File name:

NO ANTIVIRUS.zip

Full analysis: https://app.any.run/tasks/b0e98b56-2c89-4c67-8a45-dd052c6a8b96
Verdict: Malicious activity
Analysis date: July 14, 2025, 16:45:58
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
roblox
arch-doc
arch-scr
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

1374148361875F8ECAA9468CCF3ADED9

SHA1:

E10DA68956BBBE022F1CCAC26460C3DE83B5A89B

SHA256:

18C74883E48E140185A663F1ABE5561259F28554543FC3C843F4654E7415A65C

SSDEEP:

98304:UnrNREDUaUSp+Bv/+hMVP/MY0RHNtCjnQVmM/60c7htYvw+vJTMLXnYAMHHweFRj:b3xx27Zq5Vl0AgFO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • MicrosoftEdgeUpdate.exe (PID: 6140)
  • SUSPICIOUS

    • Changes default file association

      • RobloxPlayerInstaller.exe (PID: 3488)
    • Executable content was dropped or overwritten

      • RobloxPlayerInstaller.exe (PID: 3488)
      • MicrosoftEdgeWebview2Setup.exe (PID: 1612)
      • MicrosoftEdgeUpdate.exe (PID: 6140)
    • Process drops legitimate windows executable

      • RobloxPlayerInstaller.exe (PID: 3488)
      • MicrosoftEdgeWebview2Setup.exe (PID: 1612)
      • MicrosoftEdgeUpdate.exe (PID: 6140)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeUpdate.exe (PID: 6140)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 6140)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdate.exe (PID: 4320)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2976)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5008)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7080)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 6140)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 1296)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 1296)
      • RobloxPlayerInstaller.exe (PID: 3488)
      • MicrosoftEdgeWebview2Setup.exe (PID: 1612)
      • MicrosoftEdgeUpdate.exe (PID: 6140)
    • Creates files or folders in the user directory

      • RobloxPlayerInstaller.exe (PID: 3488)
      • MicrosoftEdgeUpdate.exe (PID: 6140)
    • ROBLOX mutex has been found

      • RobloxPlayerInstaller.exe (PID: 3488)
    • Checks supported languages

      • RobloxPlayerInstaller.exe (PID: 3488)
      • MicrosoftEdgeWebview2Setup.exe (PID: 1612)
      • MicrosoftEdgeUpdate.exe (PID: 6140)
      • MicrosoftEdgeUpdate.exe (PID: 4320)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2976)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5008)
      • MicrosoftEdgeUpdate.exe (PID: 320)
      • MicrosoftEdgeUpdate.exe (PID: 1688)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7080)
      • MicrosoftEdgeUpdate.exe (PID: 6348)
    • Reads the computer name

      • RobloxPlayerInstaller.exe (PID: 3488)
      • MicrosoftEdgeUpdate.exe (PID: 6140)
      • MicrosoftEdgeUpdate.exe (PID: 4320)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2976)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7080)
      • MicrosoftEdgeUpdate.exe (PID: 6348)
      • MicrosoftEdgeUpdate.exe (PID: 1688)
      • MicrosoftEdgeUpdate.exe (PID: 320)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5008)
    • Manual execution by a user

      • RobloxPlayerInstaller.exe (PID: 3488)
    • Reads the machine GUID from the registry

      • RobloxPlayerInstaller.exe (PID: 3488)
    • Process checks whether UAC notifications are on

      • RobloxPlayerInstaller.exe (PID: 3488)
    • Create files in a temporary directory

      • RobloxPlayerInstaller.exe (PID: 3488)
      • MicrosoftEdgeWebview2Setup.exe (PID: 1612)
    • Launching a file from a Registry key

      • MicrosoftEdgeUpdate.exe (PID: 6140)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 6348)
    • Process checks computer location settings

      • MicrosoftEdgeUpdate.exe (PID: 6140)
    • Checks proxy server information

      • MicrosoftEdgeUpdate.exe (PID: 6348)
      • MicrosoftEdgeUpdate.exe (PID: 1688)
    • Reads the software policy settings

      • MicrosoftEdgeUpdate.exe (PID: 6348)
      • MicrosoftEdgeUpdate.exe (PID: 1688)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2025:07:14 13:10:20
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: LX63/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
148
Monitored processes
12
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe robloxplayerinstaller.exe microsoftedgewebview2setup.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
320"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /handoff "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=false" /installsource otherinstallcmd /sessionid "{105D7125-2467-44C2-9C9A-E2708CE4D052}" /silentC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
1296"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\NO ANTIVIRUS.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1612MicrosoftEdgeWebview2Setup.exe /silent /installC:\Users\admin\AppData\Local\Roblox\Versions\version-765338e04cf54fde\WebView2RuntimeInstaller\MicrosoftEdgeWebview2Setup.exe
RobloxPlayerInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\roblox\versions\version-765338e04cf54fde\webview2runtimeinstaller\microsoftedgewebview2setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1688"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" -EmbeddingC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
2976"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.195.45\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3488"C:\Users\admin\Desktop\RobloxPlayerInstaller.exe" C:\Users\admin\Desktop\RobloxPlayerInstaller.exe
explorer.exe
User:
admin
Company:
Roblox Corporation
Integrity Level:
MEDIUM
Description:
Roblox
Version:
1, 6, 0, 6810806
Modules
Images
c:\users\admin\desktop\robloxplayerinstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
3876C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4320"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserverC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
5008"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.195.45\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6140C:\Users\admin\AppData\Local\Temp\EUB788.tmp\MicrosoftEdgeUpdate.exe /silent /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers"C:\Users\admin\AppData\Local\Temp\EUB788.tmp\MicrosoftEdgeUpdate.exe
MicrosoftEdgeWebview2Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\temp\eub788.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
Total events
7 804
Read events
6 797
Write events
973
Delete events
34

Modification events

(PID) Process:(1296) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1296) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1296) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(1296) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(1296) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(1296) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\NO ANTIVIRUS.zip
(PID) Process:(1296) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1296) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1296) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1296) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
208
Suspicious files
22
Text files
5
Unknown types
4

Dropped files

PID
Process
Filename
Type
3488RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\8bd85f4e8e0f8904501eb60e6f3bf7eecompressed
MD5:8BD85F4E8E0F8904501EB60E6F3BF7EE
SHA256:2E01FCA8EA0CDFCB1E6962AE9A8DC8FAB9241441E2568D812AAD9A11E1BFF57B
1296WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1296.38164\LX63\bin\Injector.exeexecutable
MD5:63E45A8330E446C14BC68F90E0654FC3
SHA256:7ABB23F1AF4DE43F9E04BED4E534F4D2367D83B38FDCF3F083551493D9361B4D
1296WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1296.38164\LX63\bin\LX63.dllexecutable
MD5:8A25F053F8780633EB7231915CDEB0D1
SHA256:F9577679E1DDDAD072AD5B74736B4E6B068446630080981D2B8522EADBEFE989
3488RobloxPlayerInstaller.exeC:\Users\admin\Desktop\Roblox Studio.lnklnk
MD5:F6CE79940B2AA497D9B047D5FC1C9A3F
SHA256:86EFE9CC2ED40D112E0DBF122BF3D2D3E201669CE06CC7AFC17AD1BDB4A52B7E
3488RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\logs\cacert.pemtext
MD5:18EB55403B6BFAF4927B174FC2A3AB66
SHA256:7570425CD2E18C5A5536887906B6C113F62A03C2744CFFA27FC6B9CA1AD91C2C
3488RobloxPlayerInstaller.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox\Roblox Studio.lnklnk
MD5:B91E1E3932D292B2984FED73439AE7AF
SHA256:71D6EBF513A0D4ED4FD25C730C7231132DD494C65812077982958414A3C78C81
3488RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\ad69a48a01948752ceb600ff5c3d71b3compressed
MD5:AD69A48A01948752CEB600FF5C3D71B3
SHA256:61AE45001676C407E4078ED744FF798787451718E43B461EAC5FE50D29E51EB8
1296WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1296.38164\LX63\LX63.exeexecutable
MD5:AACC60A1318DF84492D37F48861A7D0E
SHA256:E93D2B130E80A3306B158A7B042312B1DBFF54CE9BE7D8A040ECEA4AC01F66E6
3488RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Versions\RobloxStudioInstaller.exeexecutable
MD5:465CBBF5A47A0C313E1BEBC70FFE2276
SHA256:38A333463528336711757B8B1589B7627D016EB306FA2F897BE2798A9D11719C
1296WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa1296.38164\RobloxPlayerInstaller.exeexecutable
MD5:A8FA7D2FE695979FC11824013AC47FA5
SHA256:561A14050D9F0B692F9355FF5081CD516A7C7D3D3D199130DE298881A1BB945B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
31
DNS requests
23
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.55.110.211:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6700
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1300
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2388
svchost.exe
HEAD
200
208.89.74.19:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/97df600b-8033-4038-a0fb-ef60a2b87f5c?P1=1753116395&P2=404&P3=2&P4=fFBh8xkwRzxlYI2L3Ew5co020Ec%2btgAH0TJz1h1TEx%2fpGiOc8%2ffUzE7FeNZIMrlydGhrn3CqHex6%2ffzz0WgNLQ%3d%3d
unknown
whitelisted
2388
svchost.exe
GET
208.89.74.19:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/97df600b-8033-4038-a0fb-ef60a2b87f5c?P1=1753116395&P2=404&P3=2&P4=fFBh8xkwRzxlYI2L3Ew5co020Ec%2btgAH0TJz1h1TEx%2fpGiOc8%2ffUzE7FeNZIMrlydGhrn3CqHex6%2ffzz0WgNLQ%3d%3d
unknown
whitelisted
1300
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3688
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
13.71.55.58:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IN
whitelisted
1268
svchost.exe
23.55.110.211:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
6700
svchost.exe
20.190.159.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6700
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 13.71.55.58
  • 51.104.136.2
whitelisted
google.com
  • 142.250.185.78
whitelisted
crl.microsoft.com
  • 23.55.110.211
  • 23.55.110.193
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
login.live.com
  • 20.190.159.68
  • 20.190.159.129
  • 20.190.159.73
  • 40.126.31.130
  • 20.190.159.64
  • 20.190.159.71
  • 40.126.31.67
  • 40.126.31.2
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
ecsv2.roblox.com
  • 128.116.44.3
whitelisted
client-telemetry.roblox.com
  • 128.116.44.3
whitelisted
clientsettingscdn.roblox.com
  • 23.41.252.19
whitelisted
setup.rbxcdn.com
  • 13.32.27.4
  • 13.32.27.22
  • 13.32.27.35
  • 13.32.27.39
whitelisted

Threats

PID
Process
Class
Message
2388
svchost.exe
Misc activity
ET INFO Packed Executable Download
Process
Message
RobloxPlayerInstaller.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.