| SHA1: | CAD5C734BB1076259529AFF3B51CD787A7FF2337 |
| SHA256: | ACB7A4252C538D6B537F917E09C20996D141DC2E41E5177B8D8A78FB61278F06 |
| SSDEEP: | 393216:/SaiY/SeQdmLfMhRdcLYb5zxPRodd0DX5h5kKTdqO:KtY/CwLfMiLi5zsdd0DpFd |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 20 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2025:06:09 23:45:10 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | publish/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2400 | "C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\LICENSE.txt | C:\Windows\System32\notepad.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2632 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | Ryujinx.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3160 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa4684.32226\publish\Ryujinx.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa4684.32226\publish\Ryujinx.exe | WinRAR.exe | ||||||||||||
User: admin Company: Ryujinx Integrity Level: MEDIUM Description: Ryujinx Version: 1.3.2.0 Modules
| |||||||||||||||
| 3288 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\ryujinx-1.3.2-win_x64.zip | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe | |||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 4400 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4684 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\ryujinx-1.3.2-win_x64.zip" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.91.0 Modules
| |||||||||||||||
| 5436 | C:\WINDOWS\system32\OpenWith.exe -Embedding | C:\Windows\System32\OpenWith.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Pick an app Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7084 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\preferences.zip | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\chromium_ext.zip | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\ryujinx-1.3.2-win_x64.zip | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList |
| Operation: | write | Name: | ArcSort |
Value: 32 | |||
| (PID) Process: | (3288) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin |
| Operation: | write | Name: | Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4684 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa4684.32226\publish\Ryujinx.exe | — | |
MD5:— | SHA256:— | |||
| 3160 | Ryujinx.exe | C:\Users\admin\AppData\Roaming\Ryujinx\bis\system\save\8000000000000000\.lock | — | |
MD5:— | SHA256:— | |||
| 4684 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa4684.32226\publish\alsoft.ini | text | |
MD5:C0A92D39626EAB678620C85E8EFF1730 | SHA256:37B67FF73AA4FDD271C32E9652946E2557B0FC94FF460DE6FC7983D00AE21F5D | |||
| 4684 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa4684.32226\publish\avutil-58.dll | executable | |
MD5:41A99218993EA073EC161CF8358104A9 | SHA256:1119854F778E303C42084A46815F3755784E36137CF242DE8C36B0D7553DBA76 | |||
| 4684 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa4684.32226\publish\libSkiaSharp.dll | executable | |
MD5:EF1FABCE43FE32CA83260481253F5476 | SHA256:9A0D95E8CAAA852C70D085AF6A40A744242172AD9EA3FD6BC7599875A8A1DBCD | |||
| 4684 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa4684.32226\publish\OpenAL32.dll | executable | |
MD5:FF08BA3A9DFE6BD0B26F9055094C9550 | SHA256:5A42440A18A75CE588659158D74D26AB1850EABD34F3B25ABD969A56D871DB42 | |||
| 4684 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa4684.32226\publish\libHarfBuzzSharp.dll | executable | |
MD5:C22DE44419D1A1F1AA059F451FC59016 | SHA256:EF5923EF4CDC8612C1825B294174B5B8CC8A056ED0F06B58DB56AABC56AAAE12 | |||
| 4684 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa4684.32226\publish\libsoundio.dll | executable | |
MD5:B492D241DBAE5FD322B1779226A3F0A9 | SHA256:B266F223CB08279B8DD09E08538FC9468255D904B609C28775DBAEFFBE753DDB | |||
| 4684 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa4684.32226\publish\LICENSE.txt | text | |
MD5:9637787BEB66A7405DC0E8CADA65505A | SHA256:781BBDF040B7D0286C47CCA6BFFDB9148DFE751C0C9CABDF1A1752412A2E56B4 | |||
| 4684 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa4684.32226\publish\Ryujinx.SDL2.Common.dll.config | xml | |
MD5:2D175F1DAD5AFD5FF46691DB53D9459A | SHA256:CCB8D75668D09DA1D56153FEF48E62DE2EF3C6248CFB1B98169C4D94EAC77CEB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5944 | MoUsoCoreWorker.exe | GET | 200 | 23.216.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 23.216.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | GET | 200 | 69.192.161.161:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 69.192.161.161:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 69.192.161.161:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | POST | 400 | 20.190.159.129:443 | https://login.live.com/ppsecure/deviceaddcredential.srf | unknown | text | 203 b | whitelisted |
— | — | POST | 400 | 20.190.159.73:443 | https://login.live.com/ppsecure/deviceaddcredential.srf | unknown | text | 203 b | whitelisted |
— | — | POST | 400 | 40.126.31.1:443 | https://login.live.com/ppsecure/deviceaddcredential.srf | unknown | text | 203 b | whitelisted |
— | — | POST | 200 | 20.190.159.129:443 | https://login.live.com/RST2.srf | unknown | xml | 1.24 Kb | whitelisted |
— | — | POST | 400 | 20.190.159.64:443 | https://login.live.com/ppsecure/deviceaddcredential.srf | unknown | text | 203 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 23.216.77.6:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
1268 | svchost.exe | 23.216.77.6:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5944 | MoUsoCoreWorker.exe | 69.192.161.161:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
— | — | 69.192.161.161:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
1268 | svchost.exe | 69.192.161.161:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 40.126.32.72:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |