| File name: | RobloxPlayerInstaller.exe |
| Full analysis: | https://app.any.run/tasks/e8fb313f-e1ff-4e08-a86b-db6fd62b1870 |
| Verdict: | Malicious activity |
| Analysis date: | February 23, 2025, 17:21:35 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | 261A1CC1784FAD7C8FF2E9B6F6406930 |
| SHA1: | 5985A397AE1711E893E373DB4B1DC3C1E8B5F5D6 |
| SHA256: | 069D0E4206BDE17A8D80F1F79AAA8B48F9E3BC2385F57A8377AFC8B00444F8CF |
| SSDEEP: | 98304:aCs0hUc7gyYfSWonjR7ZEBnFrXq0dNaRrXzZR8NOxxynNndwdPXORvOYo7o9N+2Y:xRXR4Rxpt3W |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2000:02:01 10:04:55+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.29 |
| CodeSize: | 4833792 |
| InitializedDataSize: | 2924032 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x4397c5 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.6.0.57108 |
| ProductVersionNumber: | 1.6.0.57108 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Roblox Corporation |
| FileDescription: | Roblox |
| FileVersion: | 1, 6, 0, 6610708 |
| LegalCopyright: | Copyright © 2020 Roblox Corporation. All rights reserved. |
| OriginalFileName: | Roblox.exe |
| ProductName: | Roblox Bootstrapper |
| ProductVersion: | 1, 6, 0, 6610708 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 372 | "C:\Users\admin\AppData\Local\Roblox\Versions\version-302fe31805ab4542\RobloxPlayerBeta.exe" -app -clientLaunchTimeEpochMs 0 -isInstallerLaunch 1064 | C:\Users\admin\AppData\Local\Roblox\Versions\version-302fe31805ab4542\RobloxPlayerBeta.exe | RobloxPlayerInstaller.exe | ||||||||||||
User: admin Company: Roblox Corporation Integrity Level: MEDIUM Description: Roblox Game Client Exit code: 3221225477 Version: 0, 661, 0, 6610708 Modules
| |||||||||||||||
| 736 | "C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xNzEuMzkiIHNoZWxsX3ZlcnNpb249IjEuMy4xNzEuMzkiIGlzbWFjaGluZT0iMCIgc2Vzc2lvbmlkPSJ7Mzc4MDBDNjgtNUNGRS00ODI1LThFQTUtNDM3NUZFNzYyRTgwfSIgdXNlcmlkPSJ7QUQ2NzM0QzQtMjY2Qy00NjU2LUExRjgtMjIzM0U4NUU2NDI2fSIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiByZXF1ZXN0aWQ9InsxOTlDREZFMS05NjdCLTQ5RDktQkMxNC1GMTQwRUExODVCNkV9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iNCIgcGh5c21lbW9yeT0iNCIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE5MDQ1LjQwNDYiIHNwPSIiIGFyY2g9Ing2NCIgcHJvZHVjdF90eXBlPSI0OCIgaXNfd2lwPSIwIi8-PG9lbSBwcm9kdWN0X21hbnVmYWN0dXJlcj0iREVMTCIgcHJvZHVjdF9uYW1lPSJERUxMIi8-PGV4cCBldGFnPSImcXVvdDtyNDUydDErazJUZ3EvSFh6anZGTkJSaG9wQldSOXNialh4cWVVREg5dVgwPSZxdW90OyIvPjxhcHAgYXBwaWQ9IntGMzAxNzIyNi1GRTJBLTQyOTUtOEJERi0wMEMzQTlBN0U0QzV9IiB2ZXJzaW9uPSIiIG5leHR2ZXJzaW9uPSIxMzMuMC4zMDY1LjgyIiBsYW5nPSJlbiIgYnJhbmQ9IiIgY2xpZW50PSIiIGV4cGVyaW1lbnRzPSJjb25zZW50PWZhbHNlIiBpbnN0YWxsYWdlPSItMSIgaW5zdGFsbGRhdGU9Ii0xIj48dXBkYXRlY2hlY2svPjxldmVudCBldmVudHR5cGU9IjkiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIHN5c3RlbV91cHRpbWVfdGlja3M9IjEzMTIzMzA4MjA1IiBkb25lX2JlZm9yZV9vb2JlX2NvbXBsZXRlPSIwIi8-PGV2ZW50IGV2ZW50dHlwZT0iNSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iMTMxMjMzNzg3MjgiIGRvbmVfYmVmb3JlX29vYmVfY29tcGxldGU9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSIxIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSIxMzU5MTQ0MzkxOCIgc291cmNlX3VybF9pbmRleD0iMCIgZG9uZV9iZWZvcmVfb29iZV9jb21wbGV0ZT0iMCIgZG93bmxvYWRlcj0iYml0cyIgdXJsPSJodHRwOi8vbXNlZGdlLmYudGx1LmRsLmRlbGl2ZXJ5Lm1wLm1pY3Jvc29mdC5jb20vZmlsZXN0cmVhbWluZ3NlcnZpY2UvZmlsZXMvYzYwNDRjYjktZjNkMy00OTZkLWE3MGQtYWU5NTRjZDRhYmQ5P1AxPTE3NDA5MzYxNDgmYW1wO1AyPTQwNCZhbXA7UDM9MiZhbXA7UDQ9ajdieTJJbXZIOVdRdnNsbkVvTnR6UHdxRFFWVHlpNW0lMmJqRkRLdWI5NDNZdWJBZyUyYlhmT01BTXBPdTFnR25obFNyZkNNMXhTZ0JKWm1Ma3ZxM0xSJTJmaHclM2QlM2QiIHNlcnZlcl9pcF9oaW50PSIiIGNkbl9jaWQ9Ii0xIiBjZG5fY2NjPSIiIGNkbl9tc2VkZ2VfcmVmPSIiIGNkbl9henVyZV9yZWZfb3JpZ2luX3NoaWVsZD0iIiBjZG5fY2FjaGU9IiIgY2RuX3AzcD0iIiBkb3dubG9hZGVkPSIxNzg1ODEwNzIiIHRvdGFsPSIxNzg1ODEwNzIiIGRvd25sb2FkX3RpbWVfbXM9IjQyNjEyIi8-PGV2ZW50IGV2ZW50dHlwZT0iMSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iMTM1OTE2Mjc5MjciIHNvdXJjZV91cmxfaW5kZXg9IjAiIGRvbmVfYmVmb3JlX29vYmVfY29tcGxldGU9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSI2IiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSIxMzYxMzA4MTQ2NCIgZG9uZV9iZWZvcmVfb29iZV9jb21wbGV0ZT0iMCIvPjxldmVudCBldmVudHR5cGU9IjIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjE5Njc1NyIgc3lzdGVtX3VwdGltZV90aWNrcz0iMTQwNTE4NzUxMjEiIHNvdXJjZV91cmxfaW5kZXg9IjAiIGRvbmVfYmVmb3JlX29vYmVfY29tcGxldGU9IjAiIHVwZGF0ZV9jaGVja190aW1lX21zPSIyMTkiIGRvd25sb2FkX3RpbWVfbXM9IjQ2ODIwIiBkb3dubG9hZGVkPSIxNzg1ODEwNzIiIHRvdGFsPSIxNzg1ODEwNzIiIHBhY2thZ2VfY2FjaGVfcmVzdWx0PSIwIiBpbnN0YWxsX3RpbWVfbXM9IjQzODc2Ii8-PC9hcHA-PC9yZXF1ZXN0Pg | C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe | MicrosoftEdgeUpdate.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Update Exit code: 0 Version: 1.3.171.39 Modules
| |||||||||||||||
| 1064 | "C:\Users\admin\AppData\Local\Temp\RobloxPlayerInstaller.exe" | C:\Users\admin\AppData\Local\Temp\RobloxPlayerInstaller.exe | explorer.exe | ||||||||||||
User: admin Company: Roblox Corporation Integrity Level: MEDIUM Description: Roblox Exit code: 0 Version: 1, 6, 0, 6610708 Modules
| |||||||||||||||
| 2084 | C:\Users\admin\AppData\Local\Roblox\Versions\version-302fe31805ab4542\\RobloxCrashHandler.exe --no-rate-limit --crashCounter Win-ROBLOXPlayer-Crash --baseUrl http://www.roblox.com/ --attachment=attachment_0.661.0.6610708_20250223T172405Z_Player_CC557_last.log=C:\Users\admin\AppData\Local\Roblox\logs\0.661.0.6610708_20250223T172405Z_Player_CC557_last.log --database=C:\Users\admin\AppData\Local\Roblox\logs\crashes --metrics-dir=C:\Users\admin\AppData\Local\Roblox\logs\crashes --url=https://upload.crashes.rbxinfra.com/post?format=minidump --annotation=AppVersion=0.661.0.6610708 --annotation=BaseUrl=http://www.roblox.com/ "--annotation=CPUMake=Intel(R) Core(TM) i5-6400 CPU @ 2.70GHz" --annotation=EnableSessionEndCallback=true --annotation=Format=minidump --annotation=OSPlatform=Win32 "--annotation=OSVersion=Windows 10 - PlatformId 2, Version 10.0, Build 19045" --annotation=PlatformId=2 --annotation=RobloxChannel=production --annotation=RobloxGitHash=f2a7921f38a9f29ebb3a546c4878edc7825e0a95 --annotation=RobloxProduct=RobloxPlayer --annotation=TotalMemory=4289146880 --annotation=UniqueId=4399272261555644371 --annotation=UploadAttachmentKiloByteLimit=1000 --annotation=UseCrashpad=True --initial-client-data=0x86c,0x870,0x874,0x62c,0x838,0x7ff6f618e508,0x7ff6f618e520,0x7ff6f618e538 | C:\Users\admin\AppData\Local\Roblox\Versions\version-302fe31805ab4542\RobloxCrashHandler.exe | RobloxPlayerBeta.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3220 | "C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exe" -ServerName:App.AppXbdkk0yrkwpcgeaem8zk81k8py1eaahny.mca | C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exe | — | svchost.exe | |||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 3688 | "C:\Windows\System32\GameBarPresenceWriter.exe" -ServerName:Windows.Gaming.GameBar.Internal.PresenceWriterServer | C:\Windows\System32\GameBarPresenceWriter.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Gamebar Presence Writer Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3700 | C:\Users\admin\AppData\Local\Roblox\Versions\version-302fe31805ab4542\\RobloxCrashHandler.exe --no-rate-limit --crashCounter Win-ROBLOXPlayer-Crash --baseUrl http://www.roblox.com/ --attachment=attachment_0.661.0.6610708_20250223T172551Z_Player_F0637_last.log=C:\Users\admin\AppData\Local\Roblox\logs\0.661.0.6610708_20250223T172551Z_Player_F0637_last.log --database=C:\Users\admin\AppData\Local\Roblox\logs\crashes --metrics-dir=C:\Users\admin\AppData\Local\Roblox\logs\crashes --url=https://upload.crashes.rbxinfra.com/post?format=minidump --annotation=AppVersion=0.661.0.6610708 --annotation=BaseUrl=http://www.roblox.com/ "--annotation=CPUMake=Intel(R) Core(TM) i5-6400 CPU @ 2.70GHz" --annotation=EnableSessionEndCallback=true --annotation=Format=minidump --annotation=OSPlatform=Win32 "--annotation=OSVersion=Windows 10 - PlatformId 2, Version 10.0, Build 19045" --annotation=PlatformId=2 --annotation=RobloxChannel=production --annotation=RobloxGitHash=f2a7921f38a9f29ebb3a546c4878edc7825e0a95 --annotation=RobloxProduct=RobloxPlayer --annotation=TotalMemory=4289146880 --annotation=UniqueId=1130530998980308722 --annotation=UploadAttachmentKiloByteLimit=1000 --annotation=UseCrashpad=True --initial-client-data=0x508,0x644,0x638,0x728,0x808,0x7ff6f618e508,0x7ff6f618e520,0x7ff6f618e538 | C:\Users\admin\AppData\Local\Roblox\Versions\version-302fe31805ab4542\RobloxCrashHandler.exe | RobloxPlayerBeta.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 5472 | "C:\Users\admin\AppData\Local\Roblox\Versions\version-302fe31805ab4542\RobloxPlayerBeta.exe" | C:\Users\admin\AppData\Local\Roblox\Versions\version-302fe31805ab4542\RobloxPlayerBeta.exe | explorer.exe | ||||||||||||
User: admin Company: Roblox Corporation Integrity Level: MEDIUM Description: Roblox Game Client Version: 0, 661, 0, 6610708 Modules
| |||||||||||||||
| 6476 | MicrosoftEdgeWebview2Setup.exe /silent /install | C:\Users\admin\AppData\Local\Roblox\Versions\version-302fe31805ab4542\WebView2RuntimeInstaller\MicrosoftEdgeWebview2Setup.exe | RobloxPlayerInstaller.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Update Setup Exit code: 0 Version: 1.3.171.39 Modules
| |||||||||||||||
| 6504 | C:\Users\admin\AppData\Local\Temp\EUF63A.tmp\MicrosoftEdgeUpdate.exe /silent /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers" | C:\Users\admin\AppData\Local\Temp\EUF63A.tmp\MicrosoftEdgeUpdate.exe | MicrosoftEdgeWebview2Setup.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Update Exit code: 0 Version: 1.3.171.39 Modules
| |||||||||||||||
| (PID) Process: | (1064) RobloxPlayerInstaller.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\ProtocolExecute\roblox-studio |
| Operation: | write | Name: | WarnOnOpen |
Value: 0 | |||
| (PID) Process: | (1064) RobloxPlayerInstaller.exe | Key: | HKEY_CLASSES_ROOT\roblox-studio |
| Operation: | write | Name: | URL Protocol |
Value: | |||
| (PID) Process: | (1064) RobloxPlayerInstaller.exe | Key: | HKEY_CLASSES_ROOT\roblox-studio\shell\open\command |
| Operation: | write | Name: | version |
Value: version-0f776bc9fa9f4904 | |||
| (PID) Process: | (6504) MicrosoftEdgeUpdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate |
| Operation: | delete value | Name: | eulaaccepted |
Value: | |||
| (PID) Process: | (6504) MicrosoftEdgeUpdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate |
| Operation: | write | Name: | edgeupdate_task_name_c |
Value: MicrosoftEdgeUpdateTaskUserS-1-5-21-1693682860-607145093-2874071422-1001Core{E88B1088-3470-40DA-A643-0B24AA68918B} | |||
| (PID) Process: | (6504) MicrosoftEdgeUpdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate |
| Operation: | write | Name: | edgeupdate_task_name_ua |
Value: MicrosoftEdgeUpdateTaskUserS-1-5-21-1693682860-607145093-2874071422-1001UA{1DCC5450-8A8A-4718-A708-480FDDBE2784} | |||
| (PID) Process: | (6504) MicrosoftEdgeUpdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate |
| Operation: | write | Name: | path |
Value: C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe | |||
| (PID) Process: | (6504) MicrosoftEdgeUpdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate |
| Operation: | write | Name: | UninstallCmdLine |
Value: "C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /uninstall | |||
| (PID) Process: | (6504) MicrosoftEdgeUpdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A} |
| Operation: | write | Name: | pv |
Value: 1.3.171.39 | |||
| (PID) Process: | (6504) MicrosoftEdgeUpdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A} |
| Operation: | write | Name: | name |
Value: Microsoft Edge Update | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1064 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox\Roblox Studio.lnk | binary | |
MD5:3E268564A80BEEF540389CDA571DCB9C | SHA256:B431BB58200797C76A0F3082C1AE68D1C8F62A08351498CDB183E7ED30365C78 | |||
| 1064 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Local\Roblox\Versions\RobloxStudioInstaller.exe | executable | |
MD5:FD8B528288F80FE8A367D74A04C5AD76 | SHA256:C2D11D8B0DE81E2621773BF61ECF096C5F9EFB168B477EAA5A8E3CB8D5179AAC | |||
| 1064 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\15bd216e6fae9ca480c21db01ce4ae3b | compressed | |
MD5:15BD216E6FAE9CA480C21DB01CE4AE3B | SHA256:DD788F4010754D48447E50C1522B5A1E8CCF4EA457C7D80FBA4F6F6B7F24633F | |||
| 1064 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Local\Roblox\logs\cacert.pem | text | |
MD5:6CED45AE0FCB6620235271F2C6F41411 | SHA256:AD64CF840A0FCE7924AC5F8A4F6900BFE73709A5A61031404A213AB563C286D8 | |||
| 1064 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\32622161783a33a229827a2a0261cc16 | compressed | |
MD5:32622161783A33A229827A2A0261CC16 | SHA256:631125E9AB228CCC5CA7CC723EABC683BAFA245F2E63B9FB23A55073DF017C12 | |||
| 1064 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Local\Temp\Roblox\http\RBXE098D547F461414AAFF5335C72CCE5E0 | binary | |
MD5:A879A7B2898C2ECB5106B28B502615FF | SHA256:FCD9E53D57CC69EA7E9AB627D37B1E6BDD3998A4096AF2142F8ECD084DD1A388 | |||
| 1064 | RobloxPlayerInstaller.exe | C:\Users\admin\Desktop\Roblox Studio.lnk | binary | |
MD5:177D84C50CC5892AA7AEA2113782EE20 | SHA256:FE02491816BA20EFF7FFD488C797D5071F1309779599CDB46012767D081AD2E1 | |||
| 1064 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\4ebb8902e12a56a39b39e9537869ecd2 | compressed | |
MD5:4EBB8902E12A56A39B39E9537869ECD2 | SHA256:33EA908D14181F69DE8A9FA838B97FE126CA497265D121B626907C394DC2A8B4 | |||
| 1064 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\1d0390337d1a4a58e5514be1a9481ad6 | compressed | |
MD5:1D0390337D1A4A58E5514BE1A9481AD6 | SHA256:C79F0EEB2BCA4905C585C50333DB3C6F727A554F5DB82E64948F93668FBC18AA | |||
| 1064 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Local\Temp\Roblox\http\8913724486d5e3c463c493b25346ca31 | binary | |
MD5:A879A7B2898C2ECB5106B28B502615FF | SHA256:FCD9E53D57CC69EA7E9AB627D37B1E6BDD3998A4096AF2142F8ECD084DD1A388 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | GET | 200 | 95.101.54.122:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 95.101.54.122:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5064 | SearchApp.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
3260 | backgroundTaskHost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
6332 | SIHClient.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
6784 | svchost.exe | HEAD | 200 | 199.232.214.172:80 | http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/c6044cb9-f3d3-496d-a70d-ae954cd4abd9?P1=1740936148&P2=404&P3=2&P4=j7by2ImvH9WQvslnEoNtzPwqDQVTyi5m%2bjFDKub943YubAg%2bXfOMAMpOu1gGnhlSrfCM1xSgBJZmLkvq3LR%2fhw%3d%3d | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4652 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 95.101.54.122:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 95.101.54.122:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 2.23.246.101:80 | www.microsoft.com | Ooredoo Q.S.C. | QA | whitelisted |
— | — | 2.23.246.101:80 | www.microsoft.com | Ooredoo Q.S.C. | QA | whitelisted |
1064 | RobloxPlayerInstaller.exe | 128.116.123.3:443 | ecsv2.roblox.com | ROBLOX-PRODUCTION | US | whitelisted |
1064 | RobloxPlayerInstaller.exe | 52.222.236.86:443 | clientsettingscdn.roblox.com | AMAZON-02 | US | whitelisted |
1064 | RobloxPlayerInstaller.exe | 95.101.54.210:443 | setup.rbxcdn.com | Akamai International B.V. | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
ecsv2.roblox.com |
| whitelisted |
clientsettingscdn.roblox.com |
| whitelisted |
setup.rbxcdn.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6784 | svchost.exe | Misc activity | ET INFO Packed Executable Download |
Process | Message |
|---|---|
RobloxPlayerInstaller.exe | WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
|
RobloxPlayerBeta.exe | 2025-02-23T17:24:05.443Z,0.443437,11b8,6,Warning [FLog::RobloxStarter] Starting module: Network |
RobloxPlayerBeta.exe | |
RobloxPlayerBeta.exe | 2025-02-23T17:24:05.445Z,0.445448,11b8,6,Warning [FLog::RobloxStarterNetworkStarterModule] userAgent: Roblox/WinInetRobloxApp/0.661.0.6610708 (GlobalDist; RobloxDirectDownload) |
RobloxPlayerBeta.exe | |
RobloxPlayerBeta.exe | 2025-02-23T17:24:05.446Z,0.446453,11b8,6,Warning [FLog::RobloxStarter] Roblox stage ReadyForFlagFetch completed |
RobloxPlayerBeta.exe | |
RobloxPlayerBeta.exe | 2025-02-23T17:24:05.447Z,0.447458,11b8,6,Info [FLog::UpdateController] UpdateController: versionQueryUrl: https://clientsettingscdn.roblox.com/v2/client-version/WindowsPlayer |
RobloxPlayerBeta.exe | |
RobloxPlayerBeta.exe | 2025-02-23T17:24:05.448Z,0.448464,11b8,6,Info [FLog::UpdateController] WindowsUpdateController: updaterFullPath: C:\Users\admin\AppData\Local\Roblox\Versions\version-302fe31805ab4542\RobloxPlayerInstaller.exe |