Threat Database Hacktool Hacktool.MSIL.RobloxHack.FQ

Hacktool.MSIL.RobloxHack.FQ

By CagedTech in Hacktool

Analysis Report

General information

Family Name: Hacktool.MSIL.RobloxHack.FQ
Signature status: Modified signature

Known Samples

MD5: dedd22bffd4680d597c17ebbe9ca8772
SHA1: 2db677e1fadff15df5e3dfea2ccf097d10fcf010
SHA256: 113A01996D102D01CCF43EE03751393FF7ABC687CB7D2FD5E6DE5FC76AF64F34
File Size: 712.29 KB, 712288 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.5.0.0
Company Name REKORD SI
File Description RekordLocalLauncherWss
File Version 1.5.0.0
Internal Name RekordLocalLauncher.exe
Legal Copyright Copyright © REKORD SI 2016
Original Filename RekordLocalLauncher.exe
Product Name RekordLocalLauncherWss
Product Version 1.5.0.0

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 17
Potentially Malicious Blocks: 4
Whitelisted Blocks: 13
Unknown Blocks: 0

Visual Map

x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.RobloxHack.FQ

Files Modified

File Attributes
c:\users\user\appdata\local\temp\tmpc26a.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\tmpc2f8.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\rekord\locallauncher\logs\launcher-2025-12-29.log Generic Write,Read Attributes
c:\users\user\appdata\roaming\rekord\locallauncher\pid.txt Generic Write,Read Attributes
c:\users\user\appdata\roaming\rekord\locallauncher\rekordlocallauncher.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\run::rekordlocallauncher "C:\Users\Ngfzcmwa\AppData\Roaming\REKORD\LocalLauncher\RekordLocalLauncher.exe" RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
  • OutputDebugString
Other Suspicious
  • AdjustTokenPrivileges
Encryption Used
  • BCryptOpenAlgorithmProvider
Cert Store Read
  • CertEnumCertificatesInStore
  • CertOpenStore
Cert Store Write
  • CertAddCertificateContextToStore
Network Winsock2
  • WSASocket
  • WSAStartup
Network Winsock
  • accept
  • bind
  • closesocket
  • getsockname
  • setsockopt

Trending

Most Viewed

Loading...