File name:

RobloxPlayerLauncher.exe

Full analysis: https://app.any.run/tasks/4eed6991-5e9c-45d6-8604-93c2b6ecace8
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: March 24, 2024, 13:02:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

F5760174D03036D8D67530017D775A06

SHA1:

C933B3E8B1D3FB02B3B5DF63C9D7CEF3EC3C6B59

SHA256:

3BCB478FDCCF67E09A8CFFF08378AE7E3B756707FF342646B92C672880C65B26

SSDEEP:

12288:rH7mmzFnQy4c6eZOvUvibNpo2YY4YAcNAucrIF40FHj0h04Tg:r6y4c6eIUvibLqrROG0Nj0hpTg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • RobloxPlayerLauncher.exe (PID: 3992)
  • SUSPICIOUS

    • Reads the Internet Settings

      • RobloxPlayerLauncher.exe (PID: 3992)
      • RBX-CA62CB32.tmp (PID: 2756)
      • RBX-CA62CB32.tmp (PID: 2372)
    • Reads security settings of Internet Explorer

      • RobloxPlayerLauncher.exe (PID: 3992)
      • RBX-CA62CB32.tmp (PID: 2756)
      • RBX-CA62CB32.tmp (PID: 2372)
    • Checks Windows Trust Settings

      • RobloxPlayerLauncher.exe (PID: 3992)
      • RBX-CA62CB32.tmp (PID: 2756)
      • RBX-CA62CB32.tmp (PID: 2372)
    • Reads settings of System Certificates

      • RobloxPlayerLauncher.exe (PID: 3992)
      • RBX-CA62CB32.tmp (PID: 2756)
      • RBX-CA62CB32.tmp (PID: 2372)
    • Application launched itself

      • RBX-CA62CB32.tmp (PID: 2756)
    • Process requests binary or script from the Internet

      • RobloxPlayerLauncher.exe (PID: 3992)
    • Starts application with an unusual extension

      • RobloxPlayerLauncher.exe (PID: 3992)
      • RBX-CA62CB32.tmp (PID: 2756)
    • Executable content was dropped or overwritten

      • RobloxPlayerLauncher.exe (PID: 3992)
  • INFO

    • Reads the computer name

      • RobloxPlayerLauncher.exe (PID: 3992)
      • RBX-CA62CB32.tmp (PID: 2756)
      • RBX-CA62CB32.tmp (PID: 2372)
    • Checks proxy server information

      • RobloxPlayerLauncher.exe (PID: 3992)
      • RBX-CA62CB32.tmp (PID: 2756)
      • RBX-CA62CB32.tmp (PID: 2372)
    • Checks supported languages

      • RobloxPlayerLauncher.exe (PID: 3992)
      • RBX-CA62CB32.tmp (PID: 2756)
      • RBX-CA62CB32.tmp (PID: 2372)
    • Create files in a temporary directory

      • RobloxPlayerLauncher.exe (PID: 3992)
      • RBX-CA62CB32.tmp (PID: 2756)
      • RBX-CA62CB32.tmp (PID: 2372)
    • Reads the machine GUID from the registry

      • RobloxPlayerLauncher.exe (PID: 3992)
      • RBX-CA62CB32.tmp (PID: 2756)
      • RBX-CA62CB32.tmp (PID: 2372)
    • Reads the software policy settings

      • RobloxPlayerLauncher.exe (PID: 3992)
      • RBX-CA62CB32.tmp (PID: 2756)
      • RBX-CA62CB32.tmp (PID: 2372)
    • Creates files or folders in the user directory

      • RobloxPlayerLauncher.exe (PID: 3992)
      • RBX-CA62CB32.tmp (PID: 2756)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2014:10:06 09:31:07+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 389120
InitializedDataSize: 251392
UninitializedDataSize: -
EntryPoint: 0x40833
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.6.3.52407
ProductVersionNumber: 1.6.3.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: ROBLOX Corporation
FileDescription: Roblox
FileVersion: 1, 6, 3, 52407
LegalCopyright: (C) 2012 ROBLOX Corporation. All rights reserved.
OriginalFileName: Roblox.exe
ProductName: Roblox Bootstrapper
ProductVersion: 1, 6, 3, 0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start robloxplayerlauncher.exe rbx-ca62cb32.tmp rbx-ca62cb32.tmp

Process information

PID
CMD
Path
Indicators
Parent process
2372C:\Users\admin\AppData\Local\Temp\RBX-CA62CB32.tmp --crashpad --no-rate-limit --database=C:\Users\admin\AppData\Local\Temp\crashpad_roblox --metrics-dir=C:\Users\admin\AppData\Local\Temp\crashpad_roblox --url=https://upload.crashes.rbxinfra.com/post --annotation=RobloxChannel=production --annotation=RobloxGitHash=fde48f439a9af7a7f1b323bea0e4a5d1febc3390 --annotation=UploadAttachmentKiloByteLimit=100 --annotation=UploadPercentage=100 --annotation=format=minidump --annotation=token=a2440b0bfdada85f34d79b43839f2b49ea6bba474bd7d126e844bc119271a1c3 --initial-client-data=0x59c,0x5a0,0x5a4,0x578,0x5ac,0x1081330,0x1081340,0x1081350C:\Users\admin\AppData\Local\Temp\RBX-CA62CB32.tmp
RBX-CA62CB32.tmp
User:
admin
Company:
Roblox Corporation
Integrity Level:
MEDIUM
Description:
Roblox
Exit code:
0
Version:
1, 6, 0, 5880517
Modules
Images
c:\users\admin\appdata\local\temp\rbx-ca62cb32.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2756"C:\Users\admin\AppData\Local\Temp\RBX-CA62CB32.tmp" C:\Users\admin\AppData\Local\Temp\RBX-CA62CB32.tmp
RobloxPlayerLauncher.exe
User:
admin
Company:
Roblox Corporation
Integrity Level:
MEDIUM
Description:
Roblox
Exit code:
0
Version:
1, 6, 0, 5880517
Modules
Images
c:\users\admin\appdata\local\temp\rbx-ca62cb32.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3992"C:\Users\admin\AppData\Local\Temp\RobloxPlayerLauncher.exe" C:\Users\admin\AppData\Local\Temp\RobloxPlayerLauncher.exe
explorer.exe
User:
admin
Company:
ROBLOX Corporation
Integrity Level:
MEDIUM
Description:
Roblox
Version:
1, 6, 3, 52407
Modules
Images
c:\users\admin\appdata\local\temp\robloxplayerlauncher.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
13 108
Read events
12 969
Write events
117
Delete events
22

Modification events

(PID) Process:(3992) RobloxPlayerLauncher.exeKey:HKEY_CURRENT_USER\Software\ROBLOX Corporation\Roblox
Operation:writeName:CPath
Value:
C:\Users\admin\AppData\LocalLow\rbxcsettings.rbx
(PID) Process:(3992) RobloxPlayerLauncher.exeKey:HKEY_CURRENT_USER\Software\ROBLOX Corporation\Roblox
Operation:delete valueName:curStudioVer
Value:
(PID) Process:(3992) RobloxPlayerLauncher.exeKey:HKEY_CURRENT_USER\Software\ROBLOX Corporation\Roblox
Operation:delete valueName:curStudioUrl
Value:
(PID) Process:(3992) RobloxPlayerLauncher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3992) RobloxPlayerLauncher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3992) RobloxPlayerLauncher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3992) RobloxPlayerLauncher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3992) RobloxPlayerLauncher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(3992) RobloxPlayerLauncher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
(PID) Process:(3992) RobloxPlayerLauncher.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoConfigURL
Value:
Executable files
1
Suspicious files
7
Text files
5
Unknown types
6

Dropped files

PID
Process
Filename
Type
3992RobloxPlayerLauncher.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\72BA427A91F50409B9EAC87F2B59B951_2033B9334DC92599122A3B9136FA3F05der
MD5:8E0ED12F06BC8C233775494BDEAEA43C
SHA256:3C3F6FD69716E791614E67FDD7FFFF2A41DBE44FAC9D4107390465F8BAF9AEDC
3992RobloxPlayerLauncher.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_BACC6CD2B29F18349081C9FD2343833Bbinary
MD5:E41FE9AA800C7B8E751FF3681904DF13
SHA256:AD2CE57A0E0074FDDAECE35FB4E129E192B3BC92896B81D9CB91BF849B64A511
3992RobloxPlayerLauncher.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Ebinary
MD5:DE47F603FC0AC356CADED6C2C821E652
SHA256:5CB7DE8F7D435C43DE091B680B00029FCAB944296C57647C07EA9E386BCF0D3F
3992RobloxPlayerLauncher.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\72BA427A91F50409B9EAC87F2B59B951_2033B9334DC92599122A3B9136FA3F05binary
MD5:8DCE304F80420FF42A28EFCF86B508DF
SHA256:67C3605C78C2BF7413A70EB4C98800ED2DD1B788C1A8279430D6949F7445C559
3992RobloxPlayerLauncher.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711Eder
MD5:8E111DD59E6AC104EC96931D9DADDB52
SHA256:2AF2A019DEF88C161803F1CFA264F50AC28D5CAEE002CF8D73DAA7C93E3C998B
3992RobloxPlayerLauncher.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:9CA366106CD2B57135982FCB5138ED56
SHA256:F0253EFF707D04EA9577A2CEACDC7A3412A662745E13812269AB20C3E90A905A
3992RobloxPlayerLauncher.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_BACC6CD2B29F18349081C9FD2343833Bder
MD5:6738AE091EDC7A209C4018A7B44BD92C
SHA256:574B36B9BEDA840E0AD436B820A62CD01A390A75BD2AFB3D9D920EF006593B0F
2756RBX-CA62CB32.tmpC:\Users\admin\AppData\Local\Temp\crashpad_roblox\settings.datbinary
MD5:5CF7FCA6FAAA48377F5462EB3509A617
SHA256:0D5F60928306FC3DE07C467AF609B6D26AD5052D91477F606E0DD1B803C54CAC
2756RBX-CA62CB32.tmpC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B398B80134F72209547439DB21AB308D_A4CF52CCA82D7458083F7280801A3A04binary
MD5:16222DCA7E2316EF866A5C84B7DA67CD
SHA256:3E65B0D2823720EFAC21A9CBD7964BBB53C03ABEE375B8FC9E6FF907D4B4D342
2756RBX-CA62CB32.tmpC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\BatchIncrement[1].jsontext
MD5:BEDBF7D7D69748886E9B48F45C75FBBE
SHA256:B4A55CFD050F4A62B1C4831CA0AB6FFADDE1FE1C3F583917EADE12F8C6726F61
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
22
DNS requests
29
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3992
RobloxPlayerLauncher.exe
GET
307
128.116.119.4:80
http://clientsettings.api.roblox.com/Setting/QuietGet/WindowsBootstrapperSettings/?apiKey=76E5A40C-3AE1-4028-9F10-7C62520BD94F
unknown
unknown
3992
RobloxPlayerLauncher.exe
GET
304
23.216.77.62:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c41d92d6b09abc02
unknown
unknown
3992
RobloxPlayerLauncher.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
binary
1.42 Kb
unknown
3992
RobloxPlayerLauncher.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEBN9U5yqfDGppDNwGWiEeo0%3D
unknown
binary
2.18 Kb
unknown
3992
RobloxPlayerLauncher.exe
GET
200
172.64.149.23:80
http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBQh80WaEMqmyEvaHjlisSfVM4p8SAQUF9nWJSdn%2BTHCSUPZMDZEjGypT%2BsCEQD8GvtbaL%2Bw3YUEm%2BTVJtmE
unknown
binary
472 b
unknown
3992
RobloxPlayerLauncher.exe
GET
200
16.182.39.192:80
http://setup.roblox.com/version?guid20639
unknown
text
24 b
unknown
3992
RobloxPlayerLauncher.exe
GET
200
16.182.39.192:80
http://setup.roblox.com/version-6552be68b05d41a5-RobloxVersion.txt
unknown
text
16 b
unknown
3992
RobloxPlayerLauncher.exe
GET
200
16.182.39.192:80
http://setup.roblox.com/cdn.txt
unknown
16 b
unknown
3992
RobloxPlayerLauncher.exe
GET
200
13.224.189.57:80
http://setup.rbxcdn.com/version-6552be68b05d41a5-RobloxPlayerLauncher.exe
unknown
executable
4.69 Mb
unknown
2756
RBX-CA62CB32.tmp
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3992
RobloxPlayerLauncher.exe
128.116.119.4:80
clientsettings.api.roblox.com
ROBLOX-PRODUCTION
US
unknown
3992
RobloxPlayerLauncher.exe
128.116.119.4:443
clientsettings.api.roblox.com
ROBLOX-PRODUCTION
US
unknown
3992
RobloxPlayerLauncher.exe
23.216.77.62:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
3992
RobloxPlayerLauncher.exe
104.18.38.233:80
ocsp.comodoca.com
CLOUDFLARENET
shared
3992
RobloxPlayerLauncher.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
unknown
3992
RobloxPlayerLauncher.exe
16.182.39.192:80
setup.roblox.com
US
unknown

DNS requests

Domain
IP
Reputation
clientsettings.api.roblox.com
  • 128.116.119.4
unknown
ctldl.windowsupdate.com
  • 23.216.77.62
  • 23.216.77.66
  • 23.216.77.50
  • 23.216.77.69
  • 23.216.77.47
  • 23.216.77.48
  • 23.216.77.54
  • 23.216.77.68
  • 23.216.77.75
  • 23.216.77.79
  • 23.216.77.78
  • 23.216.77.72
  • 23.216.77.77
whitelisted
ocsp.comodoca.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
ocsp.usertrust.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
ocsp.sectigo.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted
setup.roblox.com
  • 16.182.39.192
  • 16.182.37.120
  • 52.216.166.45
  • 52.217.122.176
  • 52.217.140.64
  • 52.217.160.8
  • 52.217.195.64
  • 52.216.28.30
shared
setup.rbxcdn.com
  • 13.224.189.57
  • 13.224.189.83
  • 13.224.189.58
  • 13.224.189.122
whitelisted
clientsettingscdn.roblox.com
  • 23.41.252.19
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ephemeralcounters.api.roblox.com
  • 128.116.119.4
whitelisted

Threats

PID
Process
Class
Message
3992
RobloxPlayerLauncher.exe
Potential Corporate Privacy Violation
AV POLICY HTTP request for .exe file with no User-Agent
3992
RobloxPlayerLauncher.exe
Potentially Bad Traffic
ET POLICY Executable served from Amazon S3
3992
RobloxPlayerLauncher.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
3992
RobloxPlayerLauncher.exe
Misc activity
ET INFO EXE - Served Inline HTTP
1 ETPRO signatures available at the full report
No debug info