download:

/install/client/latestrelease/Roblox%20Kurdistan.exe

Full analysis: https://app.any.run/tasks/06d1920d-c62f-4938-ae45-bf75e35ba643
Verdict: Malicious activity
Analysis date: May 23, 2026, 02:53:38
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
roblox
arch-scr
arch-doc
arch-exec
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

3260E488781E8C2CC6D91936F1D412B5

SHA1:

1FAB08E9C60B4343D2135B7644E6FD6F136E119B

SHA256:

126DE0B8FBCB55D456BD5EF538C48F5AB42AC3EE68AEEABACD559235BCF89D94

SSDEEP:

98304:7s0V45lKAPWR6J5aXcs6XQHxgmw1P+Ug/W7aBbuwNDPLt8p+XeXSHJNqOplvRuhr:v4eBLoG9c

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • MicrosoftEdgeWebview2Setup.exe (PID: 2016)
      • MicrosoftEdgeUpdate.exe (PID: 2100)
      • MicrosoftEdgeUpdate.exe (PID: 7600)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 1176)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5224)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2156)
      • MicrosoftEdgeUpdate.exe (PID: 5304)
      • MicrosoftEdgeUpdate.exe (PID: 6836)
      • MicrosoftEdgeUpdate.exe (PID: 4488)
      • MicrosoftEdge_X64_148.0.3967.83.exe (PID: 2420)
      • setup.exe (PID: 6432)
    • Changes the autorun value in the registry

      • MicrosoftEdgeUpdate.exe (PID: 2100)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Roblox%20Kurdistan.exe (PID: 2576)
      • MicrosoftEdgeWebview2Setup.exe (PID: 2016)
      • MicrosoftEdgeUpdate.exe (PID: 2100)
      • MicrosoftEdge_X64_148.0.3967.83.exe (PID: 2420)
      • setup.exe (PID: 6432)
    • Changes default file association

      • Roblox%20Kurdistan.exe (PID: 2576)
    • Silent install from TEMP directory

      • MicrosoftEdgeWebview2Setup.exe (PID: 2016)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeUpdate.exe (PID: 2100)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 2100)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 1176)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5224)
      • MicrosoftEdgeUpdate.exe (PID: 7600)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2156)
    • Searches for installed software

      • setup.exe (PID: 6432)
  • INFO

    • Checks supported languages

      • Roblox%20Kurdistan.exe (PID: 2576)
      • MicrosoftEdgeWebview2Setup.exe (PID: 2016)
      • MicrosoftEdgeUpdate.exe (PID: 2100)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 1176)
      • MicrosoftEdgeUpdate.exe (PID: 7600)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5224)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2156)
      • MicrosoftEdgeUpdate.exe (PID: 5304)
      • MicrosoftEdgeUpdate.exe (PID: 6836)
      • MicrosoftEdgeUpdate.exe (PID: 4488)
      • MicrosoftEdge_X64_148.0.3967.83.exe (PID: 2420)
      • setup.exe (PID: 6432)
    • The sample compiled with english language support

      • Roblox%20Kurdistan.exe (PID: 2576)
      • MicrosoftEdgeWebview2Setup.exe (PID: 2016)
      • MicrosoftEdgeUpdate.exe (PID: 2100)
      • MicrosoftEdge_X64_148.0.3967.83.exe (PID: 2420)
      • setup.exe (PID: 6432)
    • Reads the machine GUID from the registry

      • Roblox%20Kurdistan.exe (PID: 2576)
      • MicrosoftEdgeUpdate.exe (PID: 4488)
    • ROBLOX mutex has been found

      • Roblox%20Kurdistan.exe (PID: 2576)
    • Reads the computer name

      • Roblox%20Kurdistan.exe (PID: 2576)
      • MicrosoftEdgeUpdate.exe (PID: 2100)
      • MicrosoftEdgeUpdate.exe (PID: 7600)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 1176)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5224)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2156)
      • MicrosoftEdgeUpdate.exe (PID: 5304)
      • MicrosoftEdgeUpdate.exe (PID: 6836)
      • MicrosoftEdgeUpdate.exe (PID: 4488)
      • MicrosoftEdge_X64_148.0.3967.83.exe (PID: 2420)
      • setup.exe (PID: 6432)
    • Creates files or folders in the user directory

      • Roblox%20Kurdistan.exe (PID: 2576)
      • MicrosoftEdgeUpdate.exe (PID: 2100)
      • MicrosoftEdgeUpdate.exe (PID: 4488)
      • setup.exe (PID: 6432)
      • MicrosoftEdge_X64_148.0.3967.83.exe (PID: 2420)
    • Process checks whether UAC notifications are on

      • Roblox%20Kurdistan.exe (PID: 2576)
    • Create files in a temporary directory

      • Roblox%20Kurdistan.exe (PID: 2576)
      • MicrosoftEdgeWebview2Setup.exe (PID: 2016)
      • MicrosoftEdgeUpdate.exe (PID: 2100)
    • Launching a file from a Registry key

      • MicrosoftEdgeUpdate.exe (PID: 2100)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 5304)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 2100)
      • MicrosoftEdgeUpdate.exe (PID: 4488)
    • Process checks computer location settings

      • MicrosoftEdgeUpdate.exe (PID: 2100)
      • setup.exe (PID: 6432)
    • Creates a software uninstall entry

      • setup.exe (PID: 6432)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2029:11:13 22:29:54+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 7407104
InitializedDataSize: 2568192
UninitializedDataSize: -
EntryPoint: 0x6a2ffe
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.6.0.7686
ProductVersionNumber: 1.6.0.7686
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Roblox Corporation
FileDescription: Roblox
FileVersion: 1, 6, 0, 7151110
LegalCopyright: Copyright © 2020 Roblox Corporation. All rights reserved.
OriginalFileName: Roblox.exe
ProductName: Roblox Bootstrapper
ProductVersion: 1, 6, 0, 7151110
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
146
Monitored processes
12
Malicious processes
7
Suspicious processes
5

Behavior graph

Click at the process to see the details
start roblox%20kurdistan.exe microsoftedgewebview2setup.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe microsoftedge_x64_148.0.3967.83.exe setup.exe

Process information

PID
CMD
Path
Indicators
Parent process
1176"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.195.45\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2016MicrosoftEdgeWebview2Setup.exe /silent /installC:\Users\admin\AppData\Local\Roblox\Versions\version-4b6315bf1f0a4dbb\WebView2RuntimeInstaller\MicrosoftEdgeWebview2Setup.exe
Roblox%20Kurdistan.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\roblox\versions\version-4b6315bf1f0a4dbb\webview2runtimeinstaller\microsoftedgewebview2setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2100C:\Users\admin\AppData\Local\Temp\EU2F59.tmp\MicrosoftEdgeUpdate.exe /silent /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers"C:\Users\admin\AppData\Local\Temp\EU2F59.tmp\MicrosoftEdgeUpdate.exe
MicrosoftEdgeWebview2Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\temp\eu2f59.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
2156"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.195.45\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2420"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{3D0823BF-F584-4928-A0AD-DFF2222F67AF}\MicrosoftEdge_X64_148.0.3967.83.exe" --msedgewebview --verbose-logging --do-not-launch-msedge --user-levelC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{3D0823BF-F584-4928-A0AD-DFF2222F67AF}\MicrosoftEdge_X64_148.0.3967.83.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Version:
148.0.3967.83
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{3d0823bf-f584-4928-a0ad-dff2222f67af}\microsoftedge_x64_148.0.3967.83.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2576"C:\Users\admin\AppData\Local\Temp\Roblox%20Kurdistan.exe" C:\Users\admin\AppData\Local\Temp\Roblox%20Kurdistan.exe
explorer.exe
User:
admin
Company:
Roblox Corporation
Integrity Level:
MEDIUM
Description:
Roblox
Version:
1, 6, 0, 7151110
Modules
Images
c:\users\admin\appdata\local\temp\roblox%20kurdistan.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ws2_32.dll
4488"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" -EmbeddingC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
5224"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.195.45\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5304"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xOTUuNDUiIHNoZWxsX3ZlcnNpb249IjEuMy4xOTUuNDUiIGlzbWFjaGluZT0iMCIgc2Vzc2lvbmlkPSJ7QjI4MTRENDUtOTU0RC00RTUxLTgyRTEtQzc1M0UzM0U3NTA2fSIgdXNlcmlkPSJ7MTIwQUI4RTYtOEQ1OC00NzE3LUI2ODgtQTFFQ0ZBQjU4RUFBfSIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiByZXF1ZXN0aWQ9Ins0QTM2NTk5Qi1GNTk1LTRCQ0UtOTZBQS1EQjcxNzlFNjA5RUF9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iNiIgcGh5c21lbW9yeT0iNiIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE5MDQ1LjQwNDYiIHNwPSIiIGFyY2g9Ing2NCIgcHJvZHVjdF90eXBlPSI0OCIgaXNfd2lwPSIwIiBpc19pbl9sb2NrZG93bl9tb2RlPSIwIi8-PG9lbSBwcm9kdWN0X21hbnVmYWN0dXJlcj0iREVMTCIgcHJvZHVjdF9uYW1lPSJERUxMIi8-PGV4cCBldGFnPSIiLz48YXBwIGFwcGlkPSJ7RjNDNEZFMDAtRUZENS00MDNCLTk1NjktMzk4QTIwRjFCQTRBfSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iMS4zLjE5NS40NSIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iOTMxMDk4NzkzMiIgaW5zdGFsbF90aW1lX21zPSI2MTIiLz48L2FwcD48L3JlcXVlc3Q-C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
6432"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{3D0823BF-F584-4928-A0AD-DFF2222F67AF}\EDGEMITMP_39603.tmp\setup.exe" --install-archive="C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{3D0823BF-F584-4928-A0AD-DFF2222F67AF}\MicrosoftEdge_X64_148.0.3967.83.exe" --msedgewebview --verbose-logging --do-not-launch-msedge --user-levelC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{3D0823BF-F584-4928-A0AD-DFF2222F67AF}\EDGEMITMP_39603.tmp\setup.exe
MicrosoftEdge_X64_148.0.3967.83.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
148.0.3967.83
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{3d0823bf-f584-4928-a0ad-dff2222f67af}\edgemitmp_39603.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
8 278
Read events
6 930
Write events
1 300
Delete events
48

Modification events

(PID) Process:(2576) Roblox%20Kurdistan.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\ProtocolExecute\roblox-studio
Operation:writeName:WarnOnOpen
Value:
0
(PID) Process:(2576) Roblox%20Kurdistan.exeKey:HKEY_CLASSES_ROOT\roblox-studio
Operation:writeName:URL Protocol
Value:
(PID) Process:(2576) Roblox%20Kurdistan.exeKey:HKEY_CLASSES_ROOT\roblox-studio\shell\open\command
Operation:writeName:version
Value:
version-b2a9c018a1e042c6
(PID) Process:(2100) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:delete valueName:eulaaccepted
Value:
(PID) Process:(2100) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:path
Value:
C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(PID) Process:(2100) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:UninstallCmdLine
Value:
"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /uninstall
(PID) Process:(2100) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.195.45
(PID) Process:(2100) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:name
Value:
Microsoft Edge Update
(PID) Process:(2100) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\ClientState\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.195.45
(PID) Process:(2100) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Microsoft Edge Update
Value:
"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateCore.exe"
Executable files
206
Suspicious files
30
Text files
7
Unknown types
2

Dropped files

PID
Process
Filename
Type
2576Roblox%20Kurdistan.exeC:\Users\admin\AppData\Local\Roblox\logs\cacert.pemtext
MD5:E46C5D007899D693A9D325FBFBBD4BBB
SHA256:416DF7C7A6AF3D35B06B3AEE5E736B02C8AEFD4A3B9BE31BEFC1C97AB323FFA6
2576Roblox%20Kurdistan.exeC:\Users\admin\AppData\Local\Roblox\Versions\RobloxStudioInstaller.exeexecutable
MD5:E9E303FD5A59745AD496C62500628C4F
SHA256:FD73715C87FEEDB40DCDA61DC7103C406A29D4857000BA9AC0E2707D20F7B527
2576Roblox%20Kurdistan.exeC:\Users\admin\AppData\Local\Roblox\RobloxPlayerInstaller\InstallerInfo.logtext
MD5:CEED091C1E092CEF84911EDF7AAEB2C4
SHA256:9C4F7F52D04DC8AACD3BAF330EDF3A267BE083B41D94161951DD37B991BB367D
2576Roblox%20Kurdistan.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox\Roblox Studio.lnkbinary
MD5:8BF1BDAA18B86E6EE997F932AE2B8984
SHA256:46DF9DB5D5F7B98B888D823B189789A3A8BC50D4292CB86AFC0F97E68B9B8974
2576Roblox%20Kurdistan.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\fbb0ce7a795cad22ef0c116ae89f13d4compressed
MD5:FBB0CE7A795CAD22EF0C116AE89F13D4
SHA256:7041752F10D5275EF1021AFA12523AA9F5E534C0A2FF87D6921C1F70CC68B534
2576Roblox%20Kurdistan.exeC:\Users\admin\Desktop\Roblox Studio.lnkbinary
MD5:339933106209C9BC5B26601562D5789D
SHA256:4E0A9B0AC639A62D492FF4C495D5D3818C40BFBA023F87BDC2DF9C92333B4BBE
2576Roblox%20Kurdistan.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\aac2b417eabea6376883ac2f50ff9c61compressed
MD5:AAC2B417EABEA6376883AC2F50FF9C61
SHA256:5AA57113DB54296BEE8F723C1A2A1D5CAB5481C8064FB31E957743ECC8C20247
2576Roblox%20Kurdistan.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\fc70e73e1f436778de4b83680f9819bb
MD5:
SHA256:
2576Roblox%20Kurdistan.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\1d799e2fae97f3cfe4fd461d90f04ad8compressed
MD5:1D799E2FAE97F3CFE4FD461D90F04AD8
SHA256:ACFCB6E86B4C0432A89962D3B791DD1621112BE6B44D760E1B9E638A067C228C
2576Roblox%20Kurdistan.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\a919e96d3276950f67903c0c19164e8acompressed
MD5:0FDE982F2A8B7C16DF5335BC0B68523B
SHA256:7F9DE5169EC785E73D80A5D03866DBADDEEBDDFB2745D6F38761887EBC147B77
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
31
TCP/UDP connections
35
DNS requests
26
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5484
svchost.exe
GET
200
2.16.164.9:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
5276
MoUsoCoreWorker.exe
GET
304
48.209.133.15:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
5484
svchost.exe
GET
200
72.246.29.11:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
5532
SearchApp.exe
GET
200
23.11.40.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
NL
binary
312 b
whitelisted
5532
SearchApp.exe
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAFUWohyJgUzPcAAAAAAAU%3D
US
binary
960 b
whitelisted
5888
SIHClient.exe
GET
304
74.179.77.204:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
5888
SIHClient.exe
GET
200
135.232.92.97:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
5888
SIHClient.exe
GET
200
74.179.77.204:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
5888
SIHClient.exe
GET
304
74.179.77.204:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
4348
svchost.exe
HEAD
200
91.80.49.85:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/cf2ec596-1193-432f-9920-156d5515f0a1?P1=1780109641&P2=404&P3=2&P4=U0kSSG71HykFAvJ0klhZ11GMsMnyryTcpx%2fNBPQP1Gv6kt44TbKQkrjCdjKD4omTudA3Qf7nJsxtkSJpI86wuA%3d%3d
IT
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5484
svchost.exe
48.209.138.168:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
5276
MoUsoCoreWorker.exe
48.209.138.168:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
48.192.1.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2576
Roblox%20Kurdistan.exe
128.116.5.3:443
ecsv2.roblox.com
ROBLOX-PRODUCTION
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
2576
Roblox%20Kurdistan.exe
23.212.218.150:443
clientsettingscdn.roblox.com
AKAMAI-AS
US
whitelisted
2576
Roblox%20Kurdistan.exe
2.16.164.129:443
setup.rbxcdn.com
AKAMAI-ASN1
NL
whitelisted
5484
svchost.exe
57.153.246.3:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5484
svchost.exe
2.16.164.9:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 48.209.138.168
  • 57.153.246.3
  • 48.209.133.15
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.65
whitelisted
google.com
  • 142.250.154.113
  • 142.250.154.138
  • 142.250.154.139
  • 142.250.154.100
  • 142.250.154.101
  • 142.250.154.102
whitelisted
ecsv2.roblox.com
  • 128.116.5.3
whitelisted
client-telemetry.roblox.com
  • 128.116.5.3
whitelisted
clientsettingscdn.roblox.com
  • 23.212.218.150
whitelisted
setup.rbxcdn.com
  • 2.16.164.129
  • 2.16.164.10
whitelisted
crl.microsoft.com
  • 2.16.164.9
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 72.246.29.11
  • 88.221.169.152
whitelisted
www.bing.com
  • 23.3.89.113
  • 23.11.206.106
  • 95.100.158.107
  • 23.3.89.90
  • 23.3.89.97
  • 23.11.206.107
  • 23.3.89.89
  • 23.3.89.120
  • 23.11.206.115
whitelisted

Threats

PID
Process
Class
Message
4348
svchost.exe
Misc activity
ET INFO Packed Executable Download
5276
MoUsoCoreWorker.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
Process
Message
Roblox%20Kurdistan.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.