File name:

Roblox.Account.Manager.3.6.1.zip

Full analysis: https://app.any.run/tasks/31a1e76d-c2c2-463a-818c-aaf827ed1221
Verdict: Malicious activity
Analysis date: December 19, 2024, 16:27:05
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

ACC4818F58F1A1D2D2844A05F1AECE19

SHA1:

E3038C4501BB62415C18BFACCA92167EBC4D623B

SHA256:

1B94210A7A05CE8379DB7B8C11D41F84BC868CBDCD0685733754728678BB5FA2

SSDEEP:

98304:zfPNQWRNX4qP4Gyl6J1wNlbLi366L/jHBZ4BPVn5XcMTsb8KkjGi+BKpCUjryykj:oyMIy5ZHCft

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6356)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 6356)
      • Roblox Account Manager.exe (PID: 6900)
    • Application launched itself

      • Roblox Account Manager.exe (PID: 6900)
    • Executable content was dropped or overwritten

      • Roblox Account Manager.exe (PID: 6972)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6356)
    • Reads the computer name

      • Roblox Account Manager.exe (PID: 6708)
      • Roblox Account Manager.exe (PID: 6900)
      • Roblox Account Manager.exe (PID: 6972)
    • Checks supported languages

      • Roblox Account Manager.exe (PID: 6708)
      • Roblox Account Manager.exe (PID: 6900)
      • Roblox Account Manager.exe (PID: 6972)
    • Creates files in the program directory

      • Roblox Account Manager.exe (PID: 6708)
      • Roblox Account Manager.exe (PID: 6972)
    • Reads the machine GUID from the registry

      • Roblox Account Manager.exe (PID: 6708)
      • Roblox Account Manager.exe (PID: 6900)
      • Roblox Account Manager.exe (PID: 6972)
    • The process uses the downloaded file

      • Roblox Account Manager.exe (PID: 6900)
      • WinRAR.exe (PID: 6356)
    • Manual execution by a user

      • Roblox Account Manager.exe (PID: 6900)
    • Process checks computer location settings

      • Roblox Account Manager.exe (PID: 6900)
    • Disables trace logs

      • Roblox Account Manager.exe (PID: 6972)
    • Creates files or folders in the user directory

      • Roblox Account Manager.exe (PID: 6972)
    • Reads the software policy settings

      • Roblox Account Manager.exe (PID: 6972)
    • Checks proxy server information

      • Roblox Account Manager.exe (PID: 6972)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2023:05:30 20:59:22
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: Roblox Account Manager/
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
121
Monitored processes
4
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe roblox account manager.exe no specs roblox account manager.exe no specs roblox account manager.exe

Process information

PID
CMD
Path
Indicators
Parent process
6356"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Roblox.Account.Manager.3.6.1.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6708"C:\Users\admin\AppData\Local\Temp\Rar$EXa6356.45000\Roblox Account Manager\Roblox Account Manager.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa6356.45000\Roblox Account Manager\Roblox Account Manager.exeWinRAR.exe
User:
admin
Company:
ic3
Integrity Level:
MEDIUM
Description:
Roblox Account Manager
Exit code:
1337
Version:
3.6.1.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa6356.45000\roblox account manager\roblox account manager.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
6900"C:\Users\admin\Desktop\Roblox Account Manager.exe" C:\Users\admin\Desktop\Roblox Account Manager.exeexplorer.exe
User:
admin
Company:
ic3
Integrity Level:
MEDIUM
Description:
Roblox Account Manager
Exit code:
0
Version:
3.6.1.0
Modules
Images
c:\users\admin\desktop\roblox account manager.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
6972"C:\Users\admin\Desktop\Roblox Account Manager.exe" -restartC:\Users\admin\Desktop\Roblox Account Manager.exe
Roblox Account Manager.exe
User:
admin
Company:
ic3
Integrity Level:
MEDIUM
Description:
Roblox Account Manager
Version:
3.6.1.0
Modules
Images
c:\users\admin\desktop\roblox account manager.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
Total events
6 378
Read events
6 356
Write events
22
Delete events
0

Modification events

(PID) Process:(6356) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6356) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6356) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6356) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Roblox.Account.Manager.3.6.1.zip
(PID) Process:(6356) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6356) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6356) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6356) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6972) Roblox Account Manager.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Roblox Account Manager_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6972) Roblox Account Manager.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Roblox Account Manager_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
Executable files
3
Suspicious files
1
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
6356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6356.47185\Roblox Account Manager\Roblox Account Manager.exeexecutable
MD5:A057FAE0C8C97EE6CF2C12FB7BCF034D
SHA256:CDB0A360CCA7A5099C2D2357BE1A833E032FFDEB3F467A6FAC845F6BB77031C9
6900Roblox Account Manager.exeC:\Users\admin\Desktop\RAMTheme.initext
MD5:F18FA783F4D27E35E54E54417334BFB4
SHA256:563EB35FD613F4298CD4DCEFF67652A13BA516A6244D9407C5709323C4CA4BB1
6900Roblox Account Manager.exeC:\Users\admin\Desktop\Roblox Account Manager.exe.configxml
MD5:7E067AFE7C779870C370C40240E2CE1F
SHA256:5E0BA1895CF088E6D6907B8ABBD8CD41C86F39CC642351A9AB0BF458BF1F5B31
6972Roblox Account Manager.exeC:\Users\admin\Desktop\RAMSettings.iniini
MD5:8EC667B649FC01D48534D916EB92743C
SHA256:A90DFE16AD4261034717B4B97982A84694A15607964A1750144C4F140E3D2D9F
6972Roblox Account Manager.exeC:\Users\admin\Desktop\AccountData.jsonbinary
MD5:E415FB1BB95350B08D8398E53913E2E7
SHA256:EF4764EC8AF66558FB759C4A0FE693DFA1F2286E7FB3CFE82C6C006C1ABAE59D
6900Roblox Account Manager.exeC:\Users\admin\Desktop\log4.configxml
MD5:E4659AC08AF3582A23F38BF6C562F841
SHA256:E4B10630D9EC2AF508DE31752FBBC6816C7426C40A3E57F0A085CE7F42C77BD5
6356WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6356.45000\Roblox Account Manager\Roblox Account Manager.exeexecutable
MD5:A057FAE0C8C97EE6CF2C12FB7BCF034D
SHA256:CDB0A360CCA7A5099C2D2357BE1A833E032FFDEB3F467A6FAC845F6BB77031C9
6972Roblox Account Manager.exeC:\Users\admin\Desktop\libsodium.dllexecutable
MD5:4F6426E3626D5D46FB19C13043CB84DE
SHA256:7A960129F6D3F8D44B4C6BE27F587C29AA8BAFB9C4D3C85BB84A5F5D8FA6E2BA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
11
DNS requests
5
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
4160
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3976
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
6972
Roblox Account Manager.exe
140.82.121.6:443
api.github.com
GITHUB
US
unknown
6972
Roblox Account Manager.exe
140.82.121.3:443
github.com
GITHUB
US
unknown
6972
Roblox Account Manager.exe
128.116.119.4:443
clientsettings.roblox.com
ROBLOX-PRODUCTION
US
unknown
6972
Roblox Account Manager.exe
142.250.185.251:443
storage.googleapis.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
clientsettings.roblox.com
  • 128.116.119.4
whitelisted
api.github.com
  • 140.82.121.6
whitelisted
github.com
  • 140.82.121.3
shared
storage.googleapis.com
  • 142.250.185.251
  • 142.250.185.219
  • 142.250.181.251
  • 142.250.185.91
  • 142.250.185.123
  • 142.250.184.251
  • 172.217.18.123
  • 216.58.206.59
  • 142.250.185.155
  • 216.58.212.155
  • 142.250.186.187
  • 142.250.185.187
  • 172.217.16.219
  • 142.250.184.219
  • 216.58.206.91
  • 142.250.186.91
whitelisted

Threats

No threats detected
No debug info