tix-robuxgenerator.exe

Roblox Account Stealer v1.0

The executable tix-robuxgenerator.exe has been detected as malware by 3 anti-virus scanners. The file has been seen being downloaded from download1432.mediafire.com and multiple other hosts.
Product:
Roblox Account Stealer v1.0

Version:
1.0.0.0

MD5:
2c09f716b992430032d73d3a297b1e27

SHA-1:
7a6edf87d1d70ca08d058af38b8a43db5ae2ba4e

SHA-256:
911f80b0345214f3c51a9a3ae9e072a0dbc15ee0e53c59da123fb21858280e72

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
1/13/2025 5:55:37 PM UTC  (today)

Scan engine
Detection
Engine version

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.1373

Reason Heuristics
Threat.Downloader.KY
16.2.29.19

Vba32 AntiVirus
Trojan.MSIL.gen.11
3.12.26.4

File size:
226.5 KB (231,936 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Original file name:
Roblox Account Stealer v1.0.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\programs\tix-robuxgenerator.exe

File PE Metadata
Compilation timestamp:
7/28/2015 10:49:07 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:Sy8cdQ8DdrINu/YEzFNfxcTty8cdQ8Dd:VhrIA/YwFVqmh

Entry address:
0x2737E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.8979

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
149 KB (152,576 bytes)

The file tix-robuxgenerator.exe has been seen being distributed by the following 5 URLs.

http://download1432.mediafire.com/516bzbgunzvg/.../TIX-RobuxGenerator.exe

Remove tix-robuxgenerator.exe - Powered by Reason Core Security