File name:

Bunni.exe

Full analysis: https://app.any.run/tasks/a602ada4-0b38-45f5-8818-cd702d9a85ee
Verdict: Malicious activity
Analysis date: July 19, 2025, 07:52:55
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
rust
roblox
arch-doc
arch-scr
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections
MD5:

26BF1D5C1AEAE5F545BC1501FC3B8821

SHA1:

3308C38EF73629A2C0B420614A5B638CAEF38EC7

SHA256:

2B41E8AE4953236929B643135E158474E4CBB538D11B4842C5BCC896F9481EBB

SSDEEP:

98304:LUUUy7UHwU+l2CIGRCAeeeqEvFawKss32GEm5xmhfpWI+54wpS3FKmARKWTDxC2V:8s26dIqJg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Creates file in the systems drive root

      • Bunni.exe (PID: 6840)
    • There is functionality for taking screenshot (YARA)

      • Bunni.exe (PID: 6840)
      • Bunni.exe (PID: 6572)
      • Bunni.exe (PID: 8028)
      • Bunni.exe (PID: 3584)
      • Bunni.exe (PID: 2216)
      • Bunni.exe (PID: 7772)
      • Bunni.exe (PID: 7492)
    • Executable content was dropped or overwritten

      • RobloxPlayerInstaller.exe (PID: 6704)
      • MicrosoftEdgeWebview2Setup.exe (PID: 6164)
      • RobloxPlayerBeta.exe (PID: 7460)
      • RobloxPlayerBeta.exe (PID: 5548)
    • Changes default file association

      • RobloxPlayerInstaller.exe (PID: 6704)
    • Process drops legitimate windows executable

      • RobloxPlayerInstaller.exe (PID: 6704)
      • MicrosoftEdgeUpdate.exe (PID: 5552)
      • MicrosoftEdgeWebview2Setup.exe (PID: 6164)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeUpdate.exe (PID: 5552)
    • Disables SEHOP

      • MicrosoftEdgeUpdate.exe (PID: 5552)
    • Creates a software uninstall entry

      • RobloxPlayerInstaller.exe (PID: 6704)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 5552)
    • Executes application which crashes

      • RobloxPlayerBeta.exe (PID: 7460)
      • RobloxPlayerInstaller.exe (PID: 6704)
      • RobloxPlayerBeta.exe (PID: 5548)
  • INFO

    • Reads the computer name

      • Bunni.exe (PID: 6840)
      • RobloxPlayerInstaller.exe (PID: 6704)
      • Bunni.exe (PID: 6572)
      • MicrosoftEdgeUpdate.exe (PID: 5552)
      • identity_helper.exe (PID: 7848)
      • Bunni.exe (PID: 8028)
      • Bunni.exe (PID: 3584)
      • Bunni.exe (PID: 7492)
      • Bunni.exe (PID: 2216)
      • Bunni.exe (PID: 7772)
      • Bunni.exe (PID: 7320)
    • Checks supported languages

      • Bunni.exe (PID: 6840)
      • RobloxPlayerInstaller.exe (PID: 6704)
      • Bunni.exe (PID: 6572)
      • MicrosoftEdgeWebview2Setup.exe (PID: 6164)
      • MicrosoftEdgeUpdate.exe (PID: 5552)
      • RobloxPlayerBeta.exe (PID: 7460)
      • Bunni.exe (PID: 8028)
      • identity_helper.exe (PID: 7848)
      • Bunni.exe (PID: 3584)
      • Bunni.exe (PID: 7492)
      • Bunni.exe (PID: 2216)
      • Bunni.exe (PID: 7772)
      • Bunni.exe (PID: 7320)
      • RobloxPlayerBeta.exe (PID: 5548)
    • Application based on Rust

      • Bunni.exe (PID: 6840)
      • Bunni.exe (PID: 6572)
      • Bunni.exe (PID: 8028)
      • Bunni.exe (PID: 3584)
      • Bunni.exe (PID: 7492)
      • Bunni.exe (PID: 2216)
      • Bunni.exe (PID: 7772)
    • Manual execution by a user

      • RobloxPlayerInstaller.exe (PID: 6704)
      • WinRAR.exe (PID: 2168)
      • Bunni.exe (PID: 6572)
      • msedge.exe (PID: 4264)
      • Bunni.exe (PID: 8028)
      • Bunni.exe (PID: 3584)
      • Bunni.exe (PID: 7492)
      • Bunni.exe (PID: 6308)
      • Bunni.exe (PID: 2216)
      • Bunni.exe (PID: 7732)
      • Bunni.exe (PID: 7772)
      • Bunni.exe (PID: 7320)
      • RobloxPlayerBeta.exe (PID: 5548)
    • ROBLOX mutex has been found

      • RobloxPlayerInstaller.exe (PID: 6704)
    • Creates files or folders in the user directory

      • RobloxPlayerInstaller.exe (PID: 6704)
      • wermgr.exe (PID: 3872)
      • WerFault.exe (PID: 7528)
      • WerFault.exe (PID: 8184)
      • WerFault.exe (PID: 8044)
    • Process checks whether UAC notifications are on

      • RobloxPlayerInstaller.exe (PID: 6704)
    • Reads the machine GUID from the registry

      • RobloxPlayerInstaller.exe (PID: 6704)
      • RobloxPlayerBeta.exe (PID: 5548)
    • Creates files in the program directory

      • RobloxPlayerInstaller.exe (PID: 6704)
      • MicrosoftEdgeWebview2Setup.exe (PID: 6164)
    • The sample compiled with english language support

      • RobloxPlayerInstaller.exe (PID: 6704)
      • MicrosoftEdgeWebview2Setup.exe (PID: 6164)
      • MicrosoftEdgeUpdate.exe (PID: 5552)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2168)
    • Create files in a temporary directory

      • RobloxPlayerInstaller.exe (PID: 6704)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 5552)
      • identity_helper.exe (PID: 7848)
    • Process checks computer location settings

      • MicrosoftEdgeUpdate.exe (PID: 5552)
    • Checks proxy server information

      • MicrosoftEdgeUpdate.exe (PID: 5552)
      • wermgr.exe (PID: 3872)
      • WerFault.exe (PID: 7528)
      • WerFault.exe (PID: 8184)
      • slui.exe (PID: 5416)
      • WerFault.exe (PID: 8044)
    • Application launched itself

      • msedge.exe (PID: 4264)
    • Reads the software policy settings

      • MicrosoftEdgeUpdate.exe (PID: 5552)
      • wermgr.exe (PID: 3872)
      • WerFault.exe (PID: 7528)
      • WerFault.exe (PID: 8184)
      • slui.exe (PID: 5416)
      • WerFault.exe (PID: 8044)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:07:01 20:04:22+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.43
CodeSize: 8476672
InitializedDataSize: 5410304
UninitializedDataSize: -
EntryPoint: 0x7f4094
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 0.1.0.0
ProductVersionNumber: 0.1.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
ProductName: Bunni
ProductVersion: 0.1.0
FileDescription: Bunni
FileVersion: 0.1.0
CompanyName: Bunni
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
211
Monitored processes
49
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start bunni.exe robloxplayerinstaller.exe winrar.exe bunni.exe microsoftedgewebview2setup.exe microsoftedgeupdate.exe msedge.exe wermgr.exe slui.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs robloxplayerbeta.exe werfault.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs bunni.exe werfault.exe bunni.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs bunni.exe msedge.exe no specs bunni.exe no specs bunni.exe msedge.exe no specs bunni.exe no specs bunni.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs bunni.exe rundll32.exe no specs msedge.exe no specs robloxplayerbeta.exe werfault.exe msedge.exe no specs msedge.exe no specs bunni.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
32"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6912,i,11597036951499037799,2278701647934775843,262144 --variations-seed-version --mojo-platform-channel-handle=5536 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
480"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6980,i,11597036951499037799,2278701647934775843,262144 --variations-seed-version --mojo-platform-channel-handle=7096 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1944"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --disable-quic --message-loop-type-ui --string-annotations --always-read-main-dll --field-trial-handle=5732,i,11597036951499037799,2278701647934775843,262144 --variations-seed-version --mojo-platform-channel-handle=4060 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2168"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\realese.zip" C:\Users\admin\Desktop\C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2216"C:\Users\admin\Desktop\Bunni.exe" C:\Users\admin\Desktop\Bunni.exe
explorer.exe
User:
admin
Company:
Bunni
Integrity Level:
HIGH
Description:
Bunni
Version:
0.1.0
Modules
Images
c:\users\admin\desktop\bunni.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\combase.dll
c:\windows\system32\gdi32.dll
2384"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --always-read-main-dll --field-trial-handle=3640,i,11597036951499037799,2278701647934775843,262144 --variations-seed-version --mojo-platform-channel-handle=3656 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2808"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --string-annotations --gpu-preferences=UAAAAAAAAADgAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAAACAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=2400,i,11597036951499037799,2278701647934775843,262144 --variations-seed-version --mojo-platform-channel-handle=2384 /prefetch:2C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3148"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=4272,i,11597036951499037799,2278701647934775843,262144 --variations-seed-version --mojo-platform-channel-handle=5988 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3584"C:\Users\admin\Desktop\Bunni.exe" C:\Users\admin\Desktop\Bunni.exe
explorer.exe
User:
admin
Company:
Bunni
Integrity Level:
HIGH
Description:
Bunni
Version:
0.1.0
Modules
Images
c:\users\admin\desktop\bunni.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\combase.dll
c:\windows\system32\gdi32.dll
3832"C:\Bunni.exe" C:\Bunni.exeexplorer.exe
User:
admin
Company:
Bunni
Integrity Level:
MEDIUM
Description:
Bunni
Exit code:
3221226540
Version:
0.1.0
Modules
Images
c:\bunni.exe
c:\windows\system32\ntdll.dll
Total events
20 806
Read events
20 711
Write events
87
Delete events
8

Modification events

(PID) Process:(6704) RobloxPlayerInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\ProtocolExecute\roblox-studio
Operation:writeName:WarnOnOpen
Value:
0
(PID) Process:(6704) RobloxPlayerInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\roblox-studio
Operation:writeName:URL Protocol
Value:
(PID) Process:(6704) RobloxPlayerInstaller.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\roblox-studio\shell\open\command
Operation:writeName:version
Value:
version-cc8f13de4c4e43de
(PID) Process:(2168) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2168) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2168) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2168) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(5552) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MicrosoftEdgeUpdate.exe
Operation:writeName:DisableExceptionChainValidation
Value:
0
(PID) Process:(5552) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\PersistedPings\{CDF245F8-17F5-4120-BCAB-C3C6D11D80FD}
Operation:writeName:PersistedPingString
Value:
<?xml version="1.0" encoding="UTF-8"?><request protocol="3.0" updater="Omaha" updaterversion="1.3.195.45" shell_version="1.3.147.37" ismachine="1" sessionid="{8816B52E-9628-46A2-BDF9-F7BF3CDD0009}" userid="{FD984739-A122-4DB0-BE5B-46E3E09D84E4}" installsource="otherinstallcmd" requestid="{CDF245F8-17F5-4120-BCAB-C3C6D11D80FD}" dedup="cr" domainjoined="0"><hw logical_cpus="4" physmemory="4" disk_type="2" sse="1" sse2="1" sse3="1" ssse3="1" sse41="1" sse42="1" avx="1"/><os platform="win" version="10.0.19045.4046" sp="" arch="x64" product_type="48" is_wip="0" is_in_lockdown_mode="0"/><oem product_manufacturer="DELL" product_name="DELL"/><exp etag="&quot;r452t1+k2Tgq/HXzjvFNBRhopBWR9sbjXxqeUDH9uX0=&quot;"/><app appid="{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}" version="1.3.195.43" nextversion="1.3.195.45" lang="" brand="" client=""><event eventtype="2" eventresult="1" errorcode="0" extracode1="0" system_uptime_ticks="16748551665" install_time_ms="214"/></app></request>
(PID) Process:(5552) MicrosoftEdgeUpdate.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\PersistedPings\{CDF245F8-17F5-4120-BCAB-C3C6D11D80FD}
Operation:writeName:PersistedPingTime
Value:
133973852313510932
Executable files
244
Suspicious files
497
Text files
117
Unknown types
0

Dropped files

PID
Process
Filename
Type
6704RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\41669728ff75ab2c7de7f34665c20c12
MD5:
SHA256:
6704RobloxPlayerInstaller.exeC:\Program Files (x86)\Roblox\Versions\RobloxStudioInstaller.exeexecutable
MD5:E7A62F78B3FD269D63A784C12C711D3D
SHA256:D8A8A5DB13C2830B6AED73B2A9FC2D47B871163906265DABE09A70D6871AF2D7
2168WinRAR.exeC:\Users\admin\Desktop\bin\RobloxPlayerBeta.dllexecutable
MD5:00114EB9091FA3B120B3A082D9FA3263
SHA256:722BFA296FFE403A21A8EB49705E31144C1096139ABADE1EB798FDDA5F0BC4D2
2168WinRAR.exeC:\Users\admin\Desktop\bin\Loader.exeexecutable
MD5:1C16A6D91BC0120C5029ED36063C188B
SHA256:326D05405EF63D5930FCE20BB649C5D3D047343D20418A54F86AC5F0B5C884AF
6704RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\1ec0bd2b90d181025de557862bda0e6bcompressed
MD5:1EC0BD2B90D181025DE557862BDA0E6B
SHA256:75D6C7197E669706B665D154BE11BB0B63D5CBA1EA6059123B439F65427C6764
6704RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\081deafb4476db284d1f0080d6f22b1acompressed
MD5:081DEAFB4476DB284D1F0080D6F22B1A
SHA256:AF92D09567C02DD7F08D0A20D73B42A70D0C3B992DE468CC851B69BE9E2DD4A7
6704RobloxPlayerInstaller.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Roblox\Roblox Studio.lnkbinary
MD5:C2E44FB85A3B8D04B61AB78F6306974B
SHA256:28BBAD615E292750D35A9BB91440C64B2E18CA443819BC3E0BE31865BA8C5DA6
2168WinRAR.exeC:\Users\admin\Desktop\x.txttext
MD5:09600F565E213BD6044311B6E1BE5F67
SHA256:0E92DD9E8745FFF8822FB300CED1DAC9610B0F792F6EF2E887BA1103C282A6C0
6704RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\5fe3ebab23de62304fae1a8d19ab7afecompressed
MD5:5FE3EBAB23DE62304FAE1A8D19AB7AFE
SHA256:727624F8059AEC7DD22E4C39F0D31D7A36DD6CFFD557E33DEB83832459D01BF4
6704RobloxPlayerInstaller.exeC:\Users\admin\Desktop\Roblox Studio.lnkbinary
MD5:33E347502E7CCF44382CC1FA7BFA5B4D
SHA256:DCB9AABAB98E859DC2523D6685EE2F11B0020A283F36D2D4DD5C336421AAAF40
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
27
TCP/UDP connections
130
DNS requests
115
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6356
svchost.exe
HEAD
200
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/4c4fdee0-d69c-42b7-bf5c-3ec046e9dfc9?P1=1753264628&P2=404&P3=2&P4=cKyW%2bQZMk0hAr9e%2fGbG%2fIhTOzQ%2frCo%2fioPAf05ASdz7Ip%2fT57dPRfo4hEt2c9CwYPTZKaIINhPJ0HkBL5iYnnQ%3d%3d
unknown
whitelisted
5328
SearchApp.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6356
svchost.exe
GET
200
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/4c4fdee0-d69c-42b7-bf5c-3ec046e9dfc9?P1=1753264628&P2=404&P3=2&P4=cKyW%2bQZMk0hAr9e%2fGbG%2fIhTOzQ%2frCo%2fioPAf05ASdz7Ip%2fT57dPRfo4hEt2c9CwYPTZKaIINhPJ0HkBL5iYnnQ%3d%3d
unknown
whitelisted
6356
svchost.exe
GET
200
199.232.210.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9244b52a-55cc-41a2-b7c4-7f4983d8753c?P1=1753264636&P2=404&P3=2&P4=QdmV33mkW1FE76ktVUXoE%2flZuAmwYzTEI2UBf2WZGKXxmA71DjU9rhG4%2b6MNVn8DgLSpSpuVWlbp879oqKPhiA%3d%3d
unknown
whitelisted
1588
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3872
wermgr.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6756
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3872
wermgr.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1588
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2752
svchost.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1636
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
6756
svchost.exe
40.126.31.1:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6756
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
23.55.110.193:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.184.238
whitelisted
login.live.com
  • 40.126.31.1
  • 40.126.31.73
  • 20.190.159.130
  • 40.126.31.3
  • 20.190.159.131
  • 20.190.159.4
  • 40.126.31.2
  • 20.190.159.129
  • 20.190.160.67
  • 20.190.160.65
  • 20.190.160.22
  • 20.190.160.64
  • 40.126.32.133
  • 20.190.160.130
  • 40.126.32.136
  • 20.190.160.128
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 184.30.131.245
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.55.110.193
  • 23.55.110.211
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
ecsv2.roblox.com
  • 128.116.44.3
whitelisted
clientsettingscdn.roblox.com
  • 23.41.252.19
whitelisted

Threats

No threats detected
Process
Message
Bunni.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Bunni.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
RobloxPlayerInstaller.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Bunni.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Bunni.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Bunni.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Bunni.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Bunni.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Bunni.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
Bunni.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.