File name:

RobloxPlayerLauncher.exe

Full analysis: https://app.any.run/tasks/fd9ca1c0-d619-4dab-a450-8932d97df0c3
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: December 08, 2023, 19:08:05
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Tags:
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

D756F2EC68565BE15B092325DFC165E4

SHA1:

5ED227AED72963F9048B50C6833A0A0177B71361

SHA256:

011D764D8EE80B0BE3359AEE4FF21D1ABB99FA4FFF869934B33F90DC6309273D

SSDEEP:

98304:77s0L6OWTMFof+9OnaXPNv0Wnv0v8YkTa9KAB/Ik+BPZHXFGyyAW4EIEC/iV+H6k:iQmqL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • RobloxPlayerLauncher.exe (PID: 2932)
      • RobloxPlayerLauncher.exe (PID: 416)
      • MicrosoftEdgeWebview2Setup.exe (PID: 2432)
      • MicrosoftEdge_X64_109.0.1518.140.exe (PID: 1828)
      • MicrosoftEdgeUpdate.exe (PID: 2596)
      • setup.exe (PID: 792)
    • Actions looks like stealing of personal data

      • RobloxPlayerLauncher.exe (PID: 416)
  • SUSPICIOUS

    • Reads the Internet Settings

      • RobloxPlayerLauncher.exe (PID: 2932)
      • RobloxPlayerLauncher.exe (PID: 1408)
      • RobloxPlayerLauncher.exe (PID: 416)
      • RobloxPlayerLauncher.exe (PID: 2788)
      • MicrosoftEdgeUpdate.exe (PID: 2796)
      • MicrosoftEdgeUpdate.exe (PID: 2028)
      • MicrosoftEdgeUpdate.exe (PID: 340)
    • Reads security settings of Internet Explorer

      • RobloxPlayerLauncher.exe (PID: 2932)
      • RobloxPlayerLauncher.exe (PID: 1408)
      • RobloxPlayerLauncher.exe (PID: 416)
      • RobloxPlayerLauncher.exe (PID: 2788)
      • MicrosoftEdgeUpdate.exe (PID: 2796)
      • MicrosoftEdgeUpdate.exe (PID: 2028)
      • MicrosoftEdgeUpdate.exe (PID: 340)
    • Checks Windows Trust Settings

      • RobloxPlayerLauncher.exe (PID: 2932)
      • RobloxPlayerLauncher.exe (PID: 1408)
      • RobloxPlayerLauncher.exe (PID: 2788)
      • RobloxPlayerLauncher.exe (PID: 416)
      • MicrosoftEdgeUpdate.exe (PID: 2796)
      • MicrosoftEdgeUpdate.exe (PID: 2028)
      • MicrosoftEdgeUpdate.exe (PID: 340)
    • Reads settings of System Certificates

      • RobloxPlayerLauncher.exe (PID: 2932)
      • RobloxPlayerLauncher.exe (PID: 1408)
      • RobloxPlayerLauncher.exe (PID: 416)
      • RobloxPlayerLauncher.exe (PID: 2788)
      • MicrosoftEdgeUpdate.exe (PID: 2796)
      • MicrosoftEdgeUpdate.exe (PID: 2028)
      • MicrosoftEdgeUpdate.exe (PID: 340)
    • Application launched itself

      • RobloxPlayerLauncher.exe (PID: 2932)
      • RobloxPlayerLauncher.exe (PID: 416)
      • MicrosoftEdgeUpdate.exe (PID: 2028)
    • Process drops legitimate windows executable

      • MicrosoftEdgeWebview2Setup.exe (PID: 2432)
      • MicrosoftEdgeUpdate.exe (PID: 2596)
      • MicrosoftEdge_X64_109.0.1518.140.exe (PID: 1828)
      • setup.exe (PID: 792)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdate.exe (PID: 1980)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2104)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2492)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 2596)
  • INFO

    • Checks supported languages

      • RobloxPlayerLauncher.exe (PID: 2932)
      • RobloxPlayerLauncher.exe (PID: 1408)
      • RobloxPlayerLauncher.exe (PID: 416)
      • RobloxPlayerLauncher.exe (PID: 2788)
      • MicrosoftEdgeWebview2Setup.exe (PID: 2432)
      • MicrosoftEdgeUpdate.exe (PID: 2596)
      • MicrosoftEdgeUpdate.exe (PID: 1980)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2612)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2104)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2492)
      • MicrosoftEdgeUpdate.exe (PID: 2796)
      • MicrosoftEdgeUpdate.exe (PID: 684)
      • MicrosoftEdgeUpdate.exe (PID: 2028)
      • MicrosoftEdge_X64_109.0.1518.140.exe (PID: 1828)
      • setup.exe (PID: 792)
      • MicrosoftEdgeUpdate.exe (PID: 340)
    • Reads the machine GUID from the registry

      • RobloxPlayerLauncher.exe (PID: 2932)
      • RobloxPlayerLauncher.exe (PID: 1408)
      • RobloxPlayerLauncher.exe (PID: 416)
      • RobloxPlayerLauncher.exe (PID: 2788)
      • MicrosoftEdgeUpdate.exe (PID: 684)
      • MicrosoftEdgeUpdate.exe (PID: 2796)
      • MicrosoftEdgeUpdate.exe (PID: 2596)
      • MicrosoftEdgeUpdate.exe (PID: 2028)
      • MicrosoftEdgeUpdate.exe (PID: 340)
    • Reads the computer name

      • RobloxPlayerLauncher.exe (PID: 2932)
      • RobloxPlayerLauncher.exe (PID: 1408)
      • RobloxPlayerLauncher.exe (PID: 416)
      • MicrosoftEdgeUpdate.exe (PID: 2596)
      • RobloxPlayerLauncher.exe (PID: 2788)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2612)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2104)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2492)
      • MicrosoftEdgeUpdate.exe (PID: 2796)
      • MicrosoftEdgeUpdate.exe (PID: 1980)
      • MicrosoftEdgeUpdate.exe (PID: 684)
      • MicrosoftEdgeUpdate.exe (PID: 2028)
      • MicrosoftEdge_X64_109.0.1518.140.exe (PID: 1828)
      • setup.exe (PID: 792)
      • MicrosoftEdgeUpdate.exe (PID: 340)
    • Create files in a temporary directory

      • RobloxPlayerLauncher.exe (PID: 2932)
      • RobloxPlayerLauncher.exe (PID: 1408)
      • RobloxPlayerLauncher.exe (PID: 416)
      • RobloxPlayerLauncher.exe (PID: 2788)
      • MicrosoftEdgeWebview2Setup.exe (PID: 2432)
      • MicrosoftEdgeUpdate.exe (PID: 2596)
      • MicrosoftEdgeUpdate.exe (PID: 2796)
      • MicrosoftEdgeUpdate.exe (PID: 340)
    • Checks proxy server information

      • RobloxPlayerLauncher.exe (PID: 2932)
      • RobloxPlayerLauncher.exe (PID: 1408)
      • RobloxPlayerLauncher.exe (PID: 416)
      • RobloxPlayerLauncher.exe (PID: 2788)
      • MicrosoftEdgeUpdate.exe (PID: 2796)
      • MicrosoftEdgeUpdate.exe (PID: 340)
    • Creates files or folders in the user directory

      • RobloxPlayerLauncher.exe (PID: 2932)
      • RobloxPlayerLauncher.exe (PID: 1408)
      • RobloxPlayerLauncher.exe (PID: 416)
      • RobloxPlayerLauncher.exe (PID: 2788)
      • MicrosoftEdgeUpdate.exe (PID: 2596)
      • MicrosoftEdgeUpdate.exe (PID: 2028)
      • MicrosoftEdge_X64_109.0.1518.140.exe (PID: 1828)
      • setup.exe (PID: 792)
    • Process checks computer location settings

      • RobloxPlayerLauncher.exe (PID: 2932)
      • RobloxPlayerLauncher.exe (PID: 416)
    • Dropped object may contain TOR URL's

      • RobloxPlayerLauncher.exe (PID: 2932)
      • RobloxPlayerLauncher.exe (PID: 416)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 2796)
      • MicrosoftEdgeUpdate.exe (PID: 340)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2058:03:24 12:20:54+01:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 3735040
InitializedDataSize: 1435136
UninitializedDataSize: -
EntryPoint: 0x32fe22
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.6.2.21346
ProductVersionNumber: 1.6.2.21346
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Roblox Corporation
FileDescription: Roblox
FileVersion: 1, 6, 2, 6050658
LegalCopyright: Copyright © 2020 Roblox Corporation. All rights reserved.
OriginalFileName: Roblox.exe
ProductName: Roblox Bootstrapper
ProductVersion: 1, 6, 2, 6050658
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
16
Malicious processes
9
Suspicious processes
1

Behavior graph

Click at the process to see the details
start robloxplayerlauncher.exe robloxplayerlauncher.exe robloxplayerlauncher.exe robloxplayerlauncher.exe microsoftedgewebview2setup.exe no specs microsoftedgeupdate.exe no specs microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe microsoftedge_x64_109.0.1518.140.exe no specs setup.exe no specs microsoftedgeupdate.exe

Process information

PID
CMD
Path
Indicators
Parent process
340"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xNzEuMzkiIHNoZWxsX3ZlcnNpb249IjEuMy4xNzEuMzkiIGlzbWFjaGluZT0iMCIgc2Vzc2lvbmlkPSJ7QjVDNkE3RUEtNkQxNS00NEE5LUI0MTctMEI1NkJBRUUzQUUxfSIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiByZXF1ZXN0aWQ9InszNDQwMTc4RC1BMkZCLTQwOEMtQTE0NS0wNTlBMEM0RDg1NkV9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iNCIgcGh5c21lbW9yeT0iNCIgZGlza190eXBlPSIwIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEuNzYwMS4wIiBzcD0iU2VydmljZSBQYWNrIDEiIGFyY2g9Ing2NCIgcHJvZHVjdF90eXBlPSI0OCIgaXNfd2lwPSIwIi8-PG9lbSBwcm9kdWN0X21hbnVmYWN0dXJlcj0iREVMTCIgcHJvZHVjdF9uYW1lPSJERUxMIi8-PGV4cCBldGFnPSImcXVvdDtyNDUydDErazJUZ3EvSFh6anZGTkJSaG9wQldSOXNialh4cWVVREg5dVgwPSZxdW90OyIvPjxhcHAgYXBwaWQ9IntGMzAxNzIyNi1GRTJBLTQyOTUtOEJERi0wMEMzQTlBN0U0QzV9IiB2ZXJzaW9uPSIiIG5leHR2ZXJzaW9uPSIxMDkuMC4xNTE4LjE0MCIgbGFuZz0iZW4iIGJyYW5kPSIiIGNsaWVudD0iIiBleHBlcmltZW50cz0iY29uc2VudD1mYWxzZSIgaW5zdGFsbGFnZT0iLTEiIGluc3RhbGxkYXRlPSItMSI-PHVwZGF0ZWNoZWNrLz48ZXZlbnQgZXZlbnR0eXBlPSI5IiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSIyNDEzNTk0NzI2NSIvPjxldmVudCBldmVudHR5cGU9IjUiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIHN5c3RlbV91cHRpbWVfdGlja3M9IjI0MTM1OTg2MzI4Ii8-PGV2ZW50IGV2ZW50dHlwZT0iMSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iMjQ5NzMwOTU3MDMiIHNvdXJjZV91cmxfaW5kZXg9IjAiIGRvd25sb2FkZXI9ImJpdHMiIHVybD0iaHR0cDovL21zZWRnZS5mLnRsdS5kbC5kZWxpdmVyeS5tcC5taWNyb3NvZnQuY29tL2ZpbGVzdHJlYW1pbmdzZXJ2aWNlL2ZpbGVzLzBjNDA4NGYzLTFiZWQtNDI0Ni1iOGVkLTIwNmNjYmU2MGUzYz9QMT0xNzAyNjY3NDMxJmFtcDtQMj00MDQmYW1wO1AzPTImYW1wO1A0PU96bng0NEIwd3B4RVl1MDdVMkU4TXpETkhUWW1iSmFja0ZYOHJYcFIybDAyb0NNbiUyZkZMNUFkT05iSXNYN0VrM2lIZyUyYkslMmJ2UUNoVEUlMmJwUWdJdEI5eVElM2QlM2QiIHNlcnZlcl9pcF9oaW50PSIiIGNkbl9jaWQ9Ii0xIiBjZG5fY2NjPSIiIGNkbl9tc2VkZ2VfcmVmPSIiIGNkbl9henVyZV9yZWZfb3JpZ2luX3NoaWVsZD0iIiBjZG5fY2FjaGU9IiIgY2RuX3AzcD0iIiBkb3dubG9hZGVkPSIxNDA2OTYwMDgiIHRvdGFsPSIxNDA2OTYwMDgiIGRvd25sb2FkX3RpbWVfbXM9Ijc4NTkwIi8-PGV2ZW50IGV2ZW50dHlwZT0iMSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iMjQ5NzMzMzk4NDMiIHNvdXJjZV91cmxfaW5kZXg9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSI2IiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSIyNTAwMTQxNjAxNSIvPjxldmVudCBldmVudHR5cGU9IjIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjE5NjYwOCIgc3lzdGVtX3VwdGltZV90aWNrcz0iMjUxOTc5Nzg1MTUiIHNvdXJjZV91cmxfaW5kZXg9IjAiIHVwZGF0ZV9jaGVja190aW1lX21zPSIzNTgiIGRvd25sb2FkX3RpbWVfbXM9IjgzNzMzIiBkb3dubG9hZGVkPSIxNDA2OTYwMDgiIHRvdGFsPSIxNDA2OTYwMDgiIHBhY2thZ2VfY2FjaGVfcmVzdWx0PSIwIiBpbnN0YWxsX3RpbWVfbXM9IjE5NjUyIi8-PC9hcHA-PC9yZXF1ZXN0PgC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.171.39
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
416"C:\Users\admin\AppData\Local\Temp\RBX-AE6CD5A0\RobloxPlayerLauncher.exe" C:\Users\admin\AppData\Local\Temp\RBX-AE6CD5A0\RobloxPlayerLauncher.exe
RobloxPlayerLauncher.exe
User:
admin
Company:
Roblox Corporation
Integrity Level:
MEDIUM
Description:
Roblox
Exit code:
0
Version:
1, 6, 1, 6050656
Modules
Images
c:\users\admin\appdata\local\temp\rbx-ae6cd5a0\robloxplayerlauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
684"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /handoff "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=false" /installsource otherinstallcmd /sessionid "{B5C6A7EA-6D15-44A9-B417-0B56BAEE3AE1}" /silentC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.171.39
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
792"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{3080C04C-C96B-477D-B945-FDDAAB8B66AA}\EDGEMITMP_F1B1F.tmp\setup.exe" --install-archive="C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{3080C04C-C96B-477D-B945-FDDAAB8B66AA}\MicrosoftEdge_X64_109.0.1518.140.exe" --msedgewebview --verbose-logging --do-not-launch-msedge --user-levelC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{3080C04C-C96B-477D-B945-FDDAAB8B66AA}\EDGEMITMP_F1B1F.tmp\setup.exeMicrosoftEdge_X64_109.0.1518.140.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
109.0.1518.140
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{3080c04c-c96b-477d-b945-fddaab8b66aa}\edgemitmp_f1b1f.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
1408C:\Users\admin\Downloads\RobloxPlayerLauncher.exe --crashpad --no-rate-limit --database=C:\Users\admin\AppData\Local\Temp\crashpad_roblox --metrics-dir=C:\Users\admin\AppData\Local\Temp\crashpad_roblox --url=https://uploads.backtrace.rbx.com/post --annotation=RobloxChannel=production --annotation=RobloxGitHash=1264a5bf4500fc8832e585558bd23fbd2002291f --annotation=UploadAttachmentKiloByteLimit=100 --annotation=UploadPercentage=100 --annotation=format=minidump --annotation=token=a2440b0bfdada85f34d79b43839f2b49ea6bba474bd7d126e844bc119271a1c3 --initial-client-data=0x540,0x544,0x548,0x514,0x550,0x1b7b690,0x1b7b6a0,0x1b7b6b0C:\Users\admin\Downloads\RobloxPlayerLauncher.exe
RobloxPlayerLauncher.exe
User:
admin
Company:
Roblox Corporation
Integrity Level:
MEDIUM
Description:
Roblox
Exit code:
0
Version:
1, 6, 2, 6050658
Modules
Images
c:\users\admin\downloads\robloxplayerlauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
1828"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{3080C04C-C96B-477D-B945-FDDAAB8B66AA}\MicrosoftEdge_X64_109.0.1518.140.exe" --msedgewebview --verbose-logging --do-not-launch-msedge --user-levelC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{3080C04C-C96B-477D-B945-FDDAAB8B66AA}\MicrosoftEdge_X64_109.0.1518.140.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
109.0.1518.140
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{3080c04c-c96b-477d-b945-fddaab8b66aa}\microsoftedge_x64_109.0.1518.140.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1980"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserverC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.171.39
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2028"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" -EmbeddingC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.171.39
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2104"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.171.39\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.171.39\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.171.39
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.171.39\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2432MicrosoftEdgeWebview2Setup.exe /silent /installC:\Users\admin\AppData\Local\Roblox\Versions\version-0e99014accac42d6\WebView2RuntimeInstaller\MicrosoftEdgeWebview2Setup.exeRobloxPlayerLauncher.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Exit code:
0
Version:
1.3.171.39
Modules
Images
c:\users\admin\appdata\local\roblox\versions\version-0e99014accac42d6\webview2runtimeinstaller\microsoftedgewebview2setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
Total events
11 831
Read events
9 011
Write events
2 788
Delete events
32

Modification events

(PID) Process:(2932) RobloxPlayerLauncher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2932) RobloxPlayerLauncher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2932) RobloxPlayerLauncher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2932) RobloxPlayerLauncher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000C1000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2932) RobloxPlayerLauncher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2932) RobloxPlayerLauncher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2932) RobloxPlayerLauncher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2932) RobloxPlayerLauncher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2932) RobloxPlayerLauncher.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\15A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1408) RobloxPlayerLauncher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
Executable files
215
Suspicious files
89
Text files
12
Unknown types
0

Dropped files

PID
Process
Filename
Type
1408RobloxPlayerLauncher.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HQYU0XHJ\BatchIncrement[1].jsonbinary
MD5:BEDBF7D7D69748886E9B48F45C75FBBE
SHA256:B4A55CFD050F4A62B1C4831CA0AB6FFADDE1FE1C3F583917EADE12F8C6726F61
2932RobloxPlayerLauncher.exeC:\Users\admin\AppData\Local\Temp\TarCCB2.tmpbinary
MD5:9C0C641C06238516F27941AA1166D427
SHA256:4276AF3669A141A59388BC56A87F6614D9A9BDDDF560636C264219A7EB11256F
2932RobloxPlayerLauncher.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:E38388C44AE6E4EEB91F6CAB18B6D565
SHA256:52ED4361AA2D13CF72407528EF117E30E18CADB46C4A84309A460BAA644A8EC4
2932RobloxPlayerLauncher.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
2932RobloxPlayerLauncher.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BDW1XBVN\BatchIncrement[1].jsonbinary
MD5:BEDBF7D7D69748886E9B48F45C75FBBE
SHA256:B4A55CFD050F4A62B1C4831CA0AB6FFADDE1FE1C3F583917EADE12F8C6726F61
2932RobloxPlayerLauncher.exeC:\Users\admin\AppData\Local\Temp\crashpad_roblox\settings.datbinary
MD5:486C9FEEFA527085F788BF75F6626623
SHA256:EA70C86A62BB1D134BB3087C3382525CAD57388DEEAAA676FFF7975FE9AA2B41
2932RobloxPlayerLauncher.exeC:\Users\admin\AppData\Local\Temp\CabCCB1.tmpcompressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
2932RobloxPlayerLauncher.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2U1WPAC\version-0e99014accac42d6-rbxBootstrapperPkgManifest[1].txttext
MD5:682F00B799F7C7EE0FA8DC9630F73251
SHA256:EA41A3FE84681950164DD02D561F344A65F0CEC3FAD621C6D1312287522B6E1D
2932RobloxPlayerLauncher.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HQYU0XHJ\RobloxPlayerLauncher[1].exeexecutable
MD5:F5E20C9636FB21FA1743C7E5A629F889
SHA256:58E0D04431321FE73E08ED9060F16DDEB724BDF1DCB9B0E49C86D05F22B3013B
2932RobloxPlayerLauncher.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HQYU0XHJ\WindowsPlayer[1].jsonbinary
MD5:4F82D255113DEEF282B5DE1E7772193D
SHA256:7AF6BDB57415F54C1C44A0E9D3E644451BF0F7D2E70D164C3FD170FBC6CDAD83
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
28
DNS requests
21
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2932
RobloxPlayerLauncher.exe
GET
200
2.22.242.122:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?ea342161508579d6
unknown
compressed
65.2 Kb
unknown
884
svchost.exe
HEAD
200
2.23.154.73:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/0c4084f3-1bed-4246-b8ed-206ccbe60e3c?P1=1702667431&P2=404&P3=2&P4=Oznx44B0wpxEYu07U2E8MzDNHTYmbJackFX8rXpR2l02oCMn%2fFL5AdONbIsX7Ek3iHg%2bK%2bvQChTE%2bpQgItB9yQ%3d%3d
unknown
unknown
2932
RobloxPlayerLauncher.exe
GET
200
2.22.242.122:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/1F24C630CDA418EF2069FFAD4FDD5F463A1B69AA.crt?15fc48b15545a490
unknown
binary
546 b
unknown
884
svchost.exe
GET
200
2.23.154.73:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/0c4084f3-1bed-4246-b8ed-206ccbe60e3c?P1=1702667431&P2=404&P3=2&P4=Oznx44B0wpxEYu07U2E8MzDNHTYmbJackFX8rXpR2l02oCMn%2fFL5AdONbIsX7Ek3iHg%2bK%2bvQChTE%2bpQgItB9yQ%3d%3d
unknown
executable
134 Mb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown
2932
RobloxPlayerLauncher.exe
23.60.195.90:443
clientsettingscdn.roblox.com
AKAMAI-AS
DE
unknown
2932
RobloxPlayerLauncher.exe
128.116.21.4:443
ephemeralcounters.api.roblox.com
ROBLOX-PRODUCTION
US
unknown
1408
RobloxPlayerLauncher.exe
23.60.195.90:443
clientsettingscdn.roblox.com
AKAMAI-AS
DE
unknown
1408
RobloxPlayerLauncher.exe
128.116.21.4:443
ephemeralcounters.api.roblox.com
ROBLOX-PRODUCTION
US
unknown
2932
RobloxPlayerLauncher.exe
205.234.175.102:443
setup.rbxcdn.com
CACHENETWORKS
US
unknown
2932
RobloxPlayerLauncher.exe
2.22.242.122:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
clientsettingscdn.roblox.com
  • 23.60.195.90
whitelisted
ephemeralcounters.api.roblox.com
  • 128.116.21.4
whitelisted
setup.rbxcdn.qq.com
  • 0.0.0.1
unknown
clientsettingscdn.roblox.qq.com
  • 0.0.0.1
unknown
setup.rbxcdn.com
  • 205.234.175.102
whitelisted
setup-ak.rbxcdn.com
  • 2.16.164.129
  • 2.16.164.82
whitelisted
setup-ll.rbxcdn.com
unknown
setup-cfly.rbxcdn.com
  • 205.234.175.102
unknown
setup-hw.rbxcdn.com
unknown
ctldl.windowsupdate.com
  • 2.22.242.122
  • 2.22.242.121
whitelisted

Threats

PID
Process
Class
Message
884
svchost.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
RobloxPlayerLauncher.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.