File name:

Roblox.exe

Full analysis: https://app.any.run/tasks/5721facb-7755-4bdc-b15c-783a296bf5fd
Verdict: Malicious activity
Analysis date: May 24, 2025, 12:29:17
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
roblox
arch-doc
arch-scr
arch-exec
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

656BADAAC0924D49DD1A25B0C873324B

SHA1:

DD1799EEE724D9559688D30BE6A9E5510CA9BD8F

SHA256:

57C7EE68E819BFDF794CDB2F8065D75445416D72CB44FBE37CFE1805B0BC1000

SSDEEP:

98304:Ys0nBxkx70GCds6C5PRAxawDZ8JSZTIaZykEGMpkYGoLNJCCU+RhkoemLq0wkdpU:2rgLRZaz

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • MicrosoftEdgeUpdate.exe (PID: 300)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Roblox.exe (PID: 4776)
      • MicrosoftEdgeWebview2Setup.exe (PID: 2516)
      • MicrosoftEdgeUpdate.exe (PID: 300)
    • Changes default file association

      • Roblox.exe (PID: 4776)
    • The process drops C-runtime libraries

      • Roblox.exe (PID: 4776)
    • Process drops legitimate windows executable

      • Roblox.exe (PID: 4776)
      • MicrosoftEdgeWebview2Setup.exe (PID: 2516)
      • MicrosoftEdgeUpdate.exe (PID: 300)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeUpdate.exe (PID: 300)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2420)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5260)
      • MicrosoftEdgeUpdate.exe (PID: 1388)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6592)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 300)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 300)
  • INFO

    • The sample compiled with english language support

      • Roblox.exe (PID: 4776)
      • MicrosoftEdgeWebview2Setup.exe (PID: 2516)
      • MicrosoftEdgeUpdate.exe (PID: 300)
    • Checks supported languages

      • Roblox.exe (PID: 4776)
      • MicrosoftEdgeWebview2Setup.exe (PID: 2516)
      • MicrosoftEdgeUpdate.exe (PID: 300)
      • MicrosoftEdgeUpdate.exe (PID: 1388)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2420)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5260)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6592)
      • MicrosoftEdgeUpdate.exe (PID: 856)
      • MicrosoftEdgeUpdate.exe (PID: 4560)
      • MicrosoftEdgeUpdate.exe (PID: 5084)
    • Reads the machine GUID from the registry

      • Roblox.exe (PID: 4776)
    • Creates files or folders in the user directory

      • Roblox.exe (PID: 4776)
      • MicrosoftEdgeUpdate.exe (PID: 300)
    • Reads the computer name

      • Roblox.exe (PID: 4776)
      • MicrosoftEdgeUpdate.exe (PID: 300)
      • MicrosoftEdgeUpdate.exe (PID: 1388)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 2420)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6592)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5260)
      • MicrosoftEdgeUpdate.exe (PID: 856)
      • MicrosoftEdgeUpdate.exe (PID: 4560)
      • MicrosoftEdgeUpdate.exe (PID: 5084)
    • ROBLOX mutex has been found

      • Roblox.exe (PID: 4776)
    • Create files in a temporary directory

      • Roblox.exe (PID: 4776)
      • MicrosoftEdgeWebview2Setup.exe (PID: 2516)
      • MicrosoftEdgeUpdate.exe (PID: 300)
    • Process checks whether UAC notifications are on

      • Roblox.exe (PID: 4776)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 856)
    • Checks proxy server information

      • MicrosoftEdgeUpdate.exe (PID: 856)
      • MicrosoftEdgeUpdate.exe (PID: 5084)
    • Process checks computer location settings

      • MicrosoftEdgeUpdate.exe (PID: 300)
    • Reads the software policy settings

      • MicrosoftEdgeUpdate.exe (PID: 856)
      • MicrosoftEdgeUpdate.exe (PID: 5084)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1971:10:22 15:29:34+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 5705216
InitializedDataSize: 2118656
UninitializedDataSize: -
EntryPoint: 0x50d445
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.6.0.56113
ProductVersionNumber: 1.6.0.56113
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Roblox Corporation
FileDescription: Roblox
FileVersion: 1, 6, 0, 6740785
LegalCopyright: Copyright © 2020 Roblox Corporation. All rights reserved.
OriginalFileName: Roblox.exe
ProductName: Roblox Bootstrapper
ProductVersion: 1, 6, 0, 6740785
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
10
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start roblox.exe microsoftedgewebview2setup.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe

Process information

PID
CMD
Path
Indicators
Parent process
300C:\Users\admin\AppData\Local\Temp\EU70F7.tmp\MicrosoftEdgeUpdate.exe /silent /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers"C:\Users\admin\AppData\Local\Temp\EU70F7.tmp\MicrosoftEdgeUpdate.exe
MicrosoftEdgeWebview2Setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\temp\eu70f7.tmp\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
856"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xOTUuNDUiIHNoZWxsX3ZlcnNpb249IjEuMy4xOTUuNDUiIGlzbWFjaGluZT0iMCIgc2Vzc2lvbmlkPSJ7RjExMDFBODAtMjU3NS00NkRFLTlGREMtNzQ5MzMzODhBNzE0fSIgdXNlcmlkPSJ7NzU5RUU4MjQtQzdFNC00QTUxLTg1RkItOEJBOUU3MjdFRTJCfSIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiByZXF1ZXN0aWQ9Ins0RDcwMEI1MC05M0Y5LTQwNEQtOTNGMC00RDRDNTUwNzAyNUV9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iNCIgcGh5c21lbW9yeT0iNCIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE5MDQ1LjQwNDYiIHNwPSIiIGFyY2g9Ing2NCIgcHJvZHVjdF90eXBlPSI0OCIgaXNfd2lwPSIwIiBpc19pbl9sb2NrZG93bl9tb2RlPSIwIi8-PG9lbSBwcm9kdWN0X21hbnVmYWN0dXJlcj0iREVMTCIgcHJvZHVjdF9uYW1lPSJERUxMIi8-PGV4cCBldGFnPSIiLz48YXBwIGFwcGlkPSJ7RjNDNEZFMDAtRUZENS00MDNCLTk1NjktMzk4QTIwRjFCQTRBfSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iMS4zLjE5NS40NSIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iMTAxNDE3NzIzNzgiIGluc3RhbGxfdGltZV9tcz0iNzE2Ii8-PC9hcHA-PC9yZXF1ZXN0PgC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
1388"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserverC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
2420"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.195.45\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2516MicrosoftEdgeWebview2Setup.exe /silent /installC:\Users\admin\AppData\Local\Roblox\Versions\version-e00a4ca39fb04359\WebView2RuntimeInstaller\MicrosoftEdgeWebview2Setup.exe
Roblox.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\roblox\versions\version-e00a4ca39fb04359\webview2runtimeinstaller\microsoftedgewebview2setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4560"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /handoff "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=false" /installsource otherinstallcmd /sessionid "{F1101A80-2575-46DE-9FDC-74933388A714}" /silentC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
4776"C:\Users\admin\AppData\Local\Temp\Roblox.exe" C:\Users\admin\AppData\Local\Temp\Roblox.exe
explorer.exe
User:
admin
Company:
Roblox Corporation
Integrity Level:
MEDIUM
Description:
Roblox
Version:
1, 6, 0, 6740785
Modules
Images
c:\users\admin\appdata\local\temp\roblox.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
5084"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" -EmbeddingC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
5260"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.195.45\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6592"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.195.45\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
3 563
Read events
3 188
Write events
341
Delete events
34

Modification events

(PID) Process:(4776) Roblox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\ProtocolExecute\roblox-studio
Operation:writeName:WarnOnOpen
Value:
0
(PID) Process:(4776) Roblox.exeKey:HKEY_CLASSES_ROOT\roblox-studio
Operation:writeName:URL Protocol
Value:
(PID) Process:(4776) Roblox.exeKey:HKEY_CLASSES_ROOT\roblox-studio\shell\open\command
Operation:writeName:version
Value:
version-6dbf1fd58a49447c
(PID) Process:(300) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:delete valueName:eulaaccepted
Value:
(PID) Process:(300) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:path
Value:
C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(PID) Process:(300) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:UninstallCmdLine
Value:
"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /uninstall
(PID) Process:(300) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.195.45
(PID) Process:(300) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:name
Value:
Microsoft Edge Update
(PID) Process:(300) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\ClientState\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.195.45
(PID) Process:(300) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Microsoft Edge Update
Value:
"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateCore.exe"
Executable files
206
Suspicious files
33
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
4776Roblox.exeC:\Users\admin\AppData\Local\Roblox\logs\cacert.pemtext
MD5:18EB55403B6BFAF4927B174FC2A3AB66
SHA256:7570425CD2E18C5A5536887906B6C113F62A03C2744CFFA27FC6B9CA1AD91C2C
4776Roblox.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\c0b029a8acb8c62034cf05e53afb1591compressed
MD5:C0B029A8ACB8C62034CF05E53AFB1591
SHA256:DEE8CDE00CB3CDC016BD0F147F05B5E1171B4B741A1F1611A90A365FEC604C05
4776Roblox.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\8bd85f4e8e0f8904501eb60e6f3bf7eecompressed
MD5:8BD85F4E8E0F8904501EB60E6F3BF7EE
SHA256:2E01FCA8EA0CDFCB1E6962AE9A8DC8FAB9241441E2568D812AAD9A11E1BFF57B
4776Roblox.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\909f4b9d7bc03a926d35e84d0c99ffbfcompressed
MD5:909F4B9D7BC03A926D35E84D0C99FFBF
SHA256:C139AD55ACEBF739689CC1E29F84BA7731DC7FFC03F70BBBBD16929E3D439EC0
4776Roblox.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\b32769aa5f9efad4c7e31fbd3a512a04compressed
MD5:B32769AA5F9EFAD4C7E31FBD3A512A04
SHA256:552A77A703E5437626B3E7980E8645DB6F0BD0F3C7A81C45DABBC6816979036C
4776Roblox.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\1f29f51e3d52d7f8ec6ed31e3f1fda6ecompressed
MD5:1F29F51E3D52D7F8EC6ED31E3F1FDA6E
SHA256:1CC22018EC11088DF3967F27008CB879EB92DB5AE0A5807698B84E93E039BD31
4776Roblox.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\a36b77316d3394b7fb734ed7ceb5a0c2compressed
MD5:A36B77316D3394B7FB734ED7CEB5A0C2
SHA256:85A1D23E0CE1A19CD35D2690A076BE26A43D7D59F6FDDBBE3A28377C44BD3ACC
4776Roblox.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\6afd47a719d26cac99abd568c21f2066compressed
MD5:6AFD47A719D26CAC99ABD568C21F2066
SHA256:F8C9F80C413BBC3A95624BCC39FA7B00100CCA26DF312C58542308A8A331D5DD
4776Roblox.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\b4b75c21ce05378163042dc45cec5834compressed
MD5:B4B75C21CE05378163042DC45CEC5834
SHA256:4D6FE68C8B4941CE335CE5597EBBC1F27AB02646E9AF98AF8A76875AD0FD191F
4776Roblox.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox\Roblox Studio.lnkbinary
MD5:A5745C06CC625D8F7F2237075A27941C
SHA256:0B2A651C1EA4DFF8229F9C87AC213E9C156525931478CF03A8F52DD061737A19
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
30
DNS requests
20
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4980
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4980
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5936
svchost.exe
GET
199.232.214.172:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3e2fb3dd-6316-4a11-801b-c8c0d21312e9?P1=1748694618&P2=404&P3=2&P4=WemrbebvOnzOXHratm%2balfpw%2bTHF5OJL17atHGIYKVKKgvUgPNFqcnLk%2bMAPeDgYjprIpI3N6oUr5wdcdgtCJA%3d%3d
unknown
whitelisted
5936
svchost.exe
HEAD
200
199.232.214.172:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3e2fb3dd-6316-4a11-801b-c8c0d21312e9?P1=1748694618&P2=404&P3=2&P4=WemrbebvOnzOXHratm%2balfpw%2bTHF5OJL17atHGIYKVKKgvUgPNFqcnLk%2bMAPeDgYjprIpI3N6oUr5wdcdgtCJA%3d%3d
unknown
whitelisted
GET
200
23.32.238.112:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.32.238.112:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2.23.181.156:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5496
MoUsoCoreWorker.exe
2.23.181.156:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4776
Roblox.exe
128.116.5.3:443
ecsv2.roblox.com
ROBLOX-PRODUCTION
US
whitelisted
4776
Roblox.exe
23.45.109.46:443
clientsettingscdn.roblox.com
AKAMAI-AS
DE
whitelisted
4776
Roblox.exe
23.32.238.91:443
setup.rbxcdn.com
Akamai International B.V.
DE
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.32.238.112
  • 23.32.238.107
whitelisted
google.com
  • 142.250.181.238
whitelisted
www.microsoft.com
  • 2.23.181.156
whitelisted
ecsv2.roblox.com
  • 128.116.5.3
whitelisted
client-telemetry.roblox.com
  • 128.116.5.3
whitelisted
clientsettingscdn.roblox.com
  • 23.45.109.46
whitelisted
setup.rbxcdn.com
  • 23.32.238.91
  • 23.32.238.96
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.31.129
  • 40.126.31.3
  • 20.190.159.130
  • 40.126.31.69
  • 20.190.159.68
  • 20.190.159.129
  • 40.126.31.71
  • 40.126.31.130
whitelisted

Threats

PID
Process
Class
Message
5936
svchost.exe
Misc activity
ET INFO Packed Executable Download
No debug info