File name:

roblox-studio-1-6-1-9670.exe

Full analysis: https://app.any.run/tasks/cebde6ca-94a2-48b5-b49c-d2324a5ab70a
Verdict: Malicious activity
Analysis date: May 18, 2024, 22:54:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

CC3B5563CE4A227D4C1B54E602E96B4F

SHA1:

3B0B352F174B3670AB59BB26B59F96A702AC1D88

SHA256:

1E1FB1CB0FC22A347E8F402DDF40323F977E88D230202BAA3565D254C52116C0

SSDEEP:

49152:008OHLT7MMG1BGt35hSBP1L3MYEmE54a4NFUmDqX1vnnj91Yd6Zzi8AiUa+nI0tE:FPJg3MYEmE2FUmeX1vnnj91Ja7q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • roblox-studio-1-6-1-9670.exe (PID: 3968)
  • SUSPICIOUS

    • Reads the Internet Settings

      • roblox-studio-1-6-1-9670.exe (PID: 928)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
      • RobloxStudioLauncherBeta.exe (PID: 524)
      • roblox-studio-1-6-1-9670.exe (PID: 3968)
    • Application launched itself

      • roblox-studio-1-6-1-9670.exe (PID: 3968)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
    • Reads security settings of Internet Explorer

      • roblox-studio-1-6-1-9670.exe (PID: 928)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
      • RobloxStudioLauncherBeta.exe (PID: 524)
      • roblox-studio-1-6-1-9670.exe (PID: 3968)
    • Checks Windows Trust Settings

      • roblox-studio-1-6-1-9670.exe (PID: 928)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
      • RobloxStudioLauncherBeta.exe (PID: 524)
      • roblox-studio-1-6-1-9670.exe (PID: 3968)
    • Changes Internet Explorer settings (feature browser emulation)

      • roblox-studio-1-6-1-9670.exe (PID: 3968)
    • Reads settings of System Certificates

      • roblox-studio-1-6-1-9670.exe (PID: 928)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
      • RobloxStudioLauncherBeta.exe (PID: 524)
      • roblox-studio-1-6-1-9670.exe (PID: 3968)
    • Executable content was dropped or overwritten

      • roblox-studio-1-6-1-9670.exe (PID: 3968)
  • INFO

    • Create files in a temporary directory

      • roblox-studio-1-6-1-9670.exe (PID: 3968)
      • roblox-studio-1-6-1-9670.exe (PID: 928)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
      • RobloxStudioLauncherBeta.exe (PID: 524)
    • Checks supported languages

      • roblox-studio-1-6-1-9670.exe (PID: 3968)
      • roblox-studio-1-6-1-9670.exe (PID: 928)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
      • wmpnscfg.exe (PID: 372)
      • RobloxStudioLauncherBeta.exe (PID: 524)
    • Reads the machine GUID from the registry

      • roblox-studio-1-6-1-9670.exe (PID: 928)
      • roblox-studio-1-6-1-9670.exe (PID: 3968)
      • RobloxStudioLauncherBeta.exe (PID: 524)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
    • Checks proxy server information

      • roblox-studio-1-6-1-9670.exe (PID: 928)
      • roblox-studio-1-6-1-9670.exe (PID: 3968)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
      • RobloxStudioLauncherBeta.exe (PID: 524)
    • Reads the computer name

      • roblox-studio-1-6-1-9670.exe (PID: 928)
      • roblox-studio-1-6-1-9670.exe (PID: 3968)
      • wmpnscfg.exe (PID: 372)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
      • RobloxStudioLauncherBeta.exe (PID: 524)
    • Reads the software policy settings

      • roblox-studio-1-6-1-9670.exe (PID: 928)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
      • RobloxStudioLauncherBeta.exe (PID: 524)
      • roblox-studio-1-6-1-9670.exe (PID: 3968)
    • Process checks computer location settings

      • roblox-studio-1-6-1-9670.exe (PID: 3968)
    • Creates files or folders in the user directory

      • roblox-studio-1-6-1-9670.exe (PID: 928)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
      • RobloxStudioLauncherBeta.exe (PID: 524)
      • roblox-studio-1-6-1-9670.exe (PID: 3968)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 372)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2035:07:08 15:24:29+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 1379328
InitializedDataSize: 701952
UninitializedDataSize: -
EntryPoint: 0x113c52
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.6.1.9670
ProductVersionNumber: 1.6.1.9670
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Roblox Corporation
FileDescription: Roblox
FileVersion: 1, 6, 1, 5580230
LegalCopyright: Copyright © 2020 Roblox Corporation. All rights reserved.
OriginalFileName: Roblox.exe
ProductName: Roblox Bootstrapper
ProductVersion: 1, 6, 1, 5580230
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
5
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start roblox-studio-1-6-1-9670.exe roblox-studio-1-6-1-9670.exe wmpnscfg.exe no specs robloxstudiolauncherbeta.exe robloxstudiolauncherbeta.exe

Process information

PID
CMD
Path
Indicators
Parent process
372"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
524C:\Users\admin\AppData\Local\Temp\RBX-1604E087\RobloxStudioLauncherBeta.exe --crashpad --no-rate-limit --database=C:\Users\admin\AppData\Local\Temp\crashpad_roblox --metrics-dir=C:\Users\admin\AppData\Local\Temp\crashpad_roblox --url=https://upload.crashes.rbxinfra.com/post --annotation=RobloxChannel=production --annotation=RobloxGitHash=3539e67194ee6ba0c99d6e96abe3b09d611a4794 --annotation=UploadAttachmentKiloByteLimit=100 --annotation=UploadPercentage=0 --annotation=format=minidump --annotation=token=a2440b0bfdada85f34d79b43839f2b49ea6bba474bd7d126e844bc119271a1c3 --initial-client-data=0x590,0x594,0x598,0x56c,0x5a0,0xca2ad8,0xca2ae8,0xca2af8C:\Users\admin\AppData\Local\Temp\RBX-1604E087\RobloxStudioLauncherBeta.exe
RobloxStudioLauncherBeta.exe
User:
admin
Company:
Roblox Corporation
Integrity Level:
MEDIUM
Description:
Roblox
Exit code:
0
Version:
1, 6, 0, 5780566
Modules
Images
c:\users\admin\appdata\local\temp\rbx-1604e087\robloxstudiolauncherbeta.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
928C:\Users\admin\AppData\Local\Temp\roblox-studio-1-6-1-9670.exe --crashpad --no-rate-limit --database=C:\Users\admin\AppData\Local\Temp\crashpad_roblox --metrics-dir=C:\Users\admin\AppData\Local\Temp\crashpad_roblox --url=https://upload.crashes.rbxinfra.com/post --annotation=RobloxChannel=production --annotation=RobloxGitHash=1aaea22e121799711df6534f3b9db58e26550dcc --annotation=UploadAttachmentKiloByteLimit=100 --annotation=UploadPercentage=0 --annotation=format=minidump --annotation=token=a2440b0bfdada85f34d79b43839f2b49ea6bba474bd7d126e844bc119271a1c3 --initial-client-data=0x580,0x584,0x588,0x55c,0x590,0x13b0a4c,0x13b0a5c,0x13b0a6cC:\Users\admin\AppData\Local\Temp\roblox-studio-1-6-1-9670.exe
roblox-studio-1-6-1-9670.exe
User:
admin
Company:
Roblox Corporation
Integrity Level:
MEDIUM
Description:
Roblox
Exit code:
0
Version:
1, 6, 1, 5580230
Modules
Images
c:\users\admin\appdata\local\temp\roblox-studio-1-6-1-9670.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1292"C:\Users\admin\AppData\Local\Temp\RBX-1604E087\RobloxStudioLauncherBeta.exe" C:\Users\admin\AppData\Local\Temp\RBX-1604E087\RobloxStudioLauncherBeta.exe
roblox-studio-1-6-1-9670.exe
User:
admin
Company:
Roblox Corporation
Integrity Level:
MEDIUM
Description:
Roblox
Exit code:
0
Version:
1, 6, 0, 5780566
Modules
Images
c:\users\admin\appdata\local\temp\rbx-1604e087\robloxstudiolauncherbeta.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3968"C:\Users\admin\AppData\Local\Temp\roblox-studio-1-6-1-9670.exe" C:\Users\admin\AppData\Local\Temp\roblox-studio-1-6-1-9670.exe
explorer.exe
User:
admin
Company:
Roblox Corporation
Integrity Level:
MEDIUM
Description:
Roblox
Exit code:
0
Version:
1, 6, 1, 5580230
Modules
Images
c:\users\admin\appdata\local\temp\roblox-studio-1-6-1-9670.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
16 217
Read events
16 029
Write events
159
Delete events
29

Modification events

(PID) Process:(3968) roblox-studio-1-6-1-9670.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3968) roblox-studio-1-6-1-9670.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3968) roblox-studio-1-6-1-9670.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3968) roblox-studio-1-6-1-9670.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3968) roblox-studio-1-6-1-9670.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(3968) roblox-studio-1-6-1-9670.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
(PID) Process:(3968) roblox-studio-1-6-1-9670.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoConfigURL
Value:
(PID) Process:(3968) roblox-studio-1-6-1-9670.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoDetect
Value:
(PID) Process:(3968) roblox-studio-1-6-1-9670.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005D010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3968) roblox-studio-1-6-1-9670.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
2
Suspicious files
28
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
3968roblox-studio-1-6-1-9670.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B398B80134F72209547439DB21AB308D_A4CF52CCA82D7458083F7280801A3A04binary
MD5:D0A543966E9ED30874FC311CB3315DA8
SHA256:DD10F206B007D155728ED82E61BE8E21454101E5F52B9584A2652B1F812FA8A4
3968roblox-studio-1-6-1-9670.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\AONGICDU.txttext
MD5:C33FDE29A3917A014DB78A8C7F3074E0
SHA256:EC2D537A1DD60EB2850E957DEF7A165EA866680F53F5AA4ADE218FF21182190A
3968roblox-studio-1-6-1-9670.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\PCStudioBootstrapper[1].jsonbinary
MD5:805555F305AE54B42E00A8BB0224F245
SHA256:3B4D6B66396B27F1FFE4C49DE2FF4DF61A47C16C11B64ECF7EFF475A3EDE0F83
3968roblox-studio-1-6-1-9670.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_A4CF52CCA82D7458083F7280801A3A04binary
MD5:8A70FF4AA7E3578A00E674416203EE2F
SHA256:CE308BE5A7D93FC7A28F220A6B7068EA798BBBAD16085EB409856C73F18A0F4B
3968roblox-studio-1-6-1-9670.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Ebinary
MD5:11AAEE8FA8F90B286DDF8C255DC6311E
SHA256:A98CF457F60A84A43F03A60A270EABAA9446EC88EE70E6D8114B025EE67F7017
3968roblox-studio-1-6-1-9670.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_BACC6CD2B29F18349081C9FD2343833Bbinary
MD5:991C45E0905E89D2CAFC52084BE58C7D
SHA256:DF1972371D25AEA90F0A4606ED6C7AEA47EDFEE870ADD714395F81C7D97559EC
3968roblox-studio-1-6-1-9670.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Ebinary
MD5:2FB1E3C170A874D307353A9FB2AFDB34
SHA256:1B25B5705735EB01696ABB4B52291EA2B362441105285C0F768CEA9A21D66695
3968roblox-studio-1-6-1-9670.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_BACC6CD2B29F18349081C9FD2343833Bbinary
MD5:61D271A64B21B901FF7268B77029BAEC
SHA256:FBD95B765C605F4F120E4AEA938CC7FEEED224BBC2C538E39E775F4199C8CE16
3968roblox-studio-1-6-1-9670.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\BatchIncrement[1].jsonbinary
MD5:BEDBF7D7D69748886E9B48F45C75FBBE
SHA256:B4A55CFD050F4A62B1C4831CA0AB6FFADDE1FE1C3F583917EADE12F8C6726F61
928roblox-studio-1-6-1-9670.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\BatchIncrement[1].jsonbinary
MD5:BEDBF7D7D69748886E9B48F45C75FBBE
SHA256:B4A55CFD050F4A62B1C4831CA0AB6FFADDE1FE1C3F583917EADE12F8C6726F61
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
21
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3968
roblox-studio-1-6-1-9670.exe
GET
304
23.50.131.216:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?2523fedc70fa6bf1
unknown
unknown
3968
roblox-studio-1-6-1-9670.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
unknown
3968
roblox-studio-1-6-1-9670.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEBN9U5yqfDGppDNwGWiEeo0%3D
unknown
unknown
3968
roblox-studio-1-6-1-9670.exe
GET
200
18.245.39.64:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
unknown
unknown
3968
roblox-studio-1-6-1-9670.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
unknown
3968
roblox-studio-1-6-1-9670.exe
GET
200
108.138.2.107:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
unknown
unknown
3968
roblox-studio-1-6-1-9670.exe
GET
200
18.245.39.64:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
3968
roblox-studio-1-6-1-9670.exe
23.41.252.19:443
clientsettingscdn.roblox.com
AKAMAI-AS
MX
unknown
3968
roblox-studio-1-6-1-9670.exe
23.50.131.216:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
3968
roblox-studio-1-6-1-9670.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3968
roblox-studio-1-6-1-9670.exe
128.116.122.4:443
ephemeralcounters.api.roblox.com
ROBLOX-PRODUCTION
US
unknown
928
roblox-studio-1-6-1-9670.exe
23.41.252.19:443
clientsettingscdn.roblox.com
AKAMAI-AS
MX
unknown
3968
roblox-studio-1-6-1-9670.exe
104.18.38.233:80
ocsp.comodoca.com
CLOUDFLARENET
shared
1088
svchost.exe
224.0.0.252:5355
unknown

DNS requests

Domain
IP
Reputation
clientsettingscdn.roblox.com
  • 23.41.252.19
unknown
ctldl.windowsupdate.com
  • 23.50.131.216
  • 23.50.131.200
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ephemeralcounters.api.roblox.com
  • 128.116.122.4
whitelisted
ocsp.comodoca.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
ocsp.usertrust.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
setup.rbxcdn.qq.com
  • 0.0.0.1
unknown
clientsettingscdn.roblox.qq.com
  • 0.0.0.1
unknown
setup.rbxcdn.com
  • 13.224.189.122
  • 13.224.189.83
  • 13.224.189.57
  • 13.224.189.58
whitelisted
setup-ak.rbxcdn.com
  • 23.48.23.156
  • 23.48.23.144
whitelisted

Threats

No threats detected
No debug info