File name:

roblox-studio-1-6-1-9670.exe

Full analysis: https://app.any.run/tasks/cebde6ca-94a2-48b5-b49c-d2324a5ab70a
Verdict: Malicious activity
Analysis date: May 18, 2024, 22:54:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

CC3B5563CE4A227D4C1B54E602E96B4F

SHA1:

3B0B352F174B3670AB59BB26B59F96A702AC1D88

SHA256:

1E1FB1CB0FC22A347E8F402DDF40323F977E88D230202BAA3565D254C52116C0

SSDEEP:

49152:008OHLT7MMG1BGt35hSBP1L3MYEmE54a4NFUmDqX1vnnj91Yd6Zzi8AiUa+nI0tE:FPJg3MYEmE2FUmeX1vnnj91Ja7q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • roblox-studio-1-6-1-9670.exe (PID: 3968)
  • SUSPICIOUS

    • Reads the Internet Settings

      • roblox-studio-1-6-1-9670.exe (PID: 928)
      • roblox-studio-1-6-1-9670.exe (PID: 3968)
      • RobloxStudioLauncherBeta.exe (PID: 524)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
    • Reads security settings of Internet Explorer

      • roblox-studio-1-6-1-9670.exe (PID: 3968)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
      • RobloxStudioLauncherBeta.exe (PID: 524)
      • roblox-studio-1-6-1-9670.exe (PID: 928)
    • Checks Windows Trust Settings

      • roblox-studio-1-6-1-9670.exe (PID: 3968)
      • roblox-studio-1-6-1-9670.exe (PID: 928)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
      • RobloxStudioLauncherBeta.exe (PID: 524)
    • Reads settings of System Certificates

      • roblox-studio-1-6-1-9670.exe (PID: 3968)
      • roblox-studio-1-6-1-9670.exe (PID: 928)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
      • RobloxStudioLauncherBeta.exe (PID: 524)
    • Application launched itself

      • roblox-studio-1-6-1-9670.exe (PID: 3968)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
    • Changes Internet Explorer settings (feature browser emulation)

      • roblox-studio-1-6-1-9670.exe (PID: 3968)
    • Executable content was dropped or overwritten

      • roblox-studio-1-6-1-9670.exe (PID: 3968)
  • INFO

    • Reads the computer name

      • roblox-studio-1-6-1-9670.exe (PID: 3968)
      • wmpnscfg.exe (PID: 372)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
      • RobloxStudioLauncherBeta.exe (PID: 524)
      • roblox-studio-1-6-1-9670.exe (PID: 928)
    • Checks supported languages

      • roblox-studio-1-6-1-9670.exe (PID: 3968)
      • roblox-studio-1-6-1-9670.exe (PID: 928)
      • wmpnscfg.exe (PID: 372)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
      • RobloxStudioLauncherBeta.exe (PID: 524)
    • Reads the machine GUID from the registry

      • roblox-studio-1-6-1-9670.exe (PID: 3968)
      • roblox-studio-1-6-1-9670.exe (PID: 928)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
      • RobloxStudioLauncherBeta.exe (PID: 524)
    • Checks proxy server information

      • roblox-studio-1-6-1-9670.exe (PID: 3968)
      • RobloxStudioLauncherBeta.exe (PID: 524)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
      • roblox-studio-1-6-1-9670.exe (PID: 928)
    • Create files in a temporary directory

      • roblox-studio-1-6-1-9670.exe (PID: 3968)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
      • RobloxStudioLauncherBeta.exe (PID: 524)
      • roblox-studio-1-6-1-9670.exe (PID: 928)
    • Reads the software policy settings

      • roblox-studio-1-6-1-9670.exe (PID: 3968)
      • roblox-studio-1-6-1-9670.exe (PID: 928)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
      • RobloxStudioLauncherBeta.exe (PID: 524)
    • Process checks computer location settings

      • roblox-studio-1-6-1-9670.exe (PID: 3968)
    • Creates files or folders in the user directory

      • roblox-studio-1-6-1-9670.exe (PID: 928)
      • RobloxStudioLauncherBeta.exe (PID: 524)
      • RobloxStudioLauncherBeta.exe (PID: 1292)
      • roblox-studio-1-6-1-9670.exe (PID: 3968)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 372)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2035:07:08 15:24:29+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 1379328
InitializedDataSize: 701952
UninitializedDataSize: -
EntryPoint: 0x113c52
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.6.1.9670
ProductVersionNumber: 1.6.1.9670
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Roblox Corporation
FileDescription: Roblox
FileVersion: 1, 6, 1, 5580230
LegalCopyright: Copyright © 2020 Roblox Corporation. All rights reserved.
OriginalFileName: Roblox.exe
ProductName: Roblox Bootstrapper
ProductVersion: 1, 6, 1, 5580230
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
5
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start roblox-studio-1-6-1-9670.exe roblox-studio-1-6-1-9670.exe wmpnscfg.exe no specs robloxstudiolauncherbeta.exe robloxstudiolauncherbeta.exe

Process information

PID
CMD
Path
Indicators
Parent process
372"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
524C:\Users\admin\AppData\Local\Temp\RBX-1604E087\RobloxStudioLauncherBeta.exe --crashpad --no-rate-limit --database=C:\Users\admin\AppData\Local\Temp\crashpad_roblox --metrics-dir=C:\Users\admin\AppData\Local\Temp\crashpad_roblox --url=https://upload.crashes.rbxinfra.com/post --annotation=RobloxChannel=production --annotation=RobloxGitHash=3539e67194ee6ba0c99d6e96abe3b09d611a4794 --annotation=UploadAttachmentKiloByteLimit=100 --annotation=UploadPercentage=0 --annotation=format=minidump --annotation=token=a2440b0bfdada85f34d79b43839f2b49ea6bba474bd7d126e844bc119271a1c3 --initial-client-data=0x590,0x594,0x598,0x56c,0x5a0,0xca2ad8,0xca2ae8,0xca2af8C:\Users\admin\AppData\Local\Temp\RBX-1604E087\RobloxStudioLauncherBeta.exe
RobloxStudioLauncherBeta.exe
User:
admin
Company:
Roblox Corporation
Integrity Level:
MEDIUM
Description:
Roblox
Exit code:
0
Version:
1, 6, 0, 5780566
Modules
Images
c:\users\admin\appdata\local\temp\rbx-1604e087\robloxstudiolauncherbeta.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
928C:\Users\admin\AppData\Local\Temp\roblox-studio-1-6-1-9670.exe --crashpad --no-rate-limit --database=C:\Users\admin\AppData\Local\Temp\crashpad_roblox --metrics-dir=C:\Users\admin\AppData\Local\Temp\crashpad_roblox --url=https://upload.crashes.rbxinfra.com/post --annotation=RobloxChannel=production --annotation=RobloxGitHash=1aaea22e121799711df6534f3b9db58e26550dcc --annotation=UploadAttachmentKiloByteLimit=100 --annotation=UploadPercentage=0 --annotation=format=minidump --annotation=token=a2440b0bfdada85f34d79b43839f2b49ea6bba474bd7d126e844bc119271a1c3 --initial-client-data=0x580,0x584,0x588,0x55c,0x590,0x13b0a4c,0x13b0a5c,0x13b0a6cC:\Users\admin\AppData\Local\Temp\roblox-studio-1-6-1-9670.exe
roblox-studio-1-6-1-9670.exe
User:
admin
Company:
Roblox Corporation
Integrity Level:
MEDIUM
Description:
Roblox
Exit code:
0
Version:
1, 6, 1, 5580230
Modules
Images
c:\users\admin\appdata\local\temp\roblox-studio-1-6-1-9670.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1292"C:\Users\admin\AppData\Local\Temp\RBX-1604E087\RobloxStudioLauncherBeta.exe" C:\Users\admin\AppData\Local\Temp\RBX-1604E087\RobloxStudioLauncherBeta.exe
roblox-studio-1-6-1-9670.exe
User:
admin
Company:
Roblox Corporation
Integrity Level:
MEDIUM
Description:
Roblox
Exit code:
0
Version:
1, 6, 0, 5780566
Modules
Images
c:\users\admin\appdata\local\temp\rbx-1604e087\robloxstudiolauncherbeta.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3968"C:\Users\admin\AppData\Local\Temp\roblox-studio-1-6-1-9670.exe" C:\Users\admin\AppData\Local\Temp\roblox-studio-1-6-1-9670.exe
explorer.exe
User:
admin
Company:
Roblox Corporation
Integrity Level:
MEDIUM
Description:
Roblox
Exit code:
0
Version:
1, 6, 1, 5580230
Modules
Images
c:\users\admin\appdata\local\temp\roblox-studio-1-6-1-9670.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
16 217
Read events
16 029
Write events
159
Delete events
29

Modification events

(PID) Process:(3968) roblox-studio-1-6-1-9670.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3968) roblox-studio-1-6-1-9670.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3968) roblox-studio-1-6-1-9670.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3968) roblox-studio-1-6-1-9670.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3968) roblox-studio-1-6-1-9670.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(3968) roblox-studio-1-6-1-9670.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
(PID) Process:(3968) roblox-studio-1-6-1-9670.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoConfigURL
Value:
(PID) Process:(3968) roblox-studio-1-6-1-9670.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoDetect
Value:
(PID) Process:(3968) roblox-studio-1-6-1-9670.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005D010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3968) roblox-studio-1-6-1-9670.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
2
Suspicious files
28
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
928roblox-studio-1-6-1-9670.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\BatchIncrement[1].jsonbinary
MD5:BEDBF7D7D69748886E9B48F45C75FBBE
SHA256:B4A55CFD050F4A62B1C4831CA0AB6FFADDE1FE1C3F583917EADE12F8C6726F61
3968roblox-studio-1-6-1-9670.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\PCStudioBootstrapper[1].jsonbinary
MD5:805555F305AE54B42E00A8BB0224F245
SHA256:3B4D6B66396B27F1FFE4C49DE2FF4DF61A47C16C11B64ECF7EFF475A3EDE0F83
3968roblox-studio-1-6-1-9670.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_A4CF52CCA82D7458083F7280801A3A04binary
MD5:8A70FF4AA7E3578A00E674416203EE2F
SHA256:CE308BE5A7D93FC7A28F220A6B7068EA798BBBAD16085EB409856C73F18A0F4B
3968roblox-studio-1-6-1-9670.exeC:\Users\admin\AppData\Local\Temp\crashpad_roblox\settings.datbinary
MD5:B6688C6280393663338238CFE28140C9
SHA256:1059E9BC1674BA0F6BE72B8199313260261C2EF327D2DC5A8B585CFE98D1FAFD
3968roblox-studio-1-6-1-9670.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Ebinary
MD5:2FB1E3C170A874D307353A9FB2AFDB34
SHA256:1B25B5705735EB01696ABB4B52291EA2B362441105285C0F768CEA9A21D66695
3968roblox-studio-1-6-1-9670.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_BACC6CD2B29F18349081C9FD2343833Bbinary
MD5:61D271A64B21B901FF7268B77029BAEC
SHA256:FBD95B765C605F4F120E4AEA938CC7FEEED224BBC2C538E39E775F4199C8CE16
3968roblox-studio-1-6-1-9670.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:716B46DFE2F84B7D88F81A35DA904E58
SHA256:19FADF8DCC7AE312B336DBB998458937E0F6ED78F4C90A34AB0F3F94DCBC9B3E
3968roblox-studio-1-6-1-9670.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Ebinary
MD5:11AAEE8FA8F90B286DDF8C255DC6311E
SHA256:A98CF457F60A84A43F03A60A270EABAA9446EC88EE70E6D8114B025EE67F7017
3968roblox-studio-1-6-1-9670.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_BACC6CD2B29F18349081C9FD2343833Bbinary
MD5:991C45E0905E89D2CAFC52084BE58C7D
SHA256:DF1972371D25AEA90F0A4606ED6C7AEA47EDFEE870ADD714395F81C7D97559EC
3968roblox-studio-1-6-1-9670.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\WindowsStudio[1].jsonbinary
MD5:E99F72728F7867015B121DE5BAFE51BB
SHA256:F4CF1B4AD1523077A2557EA1C52FC02E5CB20868428964CECC51C6AE72C962B4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
21
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3968
roblox-studio-1-6-1-9670.exe
GET
304
23.50.131.216:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?2523fedc70fa6bf1
unknown
unknown
3968
roblox-studio-1-6-1-9670.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
unknown
3968
roblox-studio-1-6-1-9670.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
unknown
3968
roblox-studio-1-6-1-9670.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEBN9U5yqfDGppDNwGWiEeo0%3D
unknown
unknown
3968
roblox-studio-1-6-1-9670.exe
GET
200
18.245.39.64:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
unknown
unknown
3968
roblox-studio-1-6-1-9670.exe
GET
200
108.138.2.107:80
http://o.ss2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
unknown
unknown
3968
roblox-studio-1-6-1-9670.exe
GET
200
18.245.39.64:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
3968
roblox-studio-1-6-1-9670.exe
23.41.252.19:443
clientsettingscdn.roblox.com
AKAMAI-AS
MX
unknown
3968
roblox-studio-1-6-1-9670.exe
23.50.131.216:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
3968
roblox-studio-1-6-1-9670.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3968
roblox-studio-1-6-1-9670.exe
128.116.122.4:443
ephemeralcounters.api.roblox.com
ROBLOX-PRODUCTION
US
unknown
928
roblox-studio-1-6-1-9670.exe
23.41.252.19:443
clientsettingscdn.roblox.com
AKAMAI-AS
MX
unknown
3968
roblox-studio-1-6-1-9670.exe
104.18.38.233:80
ocsp.comodoca.com
CLOUDFLARENET
shared
1088
svchost.exe
224.0.0.252:5355
unknown

DNS requests

Domain
IP
Reputation
clientsettingscdn.roblox.com
  • 23.41.252.19
unknown
ctldl.windowsupdate.com
  • 23.50.131.216
  • 23.50.131.200
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ephemeralcounters.api.roblox.com
  • 128.116.122.4
whitelisted
ocsp.comodoca.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
ocsp.usertrust.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
setup.rbxcdn.qq.com
  • 0.0.0.1
unknown
clientsettingscdn.roblox.qq.com
  • 0.0.0.1
unknown
setup.rbxcdn.com
  • 13.224.189.122
  • 13.224.189.83
  • 13.224.189.57
  • 13.224.189.58
whitelisted
setup-ak.rbxcdn.com
  • 23.48.23.156
  • 23.48.23.144
whitelisted

Threats

No threats detected
No debug info