File name:

RobloxPlayerInstaller.exe

Full analysis: https://app.any.run/tasks/b11ba8a7-bcbd-4150-97de-4aafe8b272b1
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: October 14, 2024, 21:02:03
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-doc
arch-scr
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

74515548BB70650C0176DF71D7E108F4

SHA1:

1892EA497636C4C2641427BC2FD466C531D0CD95

SHA256:

6E0DEA6726076158E4569745C0793202DFD6FBCC377117898C4C29F5BE2A08FD

SSDEEP:

98304:8Ns0YgOWfC1aLmOrGnI9PgznySdxZHS0zimxx5cjHGBpEh9dBb+DtsNTJs+GUd+1:MbD01kS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • MicrosoftEdgeUpdate.exe (PID: 6756)
  • SUSPICIOUS

    • Changes default file association

      • RobloxPlayerInstaller.exe (PID: 5516)
    • Process drops legitimate windows executable

      • RobloxPlayerInstaller.exe (PID: 5516)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7160)
      • MicrosoftEdgeUpdate.exe (PID: 6756)
      • MicrosoftEdge_X64_129.0.2792.89.exe (PID: 7036)
      • setup.exe (PID: 1752)
    • Executable content was dropped or overwritten

      • RobloxPlayerInstaller.exe (PID: 5516)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7160)
      • MicrosoftEdgeUpdate.exe (PID: 6756)
      • MicrosoftEdge_X64_129.0.2792.89.exe (PID: 7036)
      • setup.exe (PID: 1752)
      • RobloxPlayerBeta.exe (PID: 2484)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeUpdate.exe (PID: 6756)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 6756)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6988)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6912)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5828)
      • MicrosoftEdgeUpdate.exe (PID: 6044)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 6756)
      • MicrosoftEdgeUpdate.exe (PID: 2692)
      • RobloxPlayerBeta.exe (PID: 2484)
      • GameBar.exe (PID: 3600)
    • Potential Corporate Privacy Violation

      • svchost.exe (PID: 3944)
    • Checks Windows Trust Settings

      • MicrosoftEdgeUpdate.exe (PID: 2692)
      • RobloxPlayerBeta.exe (PID: 2484)
    • Application launched itself

      • setup.exe (PID: 1752)
      • MicrosoftEdgeUpdate.exe (PID: 2692)
    • Searches for installed software

      • setup.exe (PID: 1752)
    • Creates a software uninstall entry

      • setup.exe (PID: 1752)
      • RobloxPlayerInstaller.exe (PID: 5516)
    • Detected use of alternative data streams (AltDS)

      • RobloxPlayerBeta.exe (PID: 2484)
  • INFO

    • Creates files or folders in the user directory

      • RobloxPlayerInstaller.exe (PID: 5516)
      • MicrosoftEdgeUpdate.exe (PID: 6756)
      • MicrosoftEdgeUpdate.exe (PID: 2692)
      • setup.exe (PID: 6556)
      • setup.exe (PID: 1752)
      • RobloxPlayerBeta.exe (PID: 2484)
      • RobloxCrashHandler.exe (PID: 5612)
      • MicrosoftEdge_X64_129.0.2792.89.exe (PID: 7036)
    • Reads the computer name

      • RobloxPlayerInstaller.exe (PID: 5516)
      • MicrosoftEdgeUpdate.exe (PID: 6756)
      • MicrosoftEdgeUpdate.exe (PID: 6044)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6912)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6988)
      • MicrosoftEdgeUpdate.exe (PID: 696)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5828)
      • MicrosoftEdgeUpdate.exe (PID: 2692)
      • MicrosoftEdgeUpdate.exe (PID: 5940)
      • setup.exe (PID: 1752)
      • RobloxPlayerBeta.exe (PID: 2484)
      • GameBar.exe (PID: 3600)
      • RobloxCrashHandler.exe (PID: 5612)
      • MicrosoftEdge_X64_129.0.2792.89.exe (PID: 7036)
      • MicrosoftEdgeUpdate.exe (PID: 2068)
    • Sends debugging messages

      • RobloxPlayerInstaller.exe (PID: 5516)
      • RobloxPlayerBeta.exe (PID: 2484)
      • RobloxCrashHandler.exe (PID: 5612)
    • Process checks whether UAC notifications are on

      • RobloxPlayerInstaller.exe (PID: 5516)
    • Checks supported languages

      • RobloxPlayerInstaller.exe (PID: 5516)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7160)
      • MicrosoftEdgeUpdate.exe (PID: 6756)
      • MicrosoftEdgeUpdate.exe (PID: 6044)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6988)
      • MicrosoftEdgeUpdate.exe (PID: 696)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5828)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6912)
      • MicrosoftEdgeUpdate.exe (PID: 5940)
      • MicrosoftEdgeUpdate.exe (PID: 2692)
      • MicrosoftEdge_X64_129.0.2792.89.exe (PID: 7036)
      • setup.exe (PID: 1752)
      • MicrosoftEdgeUpdate.exe (PID: 2068)
      • setup.exe (PID: 6556)
      • RobloxPlayerBeta.exe (PID: 2484)
      • RobloxCrashHandler.exe (PID: 5612)
      • GameBar.exe (PID: 3600)
    • Reads the machine GUID from the registry

      • RobloxPlayerInstaller.exe (PID: 5516)
      • MicrosoftEdgeUpdate.exe (PID: 2692)
      • RobloxPlayerBeta.exe (PID: 2484)
      • RobloxCrashHandler.exe (PID: 5612)
    • Create files in a temporary directory

      • RobloxPlayerInstaller.exe (PID: 5516)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7160)
      • MicrosoftEdgeUpdate.exe (PID: 6756)
      • svchost.exe (PID: 3944)
      • RobloxPlayerBeta.exe (PID: 2484)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 696)
      • RobloxCrashHandler.exe (PID: 5612)
      • MicrosoftEdgeUpdate.exe (PID: 2068)
    • Process checks computer location settings

      • MicrosoftEdgeUpdate.exe (PID: 6756)
      • setup.exe (PID: 1752)
      • RobloxPlayerBeta.exe (PID: 2484)
    • Checks proxy server information

      • MicrosoftEdgeUpdate.exe (PID: 696)
      • MicrosoftEdgeUpdate.exe (PID: 2692)
      • MicrosoftEdgeUpdate.exe (PID: 2068)
      • slui.exe (PID: 3788)
    • Reads the software policy settings

      • MicrosoftEdgeUpdate.exe (PID: 696)
      • MicrosoftEdgeUpdate.exe (PID: 2692)
      • slui.exe (PID: 6956)
      • MicrosoftEdgeUpdate.exe (PID: 2068)
      • RobloxPlayerBeta.exe (PID: 2484)
      • slui.exe (PID: 3788)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1978:02:16 07:47:36+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 4392448
InitializedDataSize: 2497536
UninitializedDataSize: -
EntryPoint: 0x3d5480
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.6.0.38172
ProductVersionNumber: 1.6.0.38172
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Roblox Corporation
FileDescription: Roblox
FileVersion: 1, 6, 0, 6460700
LegalCopyright: Copyright © 2020 Roblox Corporation. All rights reserved.
OriginalFileName: Roblox.exe
ProductName: Roblox Bootstrapper
ProductVersion: 1, 6, 0, 6460700
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
163
Monitored processes
22
Malicious processes
7
Suspicious processes
1

Behavior graph

Click at the process to see the details
start robloxplayerinstaller.exe microsoftedgewebview2setup.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe svchost.exe sppextcomobj.exe no specs slui.exe microsoftedge_x64_129.0.2792.89.exe setup.exe setup.exe no specs slui.exe microsoftedgeupdate.exe robloxplayerbeta.exe robloxcrashhandler.exe gamebarpresencewriter.exe no specs gamebar.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
696"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xNzEuMzkiIHNoZWxsX3ZlcnNpb249IjEuMy4xNzEuMzkiIGlzbWFjaGluZT0iMCIgc2Vzc2lvbmlkPSJ7QjE3OEIxOUItNkJGRC00Q0JGLTgwODQtMEY3RTg0QTVEMkQ5fSIgdXNlcmlkPSJ7MUMxRENGRTEtRjVGQi00MjlELTk5NUItRUFENDE1MzcxODYyfSIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiByZXF1ZXN0aWQ9Ins4QkQxNEIyRi0yQjM0LTRDQjMtQTJFNC1GNTZDNERFOEQxMjh9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iNCIgcGh5c21lbW9yeT0iNCIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE5MDQ1LjQwNDYiIHNwPSIiIGFyY2g9Ing2NCIgcHJvZHVjdF90eXBlPSI0OCIgaXNfd2lwPSIwIi8-PG9lbSBwcm9kdWN0X21hbnVmYWN0dXJlcj0iREVMTCIgcHJvZHVjdF9uYW1lPSJERUxMIi8-PGV4cCBldGFnPSIiLz48YXBwIGFwcGlkPSJ7RjNDNEZFMDAtRUZENS00MDNCLTk1NjktMzk4QTIwRjFCQTRBfSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iMS4zLjE3MS4zOSIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iNjIzNDkxNzg0OCIgaW5zdGFsbF90aW1lX21zPSI1NjgiLz48L2FwcD48L3JlcXVlc3Q-C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.171.39
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
1752"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{BA903BDA-E310-477B-A67F-33F82F17DEA4}\EDGEMITMP_76AF2.tmp\setup.exe" --install-archive="C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{BA903BDA-E310-477B-A67F-33F82F17DEA4}\MicrosoftEdge_X64_129.0.2792.89.exe" --msedgewebview --verbose-logging --do-not-launch-msedge --user-levelC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{BA903BDA-E310-477B-A67F-33F82F17DEA4}\EDGEMITMP_76AF2.tmp\setup.exe
MicrosoftEdge_X64_129.0.2792.89.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
129.0.2792.89
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{ba903bda-e310-477b-a67f-33f82f17dea4}\edgemitmp_76af2.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1788"C:\Windows\System32\GameBarPresenceWriter.exe" -ServerName:Windows.Gaming.GameBar.Internal.PresenceWriterServerC:\Windows\System32\GameBarPresenceWriter.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Gamebar Presence Writer
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\gamebarpresencewriter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
2068"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xNzEuMzkiIHNoZWxsX3ZlcnNpb249IjEuMy4xNzEuMzkiIGlzbWFjaGluZT0iMCIgc2Vzc2lvbmlkPSJ7QjE3OEIxOUItNkJGRC00Q0JGLTgwODQtMEY3RTg0QTVEMkQ5fSIgdXNlcmlkPSJ7MUMxRENGRTEtRjVGQi00MjlELTk5NUItRUFENDE1MzcxODYyfSIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiByZXF1ZXN0aWQ9InszMjhCMzQxOC1DNTAxLTQxMkQtOUM1NC1DREM0NEM3QkZDOUF9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iNCIgcGh5c21lbW9yeT0iNCIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE5MDQ1LjQwNDYiIHNwPSIiIGFyY2g9Ing2NCIgcHJvZHVjdF90eXBlPSI0OCIgaXNfd2lwPSIwIi8-PG9lbSBwcm9kdWN0X21hbnVmYWN0dXJlcj0iREVMTCIgcHJvZHVjdF9uYW1lPSJERUxMIi8-PGV4cCBldGFnPSImcXVvdDtyNDUydDErazJUZ3EvSFh6anZGTkJSaG9wQldSOXNialh4cWVVREg5dVgwPSZxdW90OyIvPjxhcHAgYXBwaWQ9IntGMzAxNzIyNi1GRTJBLTQyOTUtOEJERi0wMEMzQTlBN0U0QzV9IiB2ZXJzaW9uPSIiIG5leHR2ZXJzaW9uPSIxMjkuMC4yNzkyLjg5IiBsYW5nPSJlbiIgYnJhbmQ9IiIgY2xpZW50PSIiIGV4cGVyaW1lbnRzPSJjb25zZW50PWZhbHNlIiBpbnN0YWxsYWdlPSItMSIgaW5zdGFsbGRhdGU9Ii0xIj48dXBkYXRlY2hlY2svPjxldmVudCBldmVudHR5cGU9IjkiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIHN5c3RlbV91cHRpbWVfdGlja3M9IjYyNDc0NzYwOTIiIGRvbmVfYmVmb3JlX29vYmVfY29tcGxldGU9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSI1IiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSI2MjQ3NTg0MDE5IiBkb25lX2JlZm9yZV9vb2JlX2NvbXBsZXRlPSIwIi8-PGV2ZW50IGV2ZW50dHlwZT0iMSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iNjY0OTY4NjM4MSIgc291cmNlX3VybF9pbmRleD0iMCIgZG9uZV9iZWZvcmVfb29iZV9jb21wbGV0ZT0iMCIgZG93bmxvYWRlcj0iYml0cyIgdXJsPSJodHRwOi8vbXNlZGdlLmYudGx1LmRsLmRlbGl2ZXJ5Lm1wLm1pY3Jvc29mdC5jb20vZmlsZXN0cmVhbWluZ3NlcnZpY2UvZmlsZXMvYjUzZmEyMTctNmY0NC00NTg1LWE0ZWMtNzBlZDM1ZjJhYTczP1AxPTE3Mjk1NDQ1ODQmYW1wO1AyPTQwNCZhbXA7UDM9MiZhbXA7UDQ9SkpibUFuZmROcTlkMmdLOXN1T0tKRklpdW45bFlJZ1hhQzNKTENFSm4yWGtIJTJmbXl3SnRxMTMlMmI4dktZcnBFUzUlMmZIaEFtcDJlJTJiMVZ2RzZTMkx1R0wxUSUzZCUzZCIgc2VydmVyX2lwX2hpbnQ9IiIgY2RuX2NpZD0iLTEiIGNkbl9jY2M9IiIgY2RuX21zZWRnZV9yZWY9IiIgY2RuX2F6dXJlX3JlZl9vcmlnaW5fc2hpZWxkPSIiIGNkbl9jYWNoZT0iIiBjZG5fcDNwPSIiIGRvd25sb2FkZWQ9IjE3MzkwMzk1MiIgdG90YWw9IjE3MzkwMzk1MiIgZG93bmxvYWRfdGltZV9tcz0iMzYxOTEiLz48ZXZlbnQgZXZlbnR0eXBlPSIxIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSI2NjQ5ODMyNjE4IiBzb3VyY2VfdXJsX2luZGV4PSIwIiBkb25lX2JlZm9yZV9vb2JlX2NvbXBsZXRlPSIwIi8-PGV2ZW50IGV2ZW50dHlwZT0iNiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iNjY3MjkwNjYzMSIgZG9uZV9iZWZvcmVfb29iZV9jb21wbGV0ZT0iMCIvPjxldmVudCBldmVudHR5cGU9IjIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjE5Njc1NyIgc3lzdGVtX3VwdGltZV90aWNrcz0iNzA1MTgzNzgxNCIgc291cmNlX3VybF9pbmRleD0iMCIgZG9uZV9iZWZvcmVfb29iZV9jb21wbGV0ZT0iMCIgdXBkYXRlX2NoZWNrX3RpbWVfbXM9IjcxMCIgZG93bmxvYWRfdGltZV9tcz0iNDAyMTciIGRvd25sb2FkZWQ9IjE3MzkwMzk1MiIgdG90YWw9IjE3MzkwMzk1MiIgcGFja2FnZV9jYWNoZV9yZXN1bHQ9IjAiIGluc3RhbGxfdGltZV9tcz0iMzc4ODciLz48L2FwcD48L3JlcXVlc3Q-C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.171.39
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
2484"C:\Users\admin\AppData\Local\Roblox\Versions\version-eadc3c90bb1a4267\RobloxPlayerBeta.exe" -app -clientLaunchTimeEpochMs 0 -isInstallerLaunch 5516C:\Users\admin\AppData\Local\Roblox\Versions\version-eadc3c90bb1a4267\RobloxPlayerBeta.exe
RobloxPlayerInstaller.exe
User:
admin
Company:
Roblox Corporation
Integrity Level:
MEDIUM
Description:
Roblox Game Client
Exit code:
3221225477
Version:
0, 646, 0, 6460700
Modules
Images
c:\users\admin\appdata\local\roblox\versions\version-eadc3c90bb1a4267\robloxplayerbeta.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\roblox\versions\version-eadc3c90bb1a4267\robloxplayerbeta.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
2692"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" -EmbeddingC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.171.39
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
3600"C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exe" -ServerName:App.AppXbdkk0yrkwpcgeaem8zk81k8py1eaahny.mcaC:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exesvchost.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\program files\windowsapps\microsoft.xboxgamingoverlay_2.34.28001.0_x64__8wekyb3d8bbwe\gamebar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\vccorlib140_app.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\msvcp140_app.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\concrt140_app.dll
3788C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3944C:\WINDOWS\System32\svchost.exe -k netsvcs -p -s BITSC:\Windows\System32\svchost.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
4232C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
Total events
24 240
Read events
21 751
Write events
2 421
Delete events
68

Modification events

(PID) Process:(5516) RobloxPlayerInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\ProtocolExecute\roblox-studio
Operation:writeName:WarnOnOpen
Value:
0
(PID) Process:(5516) RobloxPlayerInstaller.exeKey:HKEY_CLASSES_ROOT\roblox-studio
Operation:writeName:URL Protocol
Value:
(PID) Process:(5516) RobloxPlayerInstaller.exeKey:HKEY_CLASSES_ROOT\roblox-studio\shell\open\command
Operation:writeName:version
Value:
version-297eb79ede584243
(PID) Process:(3944) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS
Operation:writeName:PerfMMFileName
Value:
Global\MMF_BITSa30c85d9-8af2-442a-8107-70978eac1793
(PID) Process:(6756) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:delete valueName:eulaaccepted
Value:
(PID) Process:(6756) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:path
Value:
C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(PID) Process:(6756) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:UninstallCmdLine
Value:
"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /uninstall
(PID) Process:(6756) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.171.39
(PID) Process:(6756) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:name
Value:
Microsoft Edge Update
(PID) Process:(6756) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\ClientState\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.171.39
Executable files
209
Suspicious files
46
Text files
11
Unknown types
0

Dropped files

PID
Process
Filename
Type
5516RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\logs\cacert.pemtext
MD5:C656D325F5DF1991584F0BB00A27902F
SHA256:98ECAF8DA767CCB2870DD30A5E7334D2F45702A3A33EC8B4286E6AE88B720EB8
5516RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\889e0052812b9ed64dd5653d29180ee7compressed
MD5:889E0052812B9ED64DD5653D29180EE7
SHA256:501BFA6CCEAB8DBE2510BCDE501E29C23D0786E8FB93AB9B4B8AABDD88973F16
5516RobloxPlayerInstaller.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox\Roblox Studio.lnkbinary
MD5:EF6684D21C3CA2411FD391BEDD957EF9
SHA256:4BBCDABCC48DBA281B99A773DA6213DFB1DFAB79705118F1A2D97C7CE1DFB493
5516RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\e42a6697bf05466d4dba26c8fe476d2ecompressed
MD5:E42A6697BF05466D4DBA26C8FE476D2E
SHA256:622FF96317AAE6A02B9699F68CDF0FCE14FABDA171B49445B344A9BE62DE37B9
5516RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\9ba94e86704c5a6fca3f79c7077eae53compressed
MD5:9BA94E86704C5A6FCA3F79C7077EAE53
SHA256:63C0A4A1BA4148887B28284F165EEFA4F43074A45A401937474A85B89F631B52
5516RobloxPlayerInstaller.exeC:\Users\admin\Desktop\Roblox Studio.lnkbinary
MD5:4D92CB86999CC27D992E69E5CCF67C4A
SHA256:DF1EBC76CCAC70AD99A778995A7ECCAE84B8A35FC3B8F51F321CDDD150F74795
5516RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\ec3d2415b0c25f4eba31e255d7f4ba30compressed
MD5:EC3D2415B0C25F4EBA31E255D7F4BA30
SHA256:120AB9A39D1AF17396638EACFEE03AD01B87E24B86F93A7774A68E1246F29337
5516RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Temp\Roblox\http\8913724486d5e3c463c493b25346ca31binary
MD5:703ED578B8BF56F5134073C4E0F63408
SHA256:C3BB52B917965FE3DEE99C5133E2B376F7FA4AB17D51D5E26383A8E279E9A596
5516RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\1d0390337d1a4a58e5514be1a9481ad6compressed
MD5:1D0390337D1A4A58E5514BE1A9481AD6
SHA256:C79F0EEB2BCA4905C585C50333DB3C6F727A554F5DB82E64948F93668FBC18AA
5516RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\b240d5bd436de06ce457ed169a3fe446compressed
MD5:B240D5BD436DE06CE457ED169A3FE446
SHA256:66BC392751731EC115DED27ABE07A12C37062B807EF0596E22D13B40D2650EB3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
101
DNS requests
39
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5488
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6572
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
3944
svchost.exe
GET
200
2.19.126.157:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/b53fa217-6f44-4585-a4ec-70ed35f2aa73?P1=1729544584&P2=404&P3=2&P4=JJbmAnfdNq9d2gK9suOKJFIiun9lYIgXaC3JLCEJn2XkH%2fmywJtq13%2b8vKYrpES5%2fHhAmp2e%2b1VvG6S2LuGL1Q%3d%3d
unknown
whitelisted
6572
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6692
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
2.16.164.106:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
3836
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
3944
svchost.exe
HEAD
200
2.19.126.157:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/b53fa217-6f44-4585-a4ec-70ed35f2aa73?P1=1729544584&P2=404&P3=2&P4=JJbmAnfdNq9d2gK9suOKJFIiun9lYIgXaC3JLCEJn2XkH%2fmywJtq13%2b8vKYrpES5%2fHhAmp2e%2b1VvG6S2LuGL1Q%3d%3d
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6944
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2000
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5488
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5516
RobloxPlayerInstaller.exe
128.116.44.4:443
ecsv2.roblox.com
ROBLOX-PRODUCTION
US
whitelisted
5516
RobloxPlayerInstaller.exe
128.116.44.3:443
client-telemetry.roblox.com
ROBLOX-PRODUCTION
US
whitelisted
3836
svchost.exe
20.190.160.20:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4360
SearchApp.exe
150.171.28.10:443
www.bing.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3836
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.142
whitelisted
ecsv2.roblox.com
  • 128.116.44.4
whitelisted
client-telemetry.roblox.com
  • 128.116.44.3
whitelisted
login.live.com
  • 20.190.160.20
  • 40.126.32.134
  • 20.190.160.22
  • 20.190.160.17
  • 40.126.32.76
  • 40.126.32.136
  • 40.126.32.68
  • 40.126.32.74
whitelisted
www.bing.com
  • 150.171.28.10
  • 150.171.27.10
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
th.bing.com
  • 2.23.209.189
  • 2.23.209.193
  • 2.23.209.140
  • 2.23.209.149
  • 2.23.209.187
  • 2.23.209.179
  • 2.23.209.182
  • 2.23.209.133
  • 2.23.209.130
whitelisted
clientsettingscdn.roblox.com
  • 52.222.236.86
  • 52.222.236.43
  • 52.222.236.6
  • 52.222.236.113
whitelisted
setup.rbxcdn.com
  • 13.224.189.122
  • 13.224.189.83
  • 13.224.189.58
  • 13.224.189.57
whitelisted

Threats

PID
Process
Class
Message
3944
svchost.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
RobloxPlayerInstaller.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
RobloxPlayerBeta.exe
2024-10-14T21:04:28.448Z,0.448070,1b28,6 [FLog::Output] Loading AppSettings.xml from C:\Users\admin\AppData\Local\Roblox\Versions\version-eadc3c90bb1a4267\AppSettings.xml
RobloxPlayerBeta.exe
RobloxPlayerBeta.exe
2024-10-14T21:04:28.452Z,0.452088,1b28,6,Info [FLog::UpdateController] UpdateController: versionQueryUrl: https://clientsettingscdn.roblox.com/v2/client-version/WindowsPlayer
RobloxPlayerBeta.exe
RobloxPlayerBeta.exe
2024-10-14T21:04:28.453Z,0.453093,1b28,6,Info [FLog::UpdateController] WindowsUpdateController: updaterFullPath: C:\Users\admin\AppData\Local\Roblox\Versions\version-eadc3c90bb1a4267\RobloxPlayerInstaller.exe
RobloxPlayerBeta.exe
RobloxPlayerBeta.exe
2024-10-14T21:04:28.455Z,0.455102,0498,6,Info [FLog::UpdateController] Update check thread started
RobloxPlayerBeta.exe
RobloxPlayerBeta.exe
2024-10-14T21:04:28.456Z,0.456106,0498,6,Info [FLog::UpdateController] Checking if updater exists at C:\Users\admin\AppData\Local\Roblox\Versions\version-eadc3c90bb1a4267\RobloxPlayerInstaller.exe. Returning true