URL:

roblox.com

Full analysis: https://app.any.run/tasks/f2af05cb-b642-4b89-90f3-f0fd5758c136
Verdict: Malicious activity
Analysis date: March 06, 2026, 06:52:11
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
obfuscated-js
roblox
qrcode
Indicators:
MD5:

C06012A24CBE7C52D0E0A9AD4A936C79

SHA1:

FB22C4B259680F2301B90F8DD5FB40D975C17190

SHA256:

C1688E9B4C7A1DC950E389DE2A104CCDC8C80648F9202D1CCA5F4289D5D43032

SSDEEP:

3:MJ6In:MNn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • MicrosoftEdgeUpdate.exe (PID: 2332)
  • SUSPICIOUS

    • Changes default file association

      • RobloxPlayerInstaller-G32TBW7TJY.exe (PID: 8468)
    • Executable content was dropped or overwritten

      • RobloxPlayerInstaller-G32TBW7TJY.exe (PID: 8468)
      • MicrosoftEdgeWebview2Setup.exe (PID: 1000)
      • MicrosoftEdgeUpdate.exe (PID: 2332)
      • MicrosoftEdge_X64_145.0.3800.82.exe (PID: 4516)
      • setup.exe (PID: 6172)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeUpdate.exe (PID: 2332)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 2332)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 8148)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6156)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 1188)
      • MicrosoftEdgeUpdate.exe (PID: 3716)
    • Application launched itself

      • setup.exe (PID: 6172)
      • MicrosoftEdgeUpdate.exe (PID: 7292)
    • Potential Corporate Privacy Violation

      • chrome.exe (PID: 8132)
      • RobloxPlayerInstaller-G32TBW7TJY.exe (PID: 8468)
    • Searches for installed software

      • setup.exe (PID: 6172)
    • Executes application which crashes

      • RobloxPlayerBeta.exe (PID: 1172)
      • RobloxPlayerBeta.exe (PID: 5216)
      • RobloxPlayerBeta.exe (PID: 3192)
  • INFO

    • Executable content was dropped or overwritten

      • chrome.exe (PID: 6996)
      • chrome.exe (PID: 7376)
    • Page contains obfuscated JavaScript

      • chrome.exe (PID: 7376)
    • The sample compiled with english language support

      • chrome.exe (PID: 6996)
      • chrome.exe (PID: 7376)
      • RobloxPlayerInstaller-G32TBW7TJY.exe (PID: 8468)
      • MicrosoftEdgeWebview2Setup.exe (PID: 1000)
      • MicrosoftEdgeUpdate.exe (PID: 2332)
      • MicrosoftEdge_X64_145.0.3800.82.exe (PID: 4516)
      • setup.exe (PID: 6172)
    • Checks supported languages

      • RobloxPlayerInstaller-G32TBW7TJY.exe (PID: 8468)
      • MicrosoftEdgeWebview2Setup.exe (PID: 1000)
      • MicrosoftEdgeUpdate.exe (PID: 2332)
      • MicrosoftEdgeUpdate.exe (PID: 3716)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 8148)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6156)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 1188)
      • MicrosoftEdgeUpdate.exe (PID: 7292)
      • MicrosoftEdgeUpdate.exe (PID: 4372)
      • MicrosoftEdgeUpdate.exe (PID: 7480)
      • MicrosoftEdge_X64_145.0.3800.82.exe (PID: 4516)
      • setup.exe (PID: 5780)
      • setup.exe (PID: 6172)
      • MicrosoftEdgeUpdate.exe (PID: 3944)
      • RobloxPlayerBeta.exe (PID: 1172)
      • RobloxPlayerBeta.exe (PID: 5216)
      • RobloxPlayerBeta.exe (PID: 3192)
    • Checks proxy server information

      • slui.exe (PID: 5992)
      • MicrosoftEdgeUpdate.exe (PID: 4372)
      • MicrosoftEdgeUpdate.exe (PID: 7292)
      • MicrosoftEdgeUpdate.exe (PID: 3944)
    • Reads the machine GUID from the registry

      • RobloxPlayerInstaller-G32TBW7TJY.exe (PID: 8468)
      • MicrosoftEdgeUpdate.exe (PID: 7292)
    • Reads the computer name

      • RobloxPlayerInstaller-G32TBW7TJY.exe (PID: 8468)
      • MicrosoftEdgeUpdate.exe (PID: 2332)
      • MicrosoftEdgeUpdate.exe (PID: 3716)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 8148)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6156)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 1188)
      • MicrosoftEdgeUpdate.exe (PID: 4372)
      • MicrosoftEdgeUpdate.exe (PID: 7292)
      • MicrosoftEdgeUpdate.exe (PID: 7480)
      • MicrosoftEdge_X64_145.0.3800.82.exe (PID: 4516)
      • setup.exe (PID: 6172)
      • MicrosoftEdgeUpdate.exe (PID: 3944)
    • Process checks whether UAC notifications are on

      • RobloxPlayerInstaller-G32TBW7TJY.exe (PID: 8468)
    • Application launched itself

      • chrome.exe (PID: 7376)
    • Creates files or folders in the user directory

      • RobloxPlayerInstaller-G32TBW7TJY.exe (PID: 8468)
      • MicrosoftEdgeUpdate.exe (PID: 2332)
      • MicrosoftEdgeUpdate.exe (PID: 7292)
      • MicrosoftEdge_X64_145.0.3800.82.exe (PID: 4516)
      • setup.exe (PID: 6172)
      • setup.exe (PID: 5780)
    • ROBLOX mutex has been found

      • RobloxPlayerInstaller-G32TBW7TJY.exe (PID: 8468)
    • Launching a file from the Downloads directory

      • chrome.exe (PID: 7376)
    • Create files in a temporary directory

      • RobloxPlayerInstaller-G32TBW7TJY.exe (PID: 8468)
      • MicrosoftEdgeWebview2Setup.exe (PID: 1000)
    • Launching a file from a Registry key

      • MicrosoftEdgeUpdate.exe (PID: 2332)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 4372)
      • MicrosoftEdgeUpdate.exe (PID: 3944)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 2332)
      • MicrosoftEdgeUpdate.exe (PID: 7292)
    • Process checks computer location settings

      • MicrosoftEdgeUpdate.exe (PID: 2332)
      • setup.exe (PID: 6172)
    • Creates a software uninstall entry

      • setup.exe (PID: 6172)
      • RobloxPlayerInstaller-G32TBW7TJY.exe (PID: 8468)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
236
Monitored processes
79
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs slui.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs robloxplayerinstaller-g32tbw7tjy.exe chrome.exe no specs chrome.exe no specs microsoftedgewebview2setup.exe microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdatecomregistershell64.exe no specs microsoftedgeupdate.exe microsoftedgeupdate.exe no specs microsoftedgeupdate.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs microsoftedge_x64_145.0.3800.82.exe setup.exe setup.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs microsoftedgeupdate.exe robloxplayerbeta.exe werfault.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs robloxplayerbeta.exe werfault.exe no specs chrome.exe no specs robloxplayerbeta.exe werfault.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1000MicrosoftEdgeWebview2Setup.exe /silent /installC:\Users\admin\AppData\Local\Roblox\Versions\version-d599f7fc52a8404c\WebView2RuntimeInstaller\MicrosoftEdgeWebview2Setup.exe
RobloxPlayerInstaller-G32TBW7TJY.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update Setup
Exit code:
0
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\roblox\versions\version-d599f7fc52a8404c\webview2runtimeinstaller\microsoftedgewebview2setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
1172"C:\Users\admin\AppData\Local\Roblox\Versions\version-d599f7fc52a8404c\RobloxPlayerBeta.exe" -personalizedToken G32TBW7TJY --deeplink https://www.roblox.com/games/94217045453265/Dueling-Grounds -app -installerLaunchTimeEpochMs 0 -clientLaunchTimeEpochMs 0 -isInstallerLaunch 8468C:\Users\admin\AppData\Local\Roblox\Versions\version-d599f7fc52a8404c\RobloxPlayerBeta.exe
RobloxPlayerInstaller-G32TBW7TJY.exe
User:
admin
Company:
Roblox Corporation
Integrity Level:
MEDIUM
Description:
Roblox Game Client
Exit code:
3221226505
Version:
0, 711, 0, 7110875
Modules
Images
c:\users\admin\appdata\local\roblox\versions\version-d599f7fc52a8404c\robloxplayerbeta.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\roblox\versions\version-d599f7fc52a8404c\robloxplayerbeta.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1188"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateComRegisterShell64.exe" /user C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Update COM Registration Helper
Exit code:
0
Version:
1.3.195.45
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\1.3.195.45\microsoftedgeupdatecomregistershell64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
1200"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --field-trial-handle=6064,i,589712867757411462,6256058325153396176,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=5384 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\133.0.6943.127\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1212C:\WINDOWS\system32\WerFault.exe -u -p 1172 -s 388C:\Windows\System32\WerFault.exeRobloxPlayerBeta.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
1232"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.ProcessorMetrics --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --field-trial-handle=5356,i,589712867757411462,6256058325153396176,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=5372 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1400"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --field-trial-handle=5872,i,589712867757411462,6256058325153396176,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=5760 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1424"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --field-trial-handle=4872,i,589712867757411462,6256058325153396176,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=5796 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1840"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --extension-process --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=56 --field-trial-handle=7768,i,589712867757411462,6256058325153396176,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=7688 /prefetch:2C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\133.0.6943.127\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1944"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=quarantine.mojom.Quarantine --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --field-trial-handle=5752,i,589712867757411462,6256058325153396176,262144 --disable-features=HttpsFirstBalancedMode,HttpsFirstModeV2,HttpsOnlyMode,HttpsUpgrades --variations-seed-version=20251218-201203.402000 --mojo-platform-channel-handle=5032 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
13 614
Read events
11 798
Write events
1 750
Delete events
66

Modification events

(PID) Process:(8468) RobloxPlayerInstaller-G32TBW7TJY.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\ProtocolExecute\roblox-studio
Operation:writeName:WarnOnOpen
Value:
0
(PID) Process:(8468) RobloxPlayerInstaller-G32TBW7TJY.exeKey:HKEY_CLASSES_ROOT\roblox-studio
Operation:writeName:URL Protocol
Value:
(PID) Process:(8468) RobloxPlayerInstaller-G32TBW7TJY.exeKey:HKEY_CLASSES_ROOT\roblox-studio\shell\open\command
Operation:writeName:version
Value:
version-19073b5104cb45df
(PID) Process:(2332) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate
Operation:delete valueName:eulaaccepted
Value:
(PID) Process:(2332) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\Clients\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:name
Value:
Microsoft Edge Update
(PID) Process:(2332) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\ClientState\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}
Operation:writeName:pv
Value:
1.3.195.45
(PID) Process:(2332) MicrosoftEdgeUpdate.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Microsoft Edge Update
Value:
"C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\1.3.195.45\MicrosoftEdgeUpdateCore.exe"
(PID) Process:(8148) MicrosoftEdgeUpdateComRegisterShell64.exeKey:HKEY_CLASSES_ROOT\CLSID\{F46A78BD-06FC-442C-88DF-0500F08F2379}\InProcServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(3716) MicrosoftEdgeUpdate.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{81093D63-7825-417B-BFC8-ADC63FA4E53D}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(3716) MicrosoftEdgeUpdate.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{5EA43877-C6D8-4885-B77A-C0BB27E94372}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Both
Executable files
210
Suspicious files
668
Text files
727
Unknown types
0

Dropped files

PID
Process
Filename
Type
7376chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old~RF1e5551.TMP
MD5:
SHA256:
7376chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ClientCertificates\LOG.old~RF1e5551.TMP
MD5:
SHA256:
7376chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
7376chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
7376chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\LOG.old~RF1e5561.TMP
MD5:
SHA256:
7376chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\LOG.old
MD5:
SHA256:
7376chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old~RF1e5561.TMP
MD5:
SHA256:
7376chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RF1e5561.TMP
MD5:
SHA256:
7376chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\LOG.old~RF1e5561.TMP
MD5:
SHA256:
7376chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
943
TCP/UDP connections
270
DNS requests
311
Threats
20

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
8132
chrome.exe
GET
308
128.116.44.3:443
https://roblox.com/
US
unknown
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
US
binary
313 b
whitelisted
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D
US
binary
958 b
whitelisted
8132
chrome.exe
GET
200
142.251.37.14:80
http://clients2.google.com/time/1/current?cup2key=8:a6ATg9cGbzVbpNUURtXkCR4lDT9BwDnIZSIeykHEfsI&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
106 b
whitelisted
8132
chrome.exe
GET
307
128.116.44.3:80
http://roblox.com/
US
unknown
8132
chrome.exe
GET
200
142.250.186.67:443
https://clientservices.googleapis.com/chrome-variations/seed?osname=win&channel=stable&milestone=133
US
compressed
87.0 Kb
whitelisted
8132
chrome.exe
POST
200
142.251.127.84:443
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
US
text
17 b
whitelisted
8132
chrome.exe
GET
200
172.217.16.202:443
https://safebrowsingohttpgateway.googleapis.com/v1/ohttp/hpkekeyconfig?key=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE
US
binary
41 b
whitelisted
8132
chrome.exe
GET
200
128.116.48.3:443
https://www.roblox.com/
US
text
58.3 Kb
unknown
8132
chrome.exe
GET
200
3.165.206.25:443
https://css.rbxcdn.com/56f6868ec13cefb471ad86176c7b9642571d05082c86ac6300ddfeb028617d4e.css
US
text
119 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
8124
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8860
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5568
SearchApp.exe
2.16.241.205:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
172.66.2.5:80
ocsp.digicert.com
CLOUDFLARENET
US
whitelisted
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
8132
chrome.exe
142.251.37.14:80
clients2.google.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
self.events.data.microsoft.com
  • 104.208.16.91
  • 104.208.16.90
whitelisted
www.bing.com
  • 2.16.241.205
  • 2.16.241.203
  • 2.16.241.216
  • 2.16.241.219
  • 2.16.241.200
  • 2.16.241.206
  • 2.16.241.223
  • 2.16.241.222
  • 2.16.241.218
whitelisted
ocsp.digicert.com
  • 172.66.2.5
  • 162.159.142.9
  • 184.30.131.245
whitelisted
google.com
  • 142.250.201.78
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
clients2.google.com
  • 142.251.37.14
whitelisted
roblox.com
  • 128.116.44.3
whitelisted
safebrowsingohttpgateway.googleapis.com
  • 172.217.16.202
  • 172.217.20.138
  • 142.251.37.10
  • 142.251.141.138
  • 142.251.141.74
  • 142.251.140.170
  • 142.251.143.106
  • 142.251.141.106
  • 216.58.206.42
  • 172.217.16.170
  • 142.251.36.106
  • 142.251.127.95
  • 142.250.201.74
  • 142.251.208.10
whitelisted

Threats

PID
Process
Class
Message
8124
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
8132
chrome.exe
Generic Protocol Command Decode
SURICATA HTTP unable to match response to request
8132
chrome.exe
Misc activity
SUSPICIOUS [ANY.RUN] JavaScript Obfuscation (ParseInt)
8132
chrome.exe
Misc activity
SUSPICIOUS [ANY.RUN] JavaScript Obfuscation (ParseInt)
8132
chrome.exe
Misc activity
SUSPICIOUS [ANY.RUN] JavaScript Obfuscation (ParseInt)
8132
chrome.exe
Misc activity
SUSPICIOUS [ANY.RUN] JavaScript Obfuscation (ParseInt)
3304
svchost.exe
Misc activity
ET INFO Packed Executable Download
8132
chrome.exe
Misc activity
SUSPICIOUS [ANY.RUN] JavaScript Obfuscation (ParseInt)
8132
chrome.exe
Misc activity
SUSPICIOUS [ANY.RUN] JavaScript Obfuscation (ParseInt)
8132
chrome.exe
Misc activity
SUSPICIOUS [ANY.RUN] JavaScript Obfuscation (ParseInt)
Process
Message
RobloxPlayerInstaller-G32TBW7TJY.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.