| File name: | RobloxStudioLauncherBeta.itch.io.exe |
| Full analysis: | https://app.any.run/tasks/cbaae936-17d7-465a-91ac-260a6c8d5e83 |
| Verdict: | Malicious activity |
| Analysis date: | May 18, 2025, 00:35:26 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections |
| MD5: | 0D3AD3E8536C7FC109A6E0D7D0F4602F |
| SHA1: | 50B2854B85C719219EB90FEA2B9840A679DBB951 |
| SHA256: | 3CB2387973D95E8F14981163E2C4C99C1276D76AECD1799817BFEA0B853C7DC0 |
| SSDEEP: | 49152:kBzJ/8cO2kzY2K9rCDfrpTEMEYLcJgCZtY4mBZ+zaWi2tmlToxMGPMQ3dA4koNmU:ktL2K9gTEMEYLcVZtY4mBimH0 |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1982:08:03 23:42:01+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.29 |
| CodeSize: | 1095680 |
| InitializedDataSize: | 702976 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xd63d2 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.6.0.41861 |
| ProductVersionNumber: | 1.6.0.41861 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Roblox Corporation |
| FileDescription: | Roblox |
| FileVersion: | 1, 6, 0, 5350277 |
| LegalCopyright: | Copyright © 2020 Roblox Corporation. All rights reserved. |
| OriginalFileName: | Roblox.exe |
| ProductName: | Roblox Bootstrapper |
| ProductVersion: | 1, 6, 0, 5350277 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 7284 | "C:\Users\admin\AppData\Local\Temp\RobloxStudioLauncherBeta.itch.io.exe" | C:\Users\admin\AppData\Local\Temp\RobloxStudioLauncherBeta.itch.io.exe | explorer.exe | ||||||||||||
User: admin Company: Roblox Corporation Integrity Level: MEDIUM Description: Roblox Exit code: 0 Version: 1, 6, 0, 5350277 Modules
| |||||||||||||||
| 7380 | C:\Users\admin\AppData\Local\Temp\RobloxStudioLauncherBeta.itch.io.exe --crashpad --no-rate-limit --database=C:\Users\admin\AppData\Local\Temp\crashpad_roblox --metrics-dir=C:\Users\admin\AppData\Local\Temp\crashpad_roblox --url=https://upload.crashes.rbxinfra.com/post --annotation=RobloxChannel=production --annotation=RobloxGitHash=75e94a4b5553853bd615ec818ff02126b395c631 --annotation=UploadAttachmentKiloByteLimit=100 --annotation=UploadPercentage=0 --annotation=format=minidump --annotation=token=a2440b0bfdada85f34d79b43839f2b49ea6bba474bd7d126e844bc119271a1c3 --initial-client-data=0x7bc,0x7c0,0x7c4,0x794,0x7cc,0x8fd440,0x8fd450,0x8fd460 | C:\Users\admin\AppData\Local\Temp\RobloxStudioLauncherBeta.itch.io.exe | RobloxStudioLauncherBeta.itch.io.exe | ||||||||||||
User: admin Company: Roblox Corporation Integrity Level: MEDIUM Description: Roblox Exit code: 0 Version: 1, 6, 0, 5350277 Modules
| |||||||||||||||
| 7528 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7560 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | — | SppExtComObj.Exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7720 | "C:\Users\admin\AppData\Local\Temp\RBX-A8EDE641\RobloxStudioLauncherBeta.exe" | C:\Users\admin\AppData\Local\Temp\RBX-A8EDE641\RobloxStudioLauncherBeta.exe | RobloxStudioLauncherBeta.itch.io.exe | ||||||||||||
User: admin Company: Roblox Corporation Integrity Level: MEDIUM Description: Roblox Version: 1, 6, 0, 6730711 Modules
| |||||||||||||||
| 7852 | C:\Users\admin\AppData\Local\Temp\RBX-A8EDE641\RobloxStudioLauncherBeta.exe --crashpad --no-rate-limit --database=C:\Users\admin\AppData\Local\Temp\crashpad_roblox --metrics-dir=C:\Users\admin\AppData\Local\Temp\crashpad_roblox --url=https://uploads.backtrace.rbx.com/post --annotation=RobloxChannel=production --annotation=RobloxGitHash=6516d6b83bc5556e5bee05a8f56f47b8a98b0163 --annotation=UploadAttachmentKiloByteLimit=100 --annotation=UploadPercentage=0 --annotation=format=minidump --annotation=token=a2440b0bfdada85f34d79b43839f2b49ea6bba474bd7d126e844bc119271a1c3 --initial-client-data=0x624,0x628,0x62c,0x5f0,0x634,0x16471f4,0x1647204,0x1647214 | C:\Users\admin\AppData\Local\Temp\RBX-A8EDE641\RobloxStudioLauncherBeta.exe | RobloxStudioLauncherBeta.exe | ||||||||||||
User: admin Company: Roblox Corporation Integrity Level: MEDIUM Description: Roblox Version: 1, 6, 0, 6730711 Modules
| |||||||||||||||
| (PID) Process: | (7284) RobloxStudioLauncherBeta.itch.io.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (7284) RobloxStudioLauncherBeta.itch.io.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (7284) RobloxStudioLauncherBeta.itch.io.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (7284) RobloxStudioLauncherBeta.itch.io.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\ROBLOX Corporation\Roblox |
| Operation: | write | Name: | CPath |
Value: C:\Users\admin\AppData\LocalLow\rbxcsettings.rbx | |||
| (PID) Process: | (7284) RobloxStudioLauncherBeta.itch.io.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\ROBLOX Corporation\Environments\roblox-studio |
| Operation: | delete value | Name: | curStudioVer |
Value: | |||
| (PID) Process: | (7284) RobloxStudioLauncherBeta.itch.io.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\ROBLOX Corporation\Environments\roblox-studio |
| Operation: | delete value | Name: | curStudioUrl |
Value: | |||
| (PID) Process: | (7380) RobloxStudioLauncherBeta.itch.io.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (7380) RobloxStudioLauncherBeta.itch.io.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (7380) RobloxStudioLauncherBeta.itch.io.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (7720) RobloxStudioLauncherBeta.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7284 | RobloxStudioLauncherBeta.itch.io.exe | C:\Users\admin\AppData\Local\Temp\crashpad_roblox\settings.dat | binary | |
MD5:2CCB57B76B1B06F67569E8ACF0D8E903 | SHA256:E767C0847B35452A02929B801B5C0FC0EA1FD03D39B1E11707F1621102BECFCC | |||
| 7284 | RobloxStudioLauncherBeta.itch.io.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\26C212D9399727259664BDFCA073966E_B7ED31D77D311A56FDCB56A0083B3E0B | binary | |
MD5:68ACBB4742D6D4401AC14EB13CF8E564 | SHA256:296B12ACDB5458A19B1A6810AD5277E8055975B84CEF7B5A330AA1A0AC2EE561 | |||
| 7284 | RobloxStudioLauncherBeta.itch.io.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\PCStudioBootstrapper[1].json | binary | |
MD5:D0E61839E5DBE0F7DC0775FB816CB4C5 | SHA256:CE260D5BF147F5008DC8ED40024709EDCB2FF8C7FE08E5C3BEA1527F65940F66 | |||
| 7284 | RobloxStudioLauncherBeta.itch.io.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\72BA427A91F50409B9EAC87F2B59B951_4AB5D5FF0B7710A9A4DE10A70092573B | binary | |
MD5:D00ABB05719460328C668B20FF0C581B | SHA256:6D8CC0270C511BDD2188966BB138D4BD587670B81188DE287C9A6506716FE76E | |||
| 7284 | RobloxStudioLauncherBeta.itch.io.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\07CEF2F654E3ED6050FFC9B6EB844250_BACC6CD2B29F18349081C9FD2343833B | binary | |
MD5:406E1221C130457C13D490C8F614A72F | SHA256:AF936160303FAC8A5AC2B81F89EEC348575D08552D50F89FB0C6FEFB3AF3A12A | |||
| 7284 | RobloxStudioLauncherBeta.itch.io.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_BACC6CD2B29F18349081C9FD2343833B | binary | |
MD5:802CD3A2CE32B97764BEFFE735345D38 | SHA256:18A448F92A5A977712C6EE3EBAC54DC5783C97308417440609E78020D5EE74FD | |||
| 7284 | RobloxStudioLauncherBeta.itch.io.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711E | binary | |
MD5:296EDE2532751E877DAA1D743B8609C4 | SHA256:FD6E21C069AD2152B403801DDB75B5C99DF044395D8227826A113D6E2F87EDD1 | |||
| 7284 | RobloxStudioLauncherBeta.itch.io.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_D7393C8F62BDE4D4CB606228BC7A711E | binary | |
MD5:9E5F1DF28C9064E2E73198AD7E98B197 | SHA256:AA8FFDB539E9F331784341B0F81283C2AE251CBE574A473EAA4DE279D744777A | |||
| 7284 | RobloxStudioLauncherBeta.itch.io.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\BatchIncrement[1].json | binary | |
MD5:BEDBF7D7D69748886E9B48F45C75FBBE | SHA256:B4A55CFD050F4A62B1C4831CA0AB6FFADDE1FE1C3F583917EADE12F8C6726F61 | |||
| 7284 | RobloxStudioLauncherBeta.itch.io.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_056B48C93C4964C2E64C0A8958238656 | binary | |
MD5:F1F70A59799342FD91AFCDEAE2AFBDA8 | SHA256:8ADE804B887AFFEB7D781A0158191B9EF6955F414D15E8BD4963CE8278D9BE49 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.216.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
7284 | RobloxStudioLauncherBeta.itch.io.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAsA6S1NbXMfyjBZx8seGIY%3D | unknown | — | — | whitelisted |
7284 | RobloxStudioLauncherBeta.itch.io.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D | unknown | — | — | whitelisted |
7284 | RobloxStudioLauncherBeta.itch.io.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEBN9U5yqfDGppDNwGWiEeo0%3D | unknown | — | — | whitelisted |
7380 | RobloxStudioLauncherBeta.itch.io.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEBN9U5yqfDGppDNwGWiEeo0%3D | unknown | — | — | whitelisted |
7284 | RobloxStudioLauncherBeta.itch.io.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQh80WaEMqmyEvaHjlisSfVM4p8SAQUF9nWJSdn%2BTHCSUPZMDZEjGypT%2BsCEGxUlMUNeuJZOXh%2FQAMe0fk%3D | unknown | — | — | whitelisted |
7380 | RobloxStudioLauncherBeta.itch.io.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQh80WaEMqmyEvaHjlisSfVM4p8SAQUF9nWJSdn%2BTHCSUPZMDZEjGypT%2BsCEGxUlMUNeuJZOXh%2FQAMe0fk%3D | unknown | — | — | whitelisted |
7284 | RobloxStudioLauncherBeta.itch.io.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQh80WaEMqmyEvaHjlisSfVM4p8SAQUF9nWJSdn%2BTHCSUPZMDZEjGypT%2BsCEA4jaMy2rxGsbBqVpNHwqqg%3D | unknown | — | — | whitelisted |
7284 | RobloxStudioLauncherBeta.itch.io.exe | GET | 200 | 18.245.38.41:80 | http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkpLy9ROx7U76vGUhC06D6E%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2104 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 192.168.100.255:137 | — | — | — | whitelisted |
1852 | RUXIMICS.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 23.216.77.6:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
7284 | RobloxStudioLauncherBeta.itch.io.exe | 23.41.252.19:443 | clientsettingscdn.roblox.com | AKAMAI-AS | MX | whitelisted |
7284 | RobloxStudioLauncherBeta.itch.io.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
7284 | RobloxStudioLauncherBeta.itch.io.exe | 128.116.5.3:443 | ephemeralcounters.api.roblox.com | ROBLOX-PRODUCTION | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
clientsettingscdn.roblox.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
ephemeralcounters.api.roblox.com |
| whitelisted |
ocsp.comodoca.com |
| whitelisted |
ocsp.usertrust.com |
| whitelisted |
setup.rbxcdn.qq.com |
| whitelisted |