| File name: | RobloxPlayerInstaller-7MQ7FCYYYB.exe |
| Full analysis: | https://app.any.run/tasks/23e9a54e-3d9b-487a-b4eb-5e2f39d06252 |
| Verdict: | Malicious activity |
| Analysis date: | May 29, 2025, 19:16:06 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | 6EA9B4E01182ADF7F8F4409490CF77A6 |
| SHA1: | 06E39D7DB8A79851B1828BA41551DF15AB99A7FC |
| SHA256: | 99BB1F15FFD140E36CB26DFDD2487694C88A94C79FD73DB10DBB95101617F058 |
| SSDEEP: | 98304:Ms0n0RHraOWfrfceEqOdjMdiZgGwxU6KGR3GWjJS2U4g3J1YUtQpCU0r6Sj2kIeG:29hR+Js |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1983:12:29 01:51:34+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.29 |
| CodeSize: | 5692416 |
| InitializedDataSize: | 2106368 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x509e65 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.6.0.507 |
| ProductVersionNumber: | 1.6.0.507 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Roblox Corporation |
| FileDescription: | Roblox |
| FileVersion: | 1, 6, 0, 6750715 |
| LegalCopyright: | Copyright © 2020 Roblox Corporation. All rights reserved. |
| OriginalFileName: | Roblox.exe |
| ProductName: | Roblox Bootstrapper |
| ProductVersion: | 1, 6, 0, 6750715 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 208 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --mojo-platform-channel-handle=5452 --field-trial-handle=2136,i,15922847461173001445,2372740238279550862,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 516 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6540 --field-trial-handle=2292,i,11484197902993261800,18225436234540447243,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 632 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --mojo-platform-channel-handle=9024 --field-trial-handle=2292,i,11484197902993261800,18225436234540447243,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 672 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=62 --mojo-platform-channel-handle=9180 --field-trial-handle=2292,i,11484197902993261800,18225436234540447243,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 684 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --profile-directory=Default | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 732 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=122.0.6261.70 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=122.0.2365.59 --initial-client-data=0x290,0x294,0x298,0x288,0x2a0,0x7ffc89825fd8,0x7ffc89825fe4,0x7ffc89825ff0 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Version: 122.0.2365.59 Modules
| |||||||||||||||
| 968 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5208 --field-trial-handle=2292,i,11484197902993261800,18225436234540447243,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1760 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --no-appcompat-clear --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=2288 --field-trial-handle=2292,i,11484197902993261800,18225436234540447243,262144 --variations-seed-version /prefetch:2 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2092 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --instant-process --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3704 --field-trial-handle=2292,i,11484197902993261800,18225436234540447243,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 2192 | "C:\Users\admin\AppData\Local\Roblox\Versions\version-ad3ee47cdc5e44f6\RobloxPlayerBeta.exe" -app -installerLaunchTimeEpochMs 0 -clientLaunchTimeEpochMs 0 -isInstallerLaunch 7428 | C:\Users\admin\AppData\Local\Roblox\Versions\version-ad3ee47cdc5e44f6\RobloxPlayerBeta.exe | RobloxPlayerInstaller-7MQ7FCYYYB.exe | ||||||||||||
User: admin Company: Roblox Corporation Integrity Level: MEDIUM Description: Roblox Game Client Exit code: 3221225477 Version: 0, 675, 0, 6750715 Modules
| |||||||||||||||
| (PID) Process: | (7428) RobloxPlayerInstaller-7MQ7FCYYYB.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\ProtocolExecute\roblox-studio |
| Operation: | write | Name: | WarnOnOpen |
Value: 0 | |||
| (PID) Process: | (7428) RobloxPlayerInstaller-7MQ7FCYYYB.exe | Key: | HKEY_CLASSES_ROOT\roblox-studio |
| Operation: | write | Name: | URL Protocol |
Value: | |||
| (PID) Process: | (7428) RobloxPlayerInstaller-7MQ7FCYYYB.exe | Key: | HKEY_CLASSES_ROOT\roblox-studio\shell\open\command |
| Operation: | write | Name: | version |
Value: version-d9df23078b8e4749 | |||
| (PID) Process: | (7920) MicrosoftEdgeUpdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate |
| Operation: | delete value | Name: | eulaaccepted |
Value: | |||
| (PID) Process: | (7956) MicrosoftEdgeUpdate.exe | Key: | HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{81093D63-7825-417B-BFC8-ADC63FA4E53D}\InprocServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Both | |||
| (PID) Process: | (7956) MicrosoftEdgeUpdate.exe | Key: | HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{5EA43877-C6D8-4885-B77A-C0BB27E94372}\InprocServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Both | |||
| (PID) Process: | (7956) MicrosoftEdgeUpdate.exe | Key: | HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{D3E6ADD1-CFF8-465D-B996-174FF76B89D4}\InprocHandler32 |
| Operation: | write | Name: | ThreadingModel |
Value: Both | |||
| (PID) Process: | (7956) MicrosoftEdgeUpdate.exe | Key: | HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{81093D63-7825-417B-BFC8-ADC63FA4E53D}\InprocServer32 |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (7956) MicrosoftEdgeUpdate.exe | Key: | HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{81093D63-7825-417B-BFC8-ADC63FA4E53D} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (7956) MicrosoftEdgeUpdate.exe | Key: | HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{5EA43877-C6D8-4885-B77A-C0BB27E94372}\InprocServer32 |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7428 | RobloxPlayerInstaller-7MQ7FCYYYB.exe | C:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\f62f7d645c32934c6f4bf3cfd9de4562 | — | |
MD5:— | SHA256:— | |||
| 7428 | RobloxPlayerInstaller-7MQ7FCYYYB.exe | C:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\5fe3ebab23de62304fae1a8d19ab7afe | compressed | |
MD5:5FE3EBAB23DE62304FAE1A8D19AB7AFE | SHA256:727624F8059AEC7DD22E4C39F0D31D7A36DD6CFFD557E33DEB83832459D01BF4 | |||
| 7428 | RobloxPlayerInstaller-7MQ7FCYYYB.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox\Roblox Studio.lnk | binary | |
MD5:4F50D1E342639DC492810BD8CF49D970 | SHA256:A8E77BD83ADC92F5D8DFB7C9AE1C63F9DBEACDA98E94494900BEFE023BBDA880 | |||
| 7428 | RobloxPlayerInstaller-7MQ7FCYYYB.exe | C:\Users\admin\AppData\Local\Roblox\logs\cacert.pem | text | |
MD5:010D6ED950BB45C06D69F823689D38A0 | SHA256:560370CC311311DCA9F459668C820BAEB3177C99744A5810A254F1F72EA47E72 | |||
| 7428 | RobloxPlayerInstaller-7MQ7FCYYYB.exe | C:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\9f86768c45eeb01363f311e073ec7fab | compressed | |
MD5:9F86768C45EEB01363F311E073EC7FAB | SHA256:849814118E4D5E615B86C945A5A3C46BE18B6C9A011134E6B087DA37E8DD5C8E | |||
| 7428 | RobloxPlayerInstaller-7MQ7FCYYYB.exe | C:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\4350aaa5c4eb7dd63fb86b1acde58ed0 | compressed | |
MD5:4350AAA5C4EB7DD63FB86B1ACDE58ED0 | SHA256:506A1482F56D8DBECE216D19BD100C71D1B65ED486C9AEC84043A6E70157D65A | |||
| 7428 | RobloxPlayerInstaller-7MQ7FCYYYB.exe | C:\Users\admin\AppData\Local\Roblox\Versions\RobloxStudioInstaller.exe | executable | |
MD5:54C52F1E03AE51FA667FE52AA9097539 | SHA256:527AF50E97815DFBFE02F26B7F19787E9368DD0329BBB1970973BBE424EA89FE | |||
| 7428 | RobloxPlayerInstaller-7MQ7FCYYYB.exe | C:\Users\admin\Desktop\Roblox Studio.lnk | binary | |
MD5:1C59F5C95EA0CDC351DC67325C2A9E8D | SHA256:00E32554861130B2DF6C607393D87AEA023F6652B1FA995AAFD80455345CB380 | |||
| 7428 | RobloxPlayerInstaller-7MQ7FCYYYB.exe | C:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\8f379ec2b22ff106b837d79f7fdbf0d8 | compressed | |
MD5:8F379EC2B22FF106B837D79F7FDBF0D8 | SHA256:6620658A6288E6B58B8D86AAEF4E7734E10778974E9A01D364FC7AAC4D35F10B | |||
| 7428 | RobloxPlayerInstaller-7MQ7FCYYYB.exe | C:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\19f308d30350d08e337f40ed474b0e69 | compressed | |
MD5:19F308D30350D08E337F40ED474B0E69 | SHA256:32C0C61B47364623783E34582E5D0E384F9C16F90814375BA5246F64A89A7A5E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1284 | svchost.exe | HEAD | 200 | 199.232.210.172:80 | http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/374973f4-2935-4802-a6ad-3efbd5eaded0?P1=1749150987&P2=404&P3=2&P4=TG%2fwryIDV3AWhD57IOSPm76NocmicR3%2fdT9RiqrOq9AGnU3XnwS1TrQokh36LkWrMh571MCBY4SiSQx8%2bWJRVA%3d%3d | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.32.238.34:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
3192 | SIHClient.exe | GET | 200 | 2.16.253.202:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
1284 | svchost.exe | GET | 206 | 199.232.210.172:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1748975639&P2=404&P3=2&P4=JjlGU8RbgE4ZNZxH6Tq4mMkiOMxly4KQNhMBr04%2b0uUggVlUak6P1kOkps3NqAm%2fO3U0UaLjdqXYLy%2ftJhLzQw%3d%3d | unknown | — | — | whitelisted |
1284 | svchost.exe | HEAD | 200 | 199.232.210.172:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1748975639&P2=404&P3=2&P4=JjlGU8RbgE4ZNZxH6Tq4mMkiOMxly4KQNhMBr04%2b0uUggVlUak6P1kOkps3NqAm%2fO3U0UaLjdqXYLy%2ftJhLzQw%3d%3d | unknown | — | — | whitelisted |
3192 | SIHClient.exe | GET | 200 | 2.16.253.202:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.16.253.202:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1284 | svchost.exe | GET | — | 199.232.210.172:80 | http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/374973f4-2935-4802-a6ad-3efbd5eaded0?P1=1749150987&P2=404&P3=2&P4=TG%2fwryIDV3AWhD57IOSPm76NocmicR3%2fdT9RiqrOq9AGnU3XnwS1TrQokh36LkWrMh571MCBY4SiSQx8%2bWJRVA%3d%3d | unknown | — | — | whitelisted |
1284 | svchost.exe | GET | 206 | 199.232.210.172:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/9b9f8fb4-8a65-41e4-bda3-5416858f0aeb?P1=1748975639&P2=404&P3=2&P4=JjlGU8RbgE4ZNZxH6Tq4mMkiOMxly4KQNhMBr04%2b0uUggVlUak6P1kOkps3NqAm%2fO3U0UaLjdqXYLy%2ftJhLzQw%3d%3d | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4784 | RUXIMICS.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.32.238.34:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.16.253.202:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
5796 | svchost.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
7428 | RobloxPlayerInstaller-7MQ7FCYYYB.exe | 128.116.5.3:443 | ecsv2.roblox.com | ROBLOX-PRODUCTION | US | whitelisted |
7428 | RobloxPlayerInstaller-7MQ7FCYYYB.exe | 23.45.109.46:443 | clientsettingscdn.roblox.com | AKAMAI-AS | DE | whitelisted |
7428 | RobloxPlayerInstaller-7MQ7FCYYYB.exe | 18.245.31.60:443 | setup.rbxcdn.com | — | US | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
ecsv2.roblox.com |
| whitelisted |
clientsettingscdn.roblox.com |
| whitelisted |
apis.roblox.com |
| whitelisted |
setup.rbxcdn.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1284 | svchost.exe | Misc activity | ET INFO Packed Executable Download |
7052 | msedge.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
7052 | msedge.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
7052 | msedge.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
7052 | msedge.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
7052 | msedge.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
7052 | msedge.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
7052 | msedge.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
7052 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
7052 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |