File name:

RobloxPlayerInstaller.exe

Full analysis: https://app.any.run/tasks/8bc3aa6b-9413-4924-b10f-df559a875a74
Verdict: Malicious activity
Analysis date: February 28, 2026, 12:48:38
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
roblox
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

A1AF6BFC6571A173EE91DCF36C0BABF1

SHA1:

7BE61E72C254C5016D89896285EE335C9EA1049E

SHA256:

92AD4BF6CE23CCF7D802530FDE9773E336E2F3E03C6C2DF2D15A300FBD735DFA

SSDEEP:

98304:hs01F1pMKfhjrQadr4Zl6P2zJL1jr+hcbuktGbxIkAhTj+gO1K7yoEY9KnviILUM:a/pM9B8mX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • MicrosoftEdgeUpdate.exe (PID: 7528)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • RobloxPlayerInstaller.exe (PID: 7820)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 7528)
    • Changes default file association

      • RobloxPlayerInstaller.exe (PID: 7820)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeUpdate.exe (PID: 7528)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5220)
      • MicrosoftEdgeUpdate.exe (PID: 5456)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5164)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7764)
    • Application launched itself

      • setup.exe (PID: 7988)
      • MicrosoftEdgeUpdate.exe (PID: 7532)
    • Searches for installed software

      • setup.exe (PID: 7988)
    • Executes application which crashes

      • RobloxPlayerBeta.exe (PID: 2216)
      • RobloxPlayerBeta.exe (PID: 7192)
      • RobloxPlayerBeta.exe (PID: 6804)
  • INFO

    • Reads the computer name

      • RobloxPlayerInstaller.exe (PID: 7820)
      • MicrosoftEdgeUpdate.exe (PID: 7528)
      • MicrosoftEdgeUpdate.exe (PID: 5456)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5164)
      • MicrosoftEdgeUpdate.exe (PID: 7532)
      • MicrosoftEdgeUpdate.exe (PID: 8116)
      • MicrosoftEdgeUpdate.exe (PID: 6024)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7764)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5220)
      • MicrosoftEdgeUpdate.exe (PID: 5404)
      • MicrosoftEdgeUpdateCore.exe (PID: 5456)
      • MicrosoftEdge_X64_145.0.3800.82.exe (PID: 2036)
      • setup.exe (PID: 7988)
      • MicrosoftEdgeUpdate.exe (PID: 900)
    • Create files in a temporary directory

      • MicrosoftEdgeWebview2Setup.exe (PID: 4104)
      • MicrosoftEdgeUpdate.exe (PID: 7528)
      • RobloxPlayerInstaller.exe (PID: 7820)
    • Drops script file

      • RobloxPlayerInstaller.exe (PID: 7820)
      • WinRAR.exe (PID: 2216)
      • setup.exe (PID: 7988)
      • cmd.exe (PID: 508)
    • Reads the machine GUID from the registry

      • RobloxPlayerInstaller.exe (PID: 7820)
      • MicrosoftEdgeUpdate.exe (PID: 7532)
    • Checks supported languages

      • RobloxPlayerInstaller.exe (PID: 7820)
      • MicrosoftEdgeUpdate.exe (PID: 5456)
      • MicrosoftEdgeUpdate.exe (PID: 7528)
      • MicrosoftEdgeWebview2Setup.exe (PID: 4104)
      • MicrosoftEdgeUpdate.exe (PID: 8116)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5164)
      • MicrosoftEdgeUpdate.exe (PID: 6024)
      • MicrosoftEdgeUpdate.exe (PID: 7532)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 7764)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5220)
      • MicrosoftEdgeUpdateCore.exe (PID: 5456)
      • MicrosoftEdgeUpdate.exe (PID: 5404)
      • setup.exe (PID: 7988)
      • setup.exe (PID: 7816)
      • MicrosoftEdge_X64_145.0.3800.82.exe (PID: 2036)
      • MicrosoftEdgeUpdate.exe (PID: 900)
      • RobloxPlayerBeta.exe (PID: 2216)
      • RobloxPlayerBeta.exe (PID: 7192)
      • RobloxPlayerBeta.exe (PID: 6804)
    • Launching a file from a Registry key

      • MicrosoftEdgeUpdate.exe (PID: 7528)
    • The sample compiled with english language support

      • RobloxPlayerInstaller.exe (PID: 7820)
    • Process checks whether UAC notifications are on

      • RobloxPlayerInstaller.exe (PID: 7820)
    • ROBLOX mutex has been found

      • RobloxPlayerInstaller.exe (PID: 7820)
    • Creates files or folders in the user directory

      • MicrosoftEdgeUpdate.exe (PID: 7528)
      • RobloxPlayerInstaller.exe (PID: 7820)
      • MicrosoftEdge_X64_145.0.3800.82.exe (PID: 2036)
      • MicrosoftEdgeUpdate.exe (PID: 7532)
      • setup.exe (PID: 7816)
      • setup.exe (PID: 7988)
    • Checks proxy server information

      • MicrosoftEdgeUpdate.exe (PID: 8116)
      • MicrosoftEdgeUpdate.exe (PID: 7532)
      • MicrosoftEdgeUpdate.exe (PID: 900)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 8116)
      • MicrosoftEdgeUpdate.exe (PID: 900)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 7528)
      • MicrosoftEdgeUpdate.exe (PID: 7532)
    • Process checks computer location settings

      • MicrosoftEdgeUpdate.exe (PID: 7528)
      • setup.exe (PID: 7988)
    • Manual execution by a user

      • MicrosoftEdgeUpdateCore.exe (PID: 5456)
      • WinRAR.exe (PID: 2216)
      • cmd.exe (PID: 508)
      • RobloxPlayerBeta.exe (PID: 7192)
      • RobloxPlayerBeta.exe (PID: 6804)
    • Creates a software uninstall entry

      • setup.exe (PID: 7988)
      • RobloxPlayerInstaller.exe (PID: 7820)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1990:10:16 18:04:11+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 7404032
InitializedDataSize: 2573312
UninitializedDataSize: -
EntryPoint: 0x6a122e
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.6.1.22819
ProductVersionNumber: 1.6.1.22819
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Roblox Corporation
FileDescription: Roblox
FileVersion: 1, 6, 1, 7100707
LegalCopyright: Copyright © 2020 Roblox Corporation. All rights reserved.
OriginalFileName: Roblox.exe
ProductName: Roblox Bootstrapper
ProductVersion: 1, 6, 1, 7100707
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
163
Monitored processes
25
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start robloxplayerinstaller.exe microsoftedgewebview2setup.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe winrar.exe no specs microsoftedgeupdatecore.exe no specs microsoftedgeupdate.exe no specs microsoftedge_x64_145.0.3800.82.exe no specs setup.exe no specs setup.exe no specs cmd.exe no specs conhost.exe no specs microsoftedgeupdate.exe robloxplayerbeta.exe werfault.exe no specs robloxplayerbeta.exe werfault.exe no specs robloxplayerbeta.exe werfault.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
508C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\Desktop\LInjector-main\LInjector-main\build_singlefile.cmd" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
3221225786
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
c:\windows\system32\advapi32.dll
900"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xOTUuNDUiIHNoZWxsX3ZlcnNpb249IjEuMy4xOTUuNDUiIGlzbWFjaGluZT0iMCIgc2Vzc2lvbmlkPSJ7Q0YzQTFBNTItQjk5Qi00REE2LUIyQzAtNEUwNTgzQkU2QTY5fSIgdXNlcmlkPSJ7QTI0NzkzNDctQkQ3OS00RDZDLUIyNDAtRjZCRUI1NEIwNEU5fSIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiByZXF1ZXN0aWQ9IntFRTlDRDBGNy1GMTY5LTQ4NDYtQjM2MC1EQzlBOEZEQjhFQTV9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iNiIgcGh5c21lbW9yeT0iNiIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE5MDQ1LjQwNDYiIHNwPSIiIGFyY2g9Ing2NCIgcHJvZHVjdF90eXBlPSI0OCIgaXNfd2lwPSIwIiBpc19pbl9sb2NrZG93bl9tb2RlPSIwIi8-PG9lbSBwcm9kdWN0X21hbnVmYWN0dXJlcj0iREVMTCIgcHJvZHVjdF9uYW1lPSJERUxMIi8-PGV4cCBldGFnPSImcXVvdDsrWkZBajNTT0lJNUJKem9HdXo4T3ByMGhaOEgvckR6cWIvUVZyM1BZaDRJPSZxdW90OyIvPjxhcHAgYXBwaWQ9IntGMzAxNzIyNi1GRTJBLTQyOTUtOEJERi0wMEMzQTlBN0U0QzV9IiB2ZXJzaW9uPSIiIG5leHR2ZXJzaW9uPSIxNDUuMC4zODAwLjgyIiBsYW5nPSJlbiIgYnJhbmQ9IiIgY2xpZW50PSIiIGV4cGVyaW1lbnRzPSJjb25zZW50PWZhbHNlIiBpbnN0YWxsYWdlPSItMSIgaW5zdGFsbGRhdGU9Ii0xIj48dXBkYXRlY2hlY2svPjxldmVudCBldmVudHR5cGU9IjkiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIHN5c3RlbV91cHRpbWVfdGlja3M9IjgxMTE1MDQwNDgiIGRvbmVfYmVmb3JlX29vYmVfY29tcGxldGU9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSI1IiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSI4MTExNTc0MDc0IiBkb25lX2JlZm9yZV9vb2JlX2NvbXBsZXRlPSIwIi8-PGV2ZW50IGV2ZW50dHlwZT0iMSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iODIyMzEzNjg4NCIgc291cmNlX3VybF9pbmRleD0iMCIgZG9uZV9iZWZvcmVfb29iZV9jb21wbGV0ZT0iMCIgZG93bmxvYWRlcj0iYml0cyIgdXJsPSJodHRwOi8vbXNlZGdlLmYudGx1LmRsLmRlbGl2ZXJ5Lm1wLm1pY3Jvc29mdC5jb20vZmlsZXN0cmVhbWluZ3NlcnZpY2UvZmlsZXMvMTczNzQ5OTMtYTg5Ny00NDE2LWIzY2YtMTdhNGI3ZmRiZTllP1AxPTE3NzI4ODc3NDUmYW1wO1AyPTQwNCZhbXA7UDM9MiZhbXA7UDQ9RTVSRzVXdDhveXd6dGRxeCUyYm13MDMyaSUyYkRRZ0FicVIzcGRweEdycEdkR0IlMmY3V0tIenozQnVrR01oVHhQOXpNTDh0RzlCOXBUaEtYdjhYWnZZUmF3b2clM2QlM2QiIHNlcnZlcl9pcF9oaW50PSIiIGNkbl9jaWQ9Ii0xIiBjZG5fY2NjPSIiIGNkbl9tc2VkZ2VfcmVmPSIiIGNkbl9henVyZV9yZWZfb3JpZ2luX3NoaWVsZD0iIiBjZG5fY2FjaGU9IiIgY2RuX3AzcD0iIiBkb3dubG9hZGVkPSIxODY1OTQ0MDAiIHRvdGFsPSIxODY1OTQ0MDAiIGRvd25sb2FkX3RpbWVfbXM9IjgwOTkiLz48ZXZlbnQgZXZlbnR0eXBlPSIxIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSI4MjIzMzU2ODkwIiBzb3VyY2VfdXJsX2luZGV4PSIwIiBkb25lX2JlZm9yZV9vb2JlX2NvbXBsZXRlPSIwIi8-PGV2ZW50IGV2ZW50dHlwZT0iNiIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iODI0NjQwNTQwOSIgZG9uZV9iZWZvcmVfb29iZV9jb21wbGV0ZT0iMCIvPjxldmVudCBldmVudHR5cGU9IjIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjE5Njc1NyIgc3lzdGVtX3VwdGltZV90aWNrcz0iODU4MzM2Mzk0OSIgc291cmNlX3VybF9pbmRleD0iMCIgZG9uZV9iZWZvcmVfb29iZV9jb21wbGV0ZT0iMCIgdXBkYXRlX2NoZWNrX3RpbWVfbXM9IjIxMSIgZG93bmxvYWRfdGltZV9tcz0iMTExNzEiIGRvd25sb2FkZWQ9IjE4NjU5NDQwMCIgdG90YWw9IjE4NjU5NDQwMCIgcGFja2FnZV9jYWNoZV9yZXN1bHQ9IjAiIGluc3RhbGxfdGltZV9tcz0iMzM2ODMiLz48L2FwcD48L3JlcXVlc3Q-C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
MicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update
Exit code:
0
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\microsoftedgeupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
996C:\WINDOWS\system32\WerFault.exe -u -p 7192 -s 404C:\Windows\System32\WerFault.exeRobloxPlayerBeta.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\oleaut32.dll
2036"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{2AE1F892-7A7C-430B-B67B-7FCF6E09CF8C}\MicrosoftEdge_X64_145.0.3800.82.exe" --msedgewebview --verbose-logging --do-not-launch-msedge --user-levelC:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{2AE1F892-7A7C-430B-B67B-7FCF6E09CF8C}\MicrosoftEdge_X64_145.0.3800.82.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
145.0.3800.82
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{2ae1f892-7a7c-430b-b67b-7fcf6e09cf8c}\microsoftedge_x64_145.0.3800.82.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2216"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\LInjector-main.zip" C:\Users\admin\Desktop\LInjector-main\C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2216"C:\Users\admin\AppData\Local\Roblox\Versions\version-760d064d05424689\RobloxPlayerBeta.exe" -app -installerLaunchTimeEpochMs 0 -clientLaunchTimeEpochMs 0 -isInstallerLaunch 7820C:\Users\admin\AppData\Local\Roblox\Versions\version-760d064d05424689\RobloxPlayerBeta.exe
RobloxPlayerInstaller.exe
User:
admin
Company:
Roblox Corporation
Integrity Level:
MEDIUM
Description:
Roblox Game Client
Exit code:
3221226505
Version:
0, 710, 1, 7100707
Modules
Images
c:\users\admin\appdata\local\roblox\versions\version-760d064d05424689\robloxplayerbeta.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\roblox\versions\version-760d064d05424689\robloxplayerbeta.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
2368\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3264C:\WINDOWS\system32\WerFault.exe -u -p 6804 -s 380C:\Windows\System32\WerFault.exeRobloxPlayerBeta.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
4104MicrosoftEdgeWebview2Setup.exe /silent /installC:\Users\admin\AppData\Local\Roblox\Versions\version-760d064d05424689\WebView2RuntimeInstaller\MicrosoftEdgeWebview2Setup.exeRobloxPlayerInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Exit code:
0
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\roblox\versions\version-760d064d05424689\webview2runtimeinstaller\microsoftedgewebview2setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5164"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.195.45\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
10 388
Read events
8 822
Write events
1 500
Delete events
66

Modification events

(PID) Process:(7820) RobloxPlayerInstaller.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\ProtocolExecute\roblox-studio
Operation:writeName:WarnOnOpen
Value:
0
(PID) Process:(7820) RobloxPlayerInstaller.exeKey:HKEY_CLASSES_ROOT\roblox-studio
Operation:writeName:URL Protocol
Value:
(PID) Process:(7820) RobloxPlayerInstaller.exeKey:HKEY_CLASSES_ROOT\roblox-studio\shell\open\command
Operation:writeName:version
Value:
version-e095049f34844c41
(PID) Process:(7528) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:delete valueName:eulaaccepted
Value:
(PID) Process:(7528) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:path
Value:
C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
(PID) Process:(7528) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:writeName:UninstallCmdLine
Value:
"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /uninstall
(PID) Process:(7528) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.195.45
(PID) Process:(7528) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:name
Value:
Microsoft Edge Update
(PID) Process:(7528) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\ClientState\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.195.45
(PID) Process:(7528) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Microsoft Edge Update
Value:
"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateCore.exe"
Executable files
2
Suspicious files
0
Text files
0
Unknown types
316

Dropped files

PID
Process
Filename
Type
7820RobloxPlayerInstaller.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox\Roblox Studio.lnkbinary
MD5:89987137F379824C6DBBD95255BBEB70
SHA256:C7AD0FEC711A4E38B8055C0530CEFB1BE1D669DEEE1ED9E34F30C2E4CA3CACE5
7820RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Versions\RobloxStudioInstaller.exebinary
MD5:B7FD22DC11BC090B80917AFD62D02B4B
SHA256:8B5BF8CFFAB53D52B9346D211F509DE2648912E5CBAFB5C9671DAC0AE2466BA1
7820RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\7a62d6043b4688b6c2388f73390ec6c1binary
MD5:7A62D6043B4688B6C2388F73390EC6C1
SHA256:9E60A27AA48750E049852E623D268BE56246258BBCE78ED36199C6225E472B56
7820RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\38bad56b72b448a941153a7571c1fc38binary
MD5:38BAD56B72B448A941153A7571C1FC38
SHA256:4113F7632251BF5A98621A7CCCA9FEA0F117EE8DE85492B7DEC52C6AF350EBBC
7820RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\eb9dd4d0637fd6ae21747e6b6a281d21binary
MD5:EB9DD4D0637FD6AE21747E6B6A281D21
SHA256:5A3AAE5657899B6452004F3F43F122CB6C166C99B7261EFBEB965DA906626ED8
7820RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\cf6354c3365a4f2d09391617e7927d20binary
MD5:CF6354C3365A4F2D09391617E7927D20
SHA256:F153021929D35CC3BE2EE7E2D31D1847E655DDB6E43165C37AA7D87E29980638
7820RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\abb7c39322776c81855fe71c1451bba7binary
MD5:ABB7C39322776C81855FE71C1451BBA7
SHA256:A418F0103945D93EDADBA745A0BA6E15766669736FEEA56E6F7CC3DD5CF4516E
7820RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\10461fdfb35f35cca13dbe35dcf21343binary
MD5:10461FDFB35F35CCA13DBE35DCF21343
SHA256:73C9D9A9333623A070CCC1E5F6CF325D83F1EF9CE35C4D255B66A1733F6E6A91
7820RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\1d0390337d1a4a58e5514be1a9481ad6binary
MD5:1D0390337D1A4A58E5514BE1A9481AD6
SHA256:C79F0EEB2BCA4905C585C50333DB3C6F727A554F5DB82E64948F93668FBC18AA
7820RobloxPlayerInstaller.exeC:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\1071d083ebaf634fd6929969fc85fcf3binary
MD5:1071D083EBAF634FD6929969FC85FCF3
SHA256:BEE8EEA163344EB79155991A9950BD077C4B29244A1D4712BC1A525148D08CDD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
29
TCP/UDP connections
42
DNS requests
26
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5276
MoUsoCoreWorker.exe
GET
304
20.73.194.208:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
5276
MoUsoCoreWorker.exe
GET
304
20.73.194.208:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
7248
svchost.exe
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
5276
MoUsoCoreWorker.exe
GET
200
2.16.164.72:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
8012
svchost.exe
GET
304
20.73.194.208:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
whitelisted
4236
SIHClient.exe
GET
304
135.233.95.144:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
4236
SIHClient.exe
GET
200
13.95.31.18:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
4236
SIHClient.exe
GET
200
135.233.95.144:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
4236
SIHClient.exe
GET
304
135.233.95.144:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
900
MicrosoftEdgeUpdate.exe
GET
304
150.171.22.17:443
https://config.edge.skype.com/config/v1/EdgeUpdate/1.3.195.45?clientId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&appChannel_webview=5&appConsentState_webview=0&appDayOfInstall_webview=-1&appInactivityBadgeApplied_webview=0&appInactivityBadgeCleared_webview=0&appInactivityBadgeDuration_webview=0&appInstallTimeDiffSec_webview=-86400&appIsPinnedSystem_webview=false&appLang_webview=en&appLastLaunchCount_webview=0&appLastLaunchTime_webview=0&appLastLaunchTimeJson_webview=0&appLastLaunchTimeDaysAgo_webview=0&appVersion_webview=145.0.3800.82&appUpdateCheckIsUpdateDisabled_webview=false&appUpdatesAllowedForMeteredNetworks_webview=false&hwDiskType=2&hwHasSsse3=true&hwLogicalCpus=6&hwPhysmemory=6&isCTADevice=false&isMsftDomainJoined=false&oemProductManufacturer=DELL&oemProductName=DELL&osArch=x64&osIsDefaultNetworkConnectionMetered=false&osIsInLockdownMode=false&osIsWIP=false&osPlatform=win&osProductType=48&osVersion=10.0.19045.4046&requestCheckPeriodSec=-1&requestDomainJoined=false&requestInstallSource=otherinstallcmd&requestIsMachine=false&requestOmahaShellVersion=1.3.195.45&requestOmahaVersion=1.3.195.45
US
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
8012
svchost.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5276
MoUsoCoreWorker.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7248
svchost.exe
20.190.159.131:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
7820
RobloxPlayerInstaller.exe
128.116.5.3:443
ecsv2.roblox.com
ROBLOX-PRODUCTION
US
whitelisted
7820
RobloxPlayerInstaller.exe
23.201.250.50:443
clientsettingscdn.roblox.com
AKAMAI-AS
US
whitelisted
7820
RobloxPlayerInstaller.exe
54.192.35.28:443
setup.rbxcdn.com
AMAZON-02
US
whitelisted
5532
SearchApp.exe
23.36.162.88:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted

DNS requests

Domain
IP
Reputation
login.live.com
  • 20.190.159.131
  • 40.126.31.130
  • 40.126.31.2
  • 20.190.159.129
  • 20.190.159.68
  • 20.190.159.130
  • 40.126.31.73
  • 20.190.159.4
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
google.com
  • 172.217.20.142
whitelisted
self.events.data.microsoft.com
  • 13.89.179.11
whitelisted
ecsv2.roblox.com
  • 128.116.5.3
whitelisted
client-telemetry.roblox.com
  • 128.116.5.3
whitelisted
clientsettingscdn.roblox.com
  • 23.201.250.50
whitelisted
setup.rbxcdn.com
  • 54.192.35.28
  • 54.192.35.42
  • 54.192.35.27
  • 54.192.35.111
whitelisted
www.bing.com
  • 23.36.162.88
  • 23.36.162.68
  • 23.36.162.72
  • 23.36.162.73
  • 23.36.162.79
  • 23.36.162.85
  • 23.36.162.86
  • 23.36.162.83
  • 23.36.162.76
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 172.66.2.5
  • 162.159.142.9
whitelisted

Threats

PID
Process
Class
Message
6060
svchost.exe
Misc activity
ET INFO Packed Executable Download
5276
MoUsoCoreWorker.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
Process
Message
RobloxPlayerInstaller.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.