File name:

RobloxPlayerInstaller.exe

Full analysis: https://app.any.run/tasks/b11ba8a7-bcbd-4150-97de-4aafe8b272b1
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: October 14, 2024, 21:02:03
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-doc
arch-scr
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

74515548BB70650C0176DF71D7E108F4

SHA1:

1892EA497636C4C2641427BC2FD466C531D0CD95

SHA256:

6E0DEA6726076158E4569745C0793202DFD6FBCC377117898C4C29F5BE2A08FD

SSDEEP:

98304:8Ns0YgOWfC1aLmOrGnI9PgznySdxZHS0zimxx5cjHGBpEh9dBb+DtsNTJs+GUd+1:MbD01kS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • MicrosoftEdgeUpdate.exe (PID: 6756)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • RobloxPlayerInstaller.exe (PID: 5516)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7160)
      • MicrosoftEdgeUpdate.exe (PID: 6756)
      • MicrosoftEdge_X64_129.0.2792.89.exe (PID: 7036)
      • setup.exe (PID: 1752)
      • RobloxPlayerBeta.exe (PID: 2484)
    • Process drops legitimate windows executable

      • RobloxPlayerInstaller.exe (PID: 5516)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7160)
      • MicrosoftEdgeUpdate.exe (PID: 6756)
      • MicrosoftEdge_X64_129.0.2792.89.exe (PID: 7036)
      • setup.exe (PID: 1752)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6988)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6912)
      • MicrosoftEdgeUpdate.exe (PID: 6044)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5828)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 6756)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeUpdate.exe (PID: 6756)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 6756)
      • MicrosoftEdgeUpdate.exe (PID: 2692)
      • RobloxPlayerBeta.exe (PID: 2484)
      • GameBar.exe (PID: 3600)
    • Potential Corporate Privacy Violation

      • svchost.exe (PID: 3944)
    • Checks Windows Trust Settings

      • MicrosoftEdgeUpdate.exe (PID: 2692)
      • RobloxPlayerBeta.exe (PID: 2484)
    • Application launched itself

      • setup.exe (PID: 1752)
      • MicrosoftEdgeUpdate.exe (PID: 2692)
    • Creates a software uninstall entry

      • setup.exe (PID: 1752)
      • RobloxPlayerInstaller.exe (PID: 5516)
    • Searches for installed software

      • setup.exe (PID: 1752)
    • Detected use of alternative data streams (AltDS)

      • RobloxPlayerBeta.exe (PID: 2484)
    • Changes default file association

      • RobloxPlayerInstaller.exe (PID: 5516)
  • INFO

    • Creates files or folders in the user directory

      • RobloxPlayerInstaller.exe (PID: 5516)
      • MicrosoftEdgeUpdate.exe (PID: 6756)
      • MicrosoftEdgeUpdate.exe (PID: 2692)
      • MicrosoftEdge_X64_129.0.2792.89.exe (PID: 7036)
      • setup.exe (PID: 6556)
      • setup.exe (PID: 1752)
      • RobloxPlayerBeta.exe (PID: 2484)
      • RobloxCrashHandler.exe (PID: 5612)
    • Checks supported languages

      • RobloxPlayerInstaller.exe (PID: 5516)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7160)
      • MicrosoftEdgeUpdate.exe (PID: 6044)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6988)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6912)
      • MicrosoftEdgeUpdate.exe (PID: 6756)
      • MicrosoftEdgeUpdate.exe (PID: 696)
      • MicrosoftEdgeUpdate.exe (PID: 2692)
      • MicrosoftEdgeUpdate.exe (PID: 5940)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5828)
      • setup.exe (PID: 6556)
      • MicrosoftEdge_X64_129.0.2792.89.exe (PID: 7036)
      • setup.exe (PID: 1752)
      • MicrosoftEdgeUpdate.exe (PID: 2068)
      • RobloxPlayerBeta.exe (PID: 2484)
      • RobloxCrashHandler.exe (PID: 5612)
      • GameBar.exe (PID: 3600)
    • Process checks whether UAC notifications are on

      • RobloxPlayerInstaller.exe (PID: 5516)
    • Reads the machine GUID from the registry

      • RobloxPlayerInstaller.exe (PID: 5516)
      • MicrosoftEdgeUpdate.exe (PID: 2692)
      • RobloxPlayerBeta.exe (PID: 2484)
      • RobloxCrashHandler.exe (PID: 5612)
    • Sends debugging messages

      • RobloxPlayerInstaller.exe (PID: 5516)
      • RobloxPlayerBeta.exe (PID: 2484)
      • RobloxCrashHandler.exe (PID: 5612)
    • Reads the computer name

      • RobloxPlayerInstaller.exe (PID: 5516)
      • MicrosoftEdgeUpdate.exe (PID: 6756)
      • MicrosoftEdgeUpdate.exe (PID: 6044)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6988)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6912)
      • MicrosoftEdgeUpdate.exe (PID: 696)
      • MicrosoftEdgeUpdate.exe (PID: 5940)
      • MicrosoftEdgeUpdate.exe (PID: 2692)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5828)
      • setup.exe (PID: 1752)
      • MicrosoftEdge_X64_129.0.2792.89.exe (PID: 7036)
      • MicrosoftEdgeUpdate.exe (PID: 2068)
      • RobloxPlayerBeta.exe (PID: 2484)
      • GameBar.exe (PID: 3600)
      • RobloxCrashHandler.exe (PID: 5612)
    • Create files in a temporary directory

      • RobloxPlayerInstaller.exe (PID: 5516)
      • MicrosoftEdgeUpdate.exe (PID: 6756)
      • svchost.exe (PID: 3944)
      • RobloxPlayerBeta.exe (PID: 2484)
      • MicrosoftEdgeWebview2Setup.exe (PID: 7160)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 696)
      • MicrosoftEdgeUpdate.exe (PID: 2068)
      • RobloxCrashHandler.exe (PID: 5612)
    • Reads the software policy settings

      • MicrosoftEdgeUpdate.exe (PID: 2692)
      • MicrosoftEdgeUpdate.exe (PID: 696)
      • slui.exe (PID: 6956)
      • MicrosoftEdgeUpdate.exe (PID: 2068)
      • RobloxPlayerBeta.exe (PID: 2484)
      • slui.exe (PID: 3788)
    • Checks proxy server information

      • MicrosoftEdgeUpdate.exe (PID: 2692)
      • MicrosoftEdgeUpdate.exe (PID: 696)
      • MicrosoftEdgeUpdate.exe (PID: 2068)
      • slui.exe (PID: 3788)
    • Process checks computer location settings

      • MicrosoftEdgeUpdate.exe (PID: 6756)
      • setup.exe (PID: 1752)
      • RobloxPlayerBeta.exe (PID: 2484)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1978:02:16 07:47:36+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 4392448
InitializedDataSize: 2497536
UninitializedDataSize: -
EntryPoint: 0x3d5480
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.6.0.38172
ProductVersionNumber: 1.6.0.38172
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Roblox Corporation
FileDescription: Roblox
FileVersion: 1, 6, 0, 6460700
LegalCopyright: Copyright © 2020 Roblox Corporation. All rights reserved.
OriginalFileName: Roblox.exe
ProductName: Roblox Bootstrapper
ProductVersion: 1, 6, 0, 6460700
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
163
Monitored processes
22
Malicious processes
7
Suspicious processes
1

Behavior graph

Click at the process to see the details
start robloxplayerinstaller.exe microsoftedgewebview2setup.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe svchost.exe sppextcomobj.exe no specs slui.exe microsoftedge_x64_129.0.2792.89.exe setup.exe setup.exe no specs slui.exe microsoftedgeupdate.exe robloxplayerbeta.exe robloxcrashhandler.exe gamebarpresencewriter.exe no specs gamebar.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
696"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xNzEuMzkiIHNoZWxsX3ZlcnNpb249IjEuMy4xNzEuMzkiIGlzbWFjaGluZT0iMCIgc2Vzc2lvbmlkPSJ7QjE3OEIxOUItNkJGRC00Q0JGLTgwODQtMEY3RTg0QTVEMkQ5fSIgdXNlcmlkPSJ7MUMxRENGRTEtRjVGQi00MjlELTk5NUItRUFENDE1MzcxODYyfSIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiByZXF1ZXN0aWQ9Ins4QkQxNEIyRi0yQjM0LTRDQjMtQTJFNC1GNTZDNERFOEQxMjh9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iNCIgcGh5c21lbW9yeT0iNCIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE5MDQ1LjQwNDYiIHNwPSIiIGFyY2g9Ing2NCIgcHJvZHVjdF90eXBlPSI0OCIgaXNfd2lwPSIwIi8-PG9lbSBwcm9kdWN0X21hbnVmYWN0dXJlcj0iREVMTCIgcHJvZHVjdF9uYW1lPSJERUxMIi8-PGV4cCBldGFnPSIiLz48YXBwIGFwcGlkPSJ7RjNDNEZFMDAtRUZENS00MDNCLTk1NjktMzk4QTIwRjFCQTRBfSIgdmVyc2lvbj0iIiBuZXh0dmVyc2lvbj0iMS4zLjE3MS4zOSIgbGFuZz0iIiBicmFuZD0iIiBjbGllbnQ9IiI-PGV2ZW50IGV2ZW50dHlwZT0iMiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iNjIzNDkxNzg0OCIgaW5zdGFsbF90aW1lX21zPSI1NjgiLz48L2FwcD48L3JlcXVlc3Q-C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.171.39
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
1752"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{BA903BDA-E310-477B-A67F-33F82F17DEA4}\EDGEMITMP_76AF2.tmp\setup.exe" --install-archive="C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{BA903BDA-E310-477B-A67F-33F82F17DEA4}\MicrosoftEdge_X64_129.0.2792.89.exe" --msedgewebview --verbose-logging --do-not-launch-msedge --user-levelC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{BA903BDA-E310-477B-A67F-33F82F17DEA4}\EDGEMITMP_76AF2.tmp\setup.exe
MicrosoftEdge_X64_129.0.2792.89.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
129.0.2792.89
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{ba903bda-e310-477b-a67f-33f82f17dea4}\edgemitmp_76af2.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1788"C:\Windows\System32\GameBarPresenceWriter.exe" -ServerName:Windows.Gaming.GameBar.Internal.PresenceWriterServerC:\Windows\System32\GameBarPresenceWriter.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Gamebar Presence Writer
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\gamebarpresencewriter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
2068"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xNzEuMzkiIHNoZWxsX3ZlcnNpb249IjEuMy4xNzEuMzkiIGlzbWFjaGluZT0iMCIgc2Vzc2lvbmlkPSJ7QjE3OEIxOUItNkJGRC00Q0JGLTgwODQtMEY3RTg0QTVEMkQ5fSIgdXNlcmlkPSJ7MUMxRENGRTEtRjVGQi00MjlELTk5NUItRUFENDE1MzcxODYyfSIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiByZXF1ZXN0aWQ9InszMjhCMzQxOC1DNTAxLTQxMkQtOUM1NC1DREM0NEM3QkZDOUF9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iNCIgcGh5c21lbW9yeT0iNCIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE5MDQ1LjQwNDYiIHNwPSIiIGFyY2g9Ing2NCIgcHJvZHVjdF90eXBlPSI0OCIgaXNfd2lwPSIwIi8-PG9lbSBwcm9kdWN0X21hbnVmYWN0dXJlcj0iREVMTCIgcHJvZHVjdF9uYW1lPSJERUxMIi8-PGV4cCBldGFnPSImcXVvdDtyNDUydDErazJUZ3EvSFh6anZGTkJSaG9wQldSOXNialh4cWVVREg5dVgwPSZxdW90OyIvPjxhcHAgYXBwaWQ9IntGMzAxNzIyNi1GRTJBLTQyOTUtOEJERi0wMEMzQTlBN0U0QzV9IiB2ZXJzaW9uPSIiIG5leHR2ZXJzaW9uPSIxMjkuMC4yNzkyLjg5IiBsYW5nPSJlbiIgYnJhbmQ9IiIgY2xpZW50PSIiIGV4cGVyaW1lbnRzPSJjb25zZW50PWZhbHNlIiBpbnN0YWxsYWdlPSItMSIgaW5zdGFsbGRhdGU9Ii0xIj48dXBkYXRlY2hlY2svPjxldmVudCBldmVudHR5cGU9IjkiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIHN5c3RlbV91cHRpbWVfdGlja3M9IjYyNDc0NzYwOTIiIGRvbmVfYmVmb3JlX29vYmVfY29tcGxldGU9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSI1IiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSI2MjQ3NTg0MDE5IiBkb25lX2JlZm9yZV9vb2JlX2NvbXBsZXRlPSIwIi8-PGV2ZW50IGV2ZW50dHlwZT0iMSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iNjY0OTY4NjM4MSIgc291cmNlX3VybF9pbmRleD0iMCIgZG9uZV9iZWZvcmVfb29iZV9jb21wbGV0ZT0iMCIgZG93bmxvYWRlcj0iYml0cyIgdXJsPSJodHRwOi8vbXNlZGdlLmYudGx1LmRsLmRlbGl2ZXJ5Lm1wLm1pY3Jvc29mdC5jb20vZmlsZXN0cmVhbWluZ3NlcnZpY2UvZmlsZXMvYjUzZmEyMTctNmY0NC00NTg1LWE0ZWMtNzBlZDM1ZjJhYTczP1AxPTE3Mjk1NDQ1ODQmYW1wO1AyPTQwNCZhbXA7UDM9MiZhbXA7UDQ9SkpibUFuZmROcTlkMmdLOXN1T0tKRklpdW45bFlJZ1hhQzNKTENFSm4yWGtIJTJmbXl3SnRxMTMlMmI4dktZcnBFUzUlMmZIaEFtcDJlJTJiMVZ2RzZTMkx1R0wxUSUzZCUzZCIgc2VydmVyX2lwX2hpbnQ9IiIgY2RuX2NpZD0iLTEiIGNkbl9jY2M9IiIgY2RuX21zZWRnZV9yZWY9IiIgY2RuX2F6dXJlX3JlZl9vcmlnaW5fc2hpZWxkPSIiIGNkbl9jYWNoZT0iIiBjZG5fcDNwPSIiIGRvd25sb2FkZWQ9IjE3MzkwMzk1MiIgdG90YWw9IjE3MzkwMzk1MiIgZG93bmxvYWRfdGltZV9tcz0iMzYxOTEiLz48ZXZlbnQgZXZlbnR0eXBlPSIxIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSI2NjQ5ODMyNjE4IiBzb3VyY2VfdXJsX2luZGV4PSIwIiBkb25lX2JlZm9yZV9vb2JlX2NvbXBsZXRlPSIwIi8-PGV2ZW50IGV2ZW50dHlwZT0iNiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iNjY3MjkwNjYzMSIgZG9uZV9iZWZvcmVfb29iZV9jb21wbGV0ZT0iMCIvPjxldmVudCBldmVudHR5cGU9IjIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjE5Njc1NyIgc3lzdGVtX3VwdGltZV90aWNrcz0iNzA1MTgzNzgxNCIgc291cmNlX3VybF9pbmRleD0iMCIgZG9uZV9iZWZvcmVfb29iZV9jb21wbGV0ZT0iMCIgdXBkYXRlX2NoZWNrX3RpbWVfbXM9IjcxMCIgZG93bmxvYWRfdGltZV9tcz0iNDAyMTciIGRvd25sb2FkZWQ9IjE3MzkwMzk1MiIgdG90YWw9IjE3MzkwMzk1MiIgcGFja2FnZV9jYWNoZV9yZXN1bHQ9IjAiIGluc3RhbGxfdGltZV9tcz0iMzc4ODciLz48L2FwcD48L3JlcXVlc3Q-C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.171.39
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
2484"C:\Users\admin\AppData\Local\Roblox\Versions\version-eadc3c90bb1a4267\RobloxPlayerBeta.exe" -app -clientLaunchTimeEpochMs 0 -isInstallerLaunch 5516C:\Users\admin\AppData\Local\Roblox\Versions\version-eadc3c90bb1a4267\RobloxPlayerBeta.exe
RobloxPlayerInstaller.exe
User:
admin
Company:
Roblox Corporation
Integrity Level:
MEDIUM
Description:
Roblox Game Client
Exit code:
3221225477
Version:
0, 646, 0, 6460700
Modules
Images
c:\users\admin\appdata\local\roblox\versions\version-eadc3c90bb1a4267\robloxplayerbeta.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\roblox\versions\version-eadc3c90bb1a4267\robloxplayerbeta.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
2692"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" -EmbeddingC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.171.39
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
3600"C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exe" -ServerName:App.AppXbdkk0yrkwpcgeaem8zk81k8py1eaahny.mcaC:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exesvchost.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\program files\windowsapps\microsoft.xboxgamingoverlay_2.34.28001.0_x64__8wekyb3d8bbwe\gamebar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\vccorlib140_app.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\msvcp140_app.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\concrt140_app.dll
3788C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3944C:\WINDOWS\System32\svchost.exe -k netsvcs -p -s BITSC:\Windows\System32\svchost.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
4232C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
Total events
24 240
Read events
21 751
Write events
2 421
Delete events
68

Modification events

(PID) Process:(5516) RobloxPlayerInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\ProtocolExecute\roblox-studio
Operation:writeName:WarnOnOpen
Value:
0
(PID) Process:(5516) RobloxPlayerInstaller.exeKey:HKEY_CLASSES_ROOT\roblox-studio
Operation:writeName:URL Protocol
Value:
(PID) Process:(5516) RobloxPlayerInstaller.exeKey:HKEY_CLASSES_ROOT\roblox-studio\shell\open\command
Operation:writeName:version
Value:
version-297eb79ede584243
(PID) Process:(3944) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS
Operation:writeName:PerfMMFileName
Value:
Global\MMF_BITSa30c85d9-8af2-442a-8107-70978eac1793
(PID) Process:(6756) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:delete valueName:eulaaccepted
Value:
(PID) Process:(6756) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:path
Value:
C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(PID) Process:(6756) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:UninstallCmdLine
Value:
"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /uninstall
(PID) Process:(6756) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.171.39
(PID) Process:(6756) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:name
Value:
Microsoft Edge Update
(PID) Process:(6756) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\ClientState\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.171.39
Executable files
209
Suspicious files
46
Text files
11
Unknown types
0

Dropped files

PID
Process
Filename
Type
5516RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\b4b75c21ce05378163042dc45cec5834compressed
MD5:B4B75C21CE05378163042DC45CEC5834
SHA256:4D6FE68C8B4941CE335CE5597EBBC1F27AB02646E9AF98AF8A76875AD0FD191F
5516RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\889e0052812b9ed64dd5653d29180ee7compressed
MD5:889E0052812B9ED64DD5653D29180EE7
SHA256:501BFA6CCEAB8DBE2510BCDE501E29C23D0786E8FB93AB9B4B8AABDD88973F16
5516RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\logs\cacert.pemtext
MD5:C656D325F5DF1991584F0BB00A27902F
SHA256:98ECAF8DA767CCB2870DD30A5E7334D2F45702A3A33EC8B4286E6AE88B720EB8
5516RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\a94b6d53eea3ae5600fc749c1a0bd8cccompressed
MD5:A94B6D53EEA3AE5600FC749C1A0BD8CC
SHA256:94541B0A6B6A403C8D7243EB3078264473F3244EB467815DC574ADAA0CE849C5
5516RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\e42a6697bf05466d4dba26c8fe476d2ecompressed
MD5:E42A6697BF05466D4DBA26C8FE476D2E
SHA256:622FF96317AAE6A02B9699F68CDF0FCE14FABDA171B49445B344A9BE62DE37B9
5516RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Versions\RobloxStudioInstaller.exeexecutable
MD5:5B794D63AE37A70DAFDE076B14F13960
SHA256:A9DE88A9E0EF908E7683CBB26E3B9D203C3DB4DE03F16220A219B3F4D61CE402
5516RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\09b83e05f472feabd5e1e4aa008959d8compressed
MD5:09B83E05F472FEABD5E1E4AA008959D8
SHA256:297A67B7FF95DACEC5595D450ABB3D1F19ADC225A661519D13D8AF8C168CF31C
5516RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\1d0390337d1a4a58e5514be1a9481ad6compressed
MD5:1D0390337D1A4A58E5514BE1A9481AD6
SHA256:C79F0EEB2BCA4905C585C50333DB3C6F727A554F5DB82E64948F93668FBC18AA
5516RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\8627dd60472c31b505c69a9388e759f6compressed
MD5:8627DD60472C31B505C69A9388E759F6
SHA256:202768B663D3490B97FB42FAF6B8D3F3963E4ACFCAFB650BDB6B39F82A9A377B
5516RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\30c885074d0320c0932e06bfd537c915compressed
MD5:30C885074D0320C0932E06BFD537C915
SHA256:4C732976972BBEC8B2B0C579067F6AB4A143263637E6F9A6E2AA1FE7F9A68E7B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
101
DNS requests
39
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3836
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6572
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6572
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3944
svchost.exe
HEAD
200
2.19.126.157:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/b53fa217-6f44-4585-a4ec-70ed35f2aa73?P1=1729544584&P2=404&P3=2&P4=JJbmAnfdNq9d2gK9suOKJFIiun9lYIgXaC3JLCEJn2XkH%2fmywJtq13%2b8vKYrpES5%2fHhAmp2e%2b1VvG6S2LuGL1Q%3d%3d
unknown
whitelisted
6692
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
3944
svchost.exe
GET
200
2.19.126.157:80
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/b53fa217-6f44-4585-a4ec-70ed35f2aa73?P1=1729544584&P2=404&P3=2&P4=JJbmAnfdNq9d2gK9suOKJFIiun9lYIgXaC3JLCEJn2XkH%2fmywJtq13%2b8vKYrpES5%2fHhAmp2e%2b1VvG6S2LuGL1Q%3d%3d
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
2.16.164.106:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6944
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2000
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5488
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5516
RobloxPlayerInstaller.exe
128.116.44.4:443
ecsv2.roblox.com
ROBLOX-PRODUCTION
US
whitelisted
5516
RobloxPlayerInstaller.exe
128.116.44.3:443
client-telemetry.roblox.com
ROBLOX-PRODUCTION
US
whitelisted
3836
svchost.exe
20.190.160.20:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4360
SearchApp.exe
150.171.28.10:443
www.bing.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3836
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.142
whitelisted
ecsv2.roblox.com
  • 128.116.44.4
whitelisted
client-telemetry.roblox.com
  • 128.116.44.3
whitelisted
login.live.com
  • 20.190.160.20
  • 40.126.32.134
  • 20.190.160.22
  • 20.190.160.17
  • 40.126.32.76
  • 40.126.32.136
  • 40.126.32.68
  • 40.126.32.74
whitelisted
www.bing.com
  • 150.171.28.10
  • 150.171.27.10
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
th.bing.com
  • 2.23.209.189
  • 2.23.209.193
  • 2.23.209.140
  • 2.23.209.149
  • 2.23.209.187
  • 2.23.209.179
  • 2.23.209.182
  • 2.23.209.133
  • 2.23.209.130
whitelisted
clientsettingscdn.roblox.com
  • 52.222.236.86
  • 52.222.236.43
  • 52.222.236.6
  • 52.222.236.113
whitelisted
setup.rbxcdn.com
  • 13.224.189.122
  • 13.224.189.83
  • 13.224.189.58
  • 13.224.189.57
whitelisted

Threats

PID
Process
Class
Message
3944
svchost.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
RobloxPlayerInstaller.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
RobloxPlayerBeta.exe
2024-10-14T21:04:28.448Z,0.448070,1b28,6 [FLog::Output] Loading AppSettings.xml from C:\Users\admin\AppData\Local\Roblox\Versions\version-eadc3c90bb1a4267\AppSettings.xml
RobloxPlayerBeta.exe
RobloxPlayerBeta.exe
2024-10-14T21:04:28.452Z,0.452088,1b28,6,Info [FLog::UpdateController] UpdateController: versionQueryUrl: https://clientsettingscdn.roblox.com/v2/client-version/WindowsPlayer
RobloxPlayerBeta.exe
RobloxPlayerBeta.exe
2024-10-14T21:04:28.453Z,0.453093,1b28,6,Info [FLog::UpdateController] WindowsUpdateController: updaterFullPath: C:\Users\admin\AppData\Local\Roblox\Versions\version-eadc3c90bb1a4267\RobloxPlayerInstaller.exe
RobloxPlayerBeta.exe
RobloxPlayerBeta.exe
2024-10-14T21:04:28.455Z,0.455102,0498,6,Info [FLog::UpdateController] Update check thread started
RobloxPlayerBeta.exe
RobloxPlayerBeta.exe
2024-10-14T21:04:28.456Z,0.456106,0498,6,Info [FLog::UpdateController] Checking if updater exists at C:\Users\admin\AppData\Local\Roblox\Versions\version-eadc3c90bb1a4267\RobloxPlayerInstaller.exe. Returning true