File name:

jjsploit_8.17.7_x64_en-US.msi

Full analysis: https://app.any.run/tasks/9e46f88b-c8a6-4139-98e9-65665d5ce652
Verdict: Malicious activity
Analysis date: February 16, 2026, 21:54:49
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
generated-doc
github
roblox
Indicators:
MIME: application/x-msi
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: jjsploit, Author: wearedevs, Keywords: Installer, Comments: This installer database contains the logic and data required to install jjsploit., Template: x64;0, Revision Number: {8394103A-0A4A-4372-BC41-8CCBED0B1E7D}, Create Time/Date: Tue Feb 10 15:22:10 2026, Last Saved Time/Date: Tue Feb 10 15:22:10 2026, Number of Pages: 450, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.14.1.8722), Security: 2
MD5:

E04EE1D026F44051B3D3A464A2D29ADE

SHA1:

4695189629E708C1951319B1ADCDAD3E06939F04

SHA256:

C47F34E3B353518F5A81800B2E1EBBC0E0A14AFBC843D760C5D187F3D8262E93

SSDEEP:

98304:nWXBSo/hT/x2GB19dkM1j5IlUATheB6vneck2V9WOHtfuMIE9tqQJ7H3qrQFFduh:aUXtq2O4HIeSp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Run PowerShell with an invisible window

      • powershell.exe (PID: 8088)
    • Changes the autorun value in the registry

      • MicrosoftEdgeUpdate.exe (PID: 5660)
    • Potential DLL hijacking behavior detected

      • msedgewebview2.exe (PID: 8408)
      • msedgewebview2.exe (PID: 4684)
    • Scans artifacts that could help determine the target

      • msedgewebview2.exe (PID: 8756)
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 4624)
    • Manipulates environment variables

      • powershell.exe (PID: 8088)
    • The process bypasses the loading of PowerShell profile settings

      • msiexec.exe (PID: 9092)
    • Starts POWERSHELL.EXE for commands execution

      • msiexec.exe (PID: 9092)
    • Starts process via Powershell

      • powershell.exe (PID: 8088)
    • Downloads file from URI via Powershell

      • powershell.exe (PID: 8088)
    • Gets or sets the security protocol (POWERSHELL)

      • powershell.exe (PID: 8088)
    • Process drops legitimate windows executable

      • powershell.exe (PID: 8088)
      • MicrosoftEdgeUpdate.exe (PID: 5660)
      • MicrosoftEdge_X64_145.0.3800.58.exe (PID: 4856)
      • setup.exe (PID: 8456)
      • MicrosoftEdgeWebview2Setup.exe (PID: 4340)
      • RobloxPlayerInstaller.exe (PID: 7324)
      • msedgewebview2.exe (PID: 2016)
      • msedgewebview2.exe (PID: 7340)
      • RobloxStudioInstaller.exe (PID: 7812)
    • Executable content was dropped or overwritten

      • powershell.exe (PID: 8088)
      • MicrosoftEdgeWebview2Setup.exe (PID: 4340)
      • MicrosoftEdgeUpdate.exe (PID: 5660)
      • MicrosoftEdge_X64_145.0.3800.58.exe (PID: 4856)
      • setup.exe (PID: 8456)
      • jjsploit.exe (PID: 6948)
      • RobloxPlayerInstaller.exe (PID: 7324)
      • msedgewebview2.exe (PID: 2016)
      • msedgewebview2.exe (PID: 7340)
      • RobloxStudioInstaller.exe (PID: 8576)
      • RobloxStudioInstaller.exe (PID: 7812)
    • Starts a Microsoft application from unusual location

      • MicrosoftEdgeWebview2Setup.exe (PID: 4340)
      • MicrosoftEdgeUpdate.exe (PID: 5660)
    • Starts itself from another location

      • MicrosoftEdgeUpdate.exe (PID: 5660)
      • RobloxStudioInstaller.exe (PID: 8576)
    • Creates/Modifies COM task schedule object

      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6496)
      • MicrosoftEdgeUpdate.exe (PID: 4352)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 8492)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5796)
    • Application launched itself

      • setup.exe (PID: 8456)
      • MicrosoftEdgeUpdate.exe (PID: 7740)
      • msedgewebview2.exe (PID: 3208)
      • msedgewebview2.exe (PID: 8756)
    • Searches for installed software

      • setup.exe (PID: 8456)
      • msedgewebview2.exe (PID: 3208)
    • Changes default file association

      • RobloxPlayerInstaller.exe (PID: 7324)
      • RobloxStudioInstaller.exe (PID: 7812)
    • Executes application which crashes

      • RobloxPlayerBeta.exe (PID: 7944)
      • RobloxPlayerBeta.exe (PID: 8272)
      • RobloxStudioInstaller.exe (PID: 8576)
    • The process drops C-runtime libraries

      • RobloxStudioInstaller.exe (PID: 7812)
  • INFO

    • Checks supported languages

      • msiexec.exe (PID: 9092)
      • msiexec.exe (PID: 2456)
      • MicrosoftEdgeUpdate.exe (PID: 5660)
      • MicrosoftEdgeUpdate.exe (PID: 4352)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6496)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 8492)
      • MicrosoftEdgeUpdate.exe (PID: 6376)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5796)
      • MicrosoftEdgeUpdate.exe (PID: 8068)
      • MicrosoftEdgeUpdate.exe (PID: 7740)
      • MicrosoftEdge_X64_145.0.3800.58.exe (PID: 4856)
      • setup.exe (PID: 8456)
      • setup.exe (PID: 2368)
      • MicrosoftEdgeUpdate.exe (PID: 5804)
      • MicrosoftEdgeUpdate.exe (PID: 4220)
      • MicrosoftEdgeUpdateCore.exe (PID: 8168)
      • jjsploit.exe (PID: 6948)
      • msedgewebview2.exe (PID: 9136)
      • msedgewebview2.exe (PID: 3208)
      • MicrosoftEdgeWebview2Setup.exe (PID: 4340)
      • msedgewebview2.exe (PID: 8408)
      • msedgewebview2.exe (PID: 3096)
      • msedgewebview2.exe (PID: 1820)
      • msedgewebview2.exe (PID: 7928)
      • msedgewebview2.exe (PID: 8720)
      • msedgewebview2.exe (PID: 7868)
      • RobloxPlayerInstaller.exe (PID: 7324)
      • msedgewebview2.exe (PID: 6540)
      • msedgewebview2.exe (PID: 3132)
      • msedgewebview2.exe (PID: 3624)
      • msedgewebview2.exe (PID: 2016)
      • RobloxPlayerBeta.exe (PID: 7944)
      • RobloxPlayerBeta.exe (PID: 8272)
      • RobloxStudioInstaller.exe (PID: 8576)
      • msedgewebview2.exe (PID: 7340)
      • RobloxStudioInstaller.exe (PID: 7812)
      • msedgewebview2.exe (PID: 1128)
      • RobloxStudioBeta.exe (PID: 8016)
      • RobloxCrashHandler.exe (PID: 8360)
      • GameBar.exe (PID: 6552)
      • msedgewebview2.exe (PID: 1784)
      • msedgewebview2.exe (PID: 8756)
      • msedgewebview2.exe (PID: 5888)
      • msedgewebview2.exe (PID: 7924)
      • msedgewebview2.exe (PID: 9244)
      • msedgewebview2.exe (PID: 4684)
      • msedgewebview2.exe (PID: 9444)
      • msedgewebview2.exe (PID: 9536)
      • msedgewebview2.exe (PID: 9720)
    • An automatically generated document

      • msiexec.exe (PID: 8304)
    • Reads the computer name

      • msiexec.exe (PID: 9092)
      • msiexec.exe (PID: 2456)
      • MicrosoftEdgeUpdate.exe (PID: 5660)
      • MicrosoftEdgeUpdate.exe (PID: 4352)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 8492)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 6496)
      • MicrosoftEdgeUpdateComRegisterShell64.exe (PID: 5796)
      • MicrosoftEdgeUpdate.exe (PID: 6376)
      • MicrosoftEdgeUpdate.exe (PID: 8068)
      • MicrosoftEdgeUpdate.exe (PID: 7740)
      • setup.exe (PID: 8456)
      • MicrosoftEdge_X64_145.0.3800.58.exe (PID: 4856)
      • MicrosoftEdgeUpdateCore.exe (PID: 8168)
      • MicrosoftEdgeUpdate.exe (PID: 5804)
      • MicrosoftEdgeUpdate.exe (PID: 4220)
      • jjsploit.exe (PID: 6948)
      • msedgewebview2.exe (PID: 3208)
      • msedgewebview2.exe (PID: 8408)
      • RobloxPlayerInstaller.exe (PID: 7324)
      • msedgewebview2.exe (PID: 3624)
      • RobloxStudioInstaller.exe (PID: 8576)
      • RobloxStudioInstaller.exe (PID: 7812)
      • msedgewebview2.exe (PID: 1820)
      • RobloxStudioBeta.exe (PID: 8016)
      • msedgewebview2.exe (PID: 8756)
      • GameBar.exe (PID: 6552)
      • msedgewebview2.exe (PID: 7924)
      • msedgewebview2.exe (PID: 4684)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 8304)
      • msiexec.exe (PID: 9092)
      • firefox.exe (PID: 488)
    • Manages system restore points

      • SrTasks.exe (PID: 3404)
    • Drops script file

      • powershell.exe (PID: 8088)
      • setup.exe (PID: 8456)
      • firefox.exe (PID: 488)
      • RobloxPlayerInstaller.exe (PID: 7324)
      • RobloxStudioInstaller.exe (PID: 7812)
    • Disables trace logs

      • powershell.exe (PID: 8088)
    • Checks proxy server information

      • powershell.exe (PID: 8088)
      • MicrosoftEdgeUpdate.exe (PID: 6376)
      • MicrosoftEdgeUpdate.exe (PID: 7740)
      • MicrosoftEdgeUpdate.exe (PID: 4220)
      • jjsploit.exe (PID: 6948)
      • msedgewebview2.exe (PID: 3208)
      • slui.exe (PID: 3700)
      • WerFault.exe (PID: 2248)
      • msedgewebview2.exe (PID: 8756)
    • The sample compiled with english language support

      • powershell.exe (PID: 8088)
      • MicrosoftEdgeWebview2Setup.exe (PID: 4340)
      • MicrosoftEdgeUpdate.exe (PID: 5660)
      • MicrosoftEdge_X64_145.0.3800.58.exe (PID: 4856)
      • setup.exe (PID: 8456)
      • jjsploit.exe (PID: 6948)
      • firefox.exe (PID: 488)
      • RobloxPlayerInstaller.exe (PID: 7324)
      • msedgewebview2.exe (PID: 2016)
      • RobloxStudioInstaller.exe (PID: 8576)
      • RobloxStudioInstaller.exe (PID: 7812)
    • The executable file from the user directory is run by the Powershell process

      • MicrosoftEdgeWebview2Setup.exe (PID: 4340)
    • Create files in a temporary directory

      • MicrosoftEdgeWebview2Setup.exe (PID: 4340)
      • RobloxPlayerInstaller.exe (PID: 7324)
      • RobloxStudioInstaller.exe (PID: 8576)
      • RobloxStudioInstaller.exe (PID: 7812)
      • msedgewebview2.exe (PID: 3208)
      • RobloxStudioBeta.exe (PID: 8016)
      • msedgewebview2.exe (PID: 8756)
    • Creates files or folders in the user directory

      • MicrosoftEdgeUpdate.exe (PID: 5660)
      • MicrosoftEdge_X64_145.0.3800.58.exe (PID: 4856)
      • MicrosoftEdgeUpdate.exe (PID: 7740)
      • setup.exe (PID: 2368)
      • setup.exe (PID: 8456)
      • msedgewebview2.exe (PID: 9136)
      • msedgewebview2.exe (PID: 3208)
      • jjsploit.exe (PID: 6948)
      • msedgewebview2.exe (PID: 1820)
      • RobloxPlayerInstaller.exe (PID: 7324)
      • msedgewebview2.exe (PID: 3624)
      • RobloxStudioInstaller.exe (PID: 8576)
      • RobloxStudioInstaller.exe (PID: 7812)
      • WerFault.exe (PID: 2248)
      • RobloxStudioBeta.exe (PID: 8016)
      • RobloxCrashHandler.exe (PID: 8360)
      • msedgewebview2.exe (PID: 8756)
      • msedgewebview2.exe (PID: 1784)
      • msedgewebview2.exe (PID: 7924)
    • Launching a file from a Registry key

      • MicrosoftEdgeUpdate.exe (PID: 5660)
    • Reads Environment values

      • MicrosoftEdgeUpdate.exe (PID: 6376)
      • MicrosoftEdgeUpdate.exe (PID: 4220)
      • msedgewebview2.exe (PID: 3208)
      • msedgewebview2.exe (PID: 8756)
    • Process checks computer location settings

      • MicrosoftEdgeUpdate.exe (PID: 5660)
      • setup.exe (PID: 8456)
      • msedgewebview2.exe (PID: 3208)
      • msedgewebview2.exe (PID: 3096)
      • msedgewebview2.exe (PID: 8756)
      • msedgewebview2.exe (PID: 9244)
      • msedgewebview2.exe (PID: 9444)
      • msedgewebview2.exe (PID: 9536)
      • msedgewebview2.exe (PID: 9720)
    • Reads security settings of Internet Explorer

      • MicrosoftEdgeUpdate.exe (PID: 5660)
      • MicrosoftEdgeUpdate.exe (PID: 7740)
      • msedgewebview2.exe (PID: 3208)
      • GameBar.exe (PID: 6552)
      • msedgewebview2.exe (PID: 8756)
    • Reads the machine GUID from the registry

      • MicrosoftEdgeUpdate.exe (PID: 7740)
      • jjsploit.exe (PID: 6948)
      • RobloxPlayerInstaller.exe (PID: 7324)
      • msedgewebview2.exe (PID: 3624)
      • RobloxStudioInstaller.exe (PID: 8576)
      • RobloxStudioInstaller.exe (PID: 7812)
      • msedgewebview2.exe (PID: 3208)
      • RobloxStudioBeta.exe (PID: 8016)
      • RobloxCrashHandler.exe (PID: 8360)
      • msedgewebview2.exe (PID: 8756)
    • Manual execution by a user

      • MicrosoftEdgeUpdateCore.exe (PID: 8168)
      • firefox.exe (PID: 2680)
      • RobloxPlayerBeta.exe (PID: 8272)
      • RobloxStudioInstaller.exe (PID: 8576)
    • Creates a software uninstall entry

      • setup.exe (PID: 8456)
      • RobloxPlayerInstaller.exe (PID: 7324)
      • RobloxStudioInstaller.exe (PID: 7812)
    • Application launched itself

      • firefox.exe (PID: 2680)
      • firefox.exe (PID: 488)
    • ROBLOX mutex has been found

      • RobloxPlayerInstaller.exe (PID: 7324)
      • RobloxStudioInstaller.exe (PID: 8576)
      • RobloxStudioInstaller.exe (PID: 7812)
    • Process checks whether UAC notifications are on

      • RobloxPlayerInstaller.exe (PID: 7324)
      • RobloxStudioInstaller.exe (PID: 7812)
      • RobloxStudioBeta.exe (PID: 8016)
    • Launching a file from the Downloads directory

      • firefox.exe (PID: 488)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msi | Microsoft Windows Installer (98.5)
.msi | Microsoft Installer (100)

EXIF

FlashPix

CodePage: Windows Latin 1 (Western European)
Title: Installation Database
Subject: jjsploit
Author: wearedevs
Keywords: Installer
Comments: This installer database contains the logic and data required to install jjsploit.
Template: x64;0
RevisionNumber: {8394103A-0A4A-4372-BC41-8CCBED0B1E7D}
CreateDate: 2026:02:10 15:22:10
ModifyDate: 2026:02:10 15:22:10
Pages: 450
Words: 2
Software: Windows Installer XML Toolset (3.14.1.8722)
Security: Read-only recommended
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
242
Monitored processes
73
Malicious processes
7
Suspicious processes
6

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
272"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 5048 -prefsLen 39330 -prefMapHandle 5116 -prefMapSize 272981 -jsInitHandle 5124 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 5140 -initialChannelId {e2b0893b-5449-47ce-89ad-fdf439e29fad} -parentPid 488 -crashReporter "\\.\pipe\gecko-crash-server-pipe.488" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 7 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
488"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1128"C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\145.0.3800.58\msedgewebview2.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\net.wearedevs\EBWebView" --webview-exe-name=jjsploit.exe --webview-exe-version=8.17.7 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --ram-no-pressure-read-main-dll --metrics-shmem-handle=3472,i,13019262988113031276,15976753469970687063,524288 --field-trial-handle=1876,i,10790782215483225475,9964604844887086708,262144 --disable-features=msPdfOOUI,msSmartScreenProtection,msWebOOUI --variations-seed-version --trace-process-track-uuid=3190708998493415531 --mojo-platform-channel-handle=3480 /prefetch:8C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\145.0.3800.58\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge WebView2
Exit code:
0
Version:
145.0.3800.58
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\145.0.3800.58\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\145.0.3800.58\msedge_elf.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
1784C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\145.0.3800.58\msedgewebview2.exe --type=crashpad-handler --user-data-dir=C:\Users\admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Crashpad --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=145.0.7632.76 --annotation=exe=C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\145.0.3800.58\msedgewebview2.exe --annotation=plat=Win64 "--annotation=prod=Edge WebView2" --annotation=ver=145.0.3800.58 --initial-client-data=0x1a0,0x1a4,0x1a8,0x17c,0x1b0,0x7ffd6fc40f18,0x7ffd6fc40f24,0x7ffd6fc40f30C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\145.0.3800.58\msedgewebview2.exemsedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge WebView2
Exit code:
0
Version:
145.0.3800.58
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\145.0.3800.58\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\145.0.3800.58\msedge_elf.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcryptprimitives.dll
1820"C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\145.0.3800.58\msedgewebview2.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\net.wearedevs\EBWebView" --webview-exe-name=jjsploit.exe --webview-exe-version=8.17.7 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --startup-read-main-dll --metrics-shmem-handle=2144,i,2434505795041243037,10856201940782328440,524288 --field-trial-handle=1876,i,10790782215483225475,9964604844887086708,262144 --disable-features=msPdfOOUI,msSmartScreenProtection,msWebOOUI --variations-seed-version --trace-process-track-uuid=3190708989122997041 --mojo-platform-channel-handle=2160 /prefetch:3C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\145.0.3800.58\msedgewebview2.exe
msedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge WebView2
Version:
145.0.3800.58
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\145.0.3800.58\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\145.0.3800.58\msedge_elf.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
2016"C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\145.0.3800.58\msedgewebview2.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\admin\AppData\Local\net.wearedevs\EBWebView" --webview-exe-name=jjsploit.exe --webview-exe-version=8.17.7 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --skip-read-main-dll --metrics-shmem-handle=5072,i,148759760614596308,7219687565393973352,524288 --field-trial-handle=1876,i,10790782215483225475,9964604844887086708,262144 --disable-features=msPdfOOUI,msSmartScreenProtection,msWebOOUI --variations-seed-version --trace-process-track-uuid=3190708996619331833 --mojo-platform-channel-handle=3472 /prefetch:8C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\Application\145.0.3800.58\msedgewebview2.exe
msedgewebview2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge WebView2
Exit code:
0
Version:
145.0.3800.58
Modules
Images
c:\users\admin\appdata\local\microsoft\edgewebview\application\145.0.3800.58\msedgewebview2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\microsoft\edgewebview\application\145.0.3800.58\msedge_elf.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\shcore.dll
2248C:\WINDOWS\SysWOW64\WerFault.exe -u -p 8576 -s 968C:\Windows\SysWOW64\WerFault.exe
RobloxStudioInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
2368C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{61C3FC85-477B-420E-AF85-CF0F26DADBEA}\EDGEMITMP_A408F.tmp\setup.exe --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\EdgeWebView\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=145.0.7632.76 --annotation=exe=C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{61C3FC85-477B-420E-AF85-CF0F26DADBEA}\EDGEMITMP_A408F.tmp\setup.exe --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=145.0.3800.58 --initial-client-data=0x240,0x244,0x248,0x23c,0x24c,0x7ff68ebdcc68,0x7ff68ebdcc74,0x7ff68ebdcc80C:\Users\admin\AppData\Local\Microsoft\EdgeUpdate\Install\{61C3FC85-477B-420E-AF85-CF0F26DADBEA}\EDGEMITMP_A408F.tmp\setup.exesetup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge Installer
Exit code:
0
Version:
145.0.3800.58
Modules
Images
c:\users\admin\appdata\local\microsoft\edgeupdate\install\{61c3fc85-477b-420e-af85-cf0f26dadbea}\edgemitmp_a408f.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2376"C:\Windows\System32\GameBarPresenceWriter.exe" -ServerName:Windows.Gaming.GameBar.Internal.PresenceWriterServerC:\Windows\System32\GameBarPresenceWriter.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Gamebar Presence Writer
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\gamebarpresencewriter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
2432"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc -isForBrowser -prefsHandle 6020 -prefsLen 39650 -prefMapHandle 6024 -prefMapSize 272981 -jsInitHandle 6028 -jsInitLen 247456 -parentBuildID 20250227124745 -ipcHandle 6036 -initialChannelId {662e1fb2-f31d-48b5-a2d8-7fc59fb6c873} -parentPid 488 -crashReporter "\\.\pipe\gecko-crash-server-pipe.488" -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - 11 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
136.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\crypt32.dll
Total events
34 699
Read events
32 959
Write events
1 646
Delete events
94

Modification events

(PID) Process:(9092) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4800000000000000E38E92E98E9FDC0184230000341D0000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(9092) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
480000000000000036F194E98E9FDC0184230000341D0000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(9092) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
4800000000000000F850D5E98E9FDC0184230000341D0000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(9092) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
15
(PID) Process:(9092) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
48000000000000008563E8E98E9FDC0184230000341D0000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4624) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:delete keyName:(default)
Value:
(PID) Process:(4624) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\COM+ REGDB Writer
Operation:writeName:IDENTIFY (Leave)
Value:
4800000000000000E013F9E98E9FDC0110120000D4080000E80300000000000001000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4624) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:writeName:Element
Value:
0000000000000000000000000000000006000000000000004800000000000000715E5C2FA985EB1190A89A9B763584210000000000000000745E5C2FA985EB1190A89A9B7635842100000000000000000000000000000000
(PID) Process:(4624) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\12000002
Operation:delete keyName:(default)
Value:
(PID) Process:(4624) VSSVC.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\12000002
Operation:writeName:Element
Value:
\EFI\Microsoft\Boot\bootmgfw.efi
Executable files
225
Suspicious files
626
Text files
286
Unknown types
118

Dropped files

PID
Process
Filename
Type
9092msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
9092msiexec.exeC:\Windows\Installer\1e922c.msi
MD5:
SHA256:
9092msiexec.exeC:\Windows\Installer\MSI94CB.tmpbinary
MD5:099584951640586F1D92022E5BCABE52
SHA256:45B948401CE07DDC5584102A20406A87A218DA14E4C8B8154F64BB043B8954C3
9092msiexec.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:37CE36C93F1B771CCC00A97CA0DD0BA7
SHA256:A58A8C84329E0FDCE081D7D8BD92D3DD21C7EE0EA94283C98CA005699FC61B1C
8304msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI63C9.tmpexecutable
MD5:CFBB8568BD3711A97E6124C56FCFA8D9
SHA256:7F47D98AB25CFEA9B3A2E898C3376CC9BA1CD893B4948B0C27CAA530FD0E34CC
9092msiexec.exeC:\Program Files\jjsploit\jjsploit.exeexecutable
MD5:7650D2744BA2C4E1B0C1F00CCB571D7C
SHA256:1D0917B788584E0B5F3687632260D0605D3CBD075949D77C810DF907CF13DF53
9092msiexec.exeC:\Program Files\jjsploit\resources\luascripts\general\tptool.luatext
MD5:78990037F24311727092F08334ACE6E0
SHA256:17BDAD5A7E4910982519F219B1E40525F4F5B2E4C55224E491A13CE4D98CA60C
9092msiexec.exeC:\Program Files\jjsploit\resources\luascripts\beesim\autodig.luatext
MD5:A99F423612E047906C288D32DED6F773
SHA256:AFD46C7CD01F271454C96D9BC71ECD4778D508C23D5C66103A85B8BA180DBC8A
9092msiexec.exeC:\Program Files\jjsploit\resources\luascripts\general\infinitejump.luatext
MD5:F13B9AD3F7D7EB0827D189699D50490C
SHA256:E81510EB4EE69A72D9087DEFD412453C0C63D2772CAC3749757B842FB126E435
9092msiexec.exeC:\Program Files\jjsploit\resources\luascripts\jailbreak\criminalesp.luatext
MD5:ECA04338C0A816002856B788FAAC0A47
SHA256:354CBF71EA3D2581FC192C896EFAB1C5555DCECFDCA6982A84F319E7C7B252DA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
438
TCP/UDP connections
204
DNS requests
241
Threats
15

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6768
MoUsoCoreWorker.exe
GET
304
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
7428
svchost.exe
GET
304
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
whitelisted
8088
powershell.exe
GET
301
88.221.169.205:443
https://go.microsoft.com/fwlink/p/?LinkId=2124703
US
whitelisted
356
svchost.exe
POST
200
40.126.31.71:443
https://login.live.com/RST2.srf
US
xml
11.1 Kb
whitelisted
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
US
binary
312 b
whitelisted
356
svchost.exe
POST
200
40.126.31.71:443
https://login.live.com/RST2.srf
US
xml
10.3 Kb
whitelisted
356
svchost.exe
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
8228
svchost.exe
POST
403
88.221.169.205:443
https://go.microsoft.com/fwlink/?LinkID=2257403&clcid=0x409
US
html
386 b
whitelisted
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D
US
binary
960 b
whitelisted
7428
svchost.exe
GET
200
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/WaaSAssessment?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&ring=Retail&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=10.0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=WaaSAssessment&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&ServicingBranch=CB&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&HonorWUfBDeferrals=0&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
text
5.67 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
7428
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5568
SearchApp.exe
2.16.204.143:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
23.63.118.230:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3412
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
356
svchost.exe
40.126.31.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
whitelisted
google.com
  • 172.217.16.206
whitelisted
www.bing.com
  • 2.16.204.143
  • 2.16.204.158
  • 2.16.204.153
  • 2.16.204.141
  • 2.16.204.156
  • 2.16.204.146
  • 2.16.204.145
  • 2.16.204.138
  • 2.16.204.134
whitelisted
ocsp.digicert.com
  • 23.63.118.230
  • 184.30.131.245
whitelisted
self.events.data.microsoft.com
  • 52.168.117.175
  • 20.42.65.94
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
client.wns.windows.com
  • 172.211.123.250
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.31.71
  • 20.190.159.130
  • 20.190.159.73
  • 40.126.31.67
  • 40.126.31.69
  • 20.190.159.75
  • 20.190.159.0
  • 20.190.159.71
whitelisted
crl.microsoft.com
  • 23.48.23.29
  • 23.48.23.57
  • 2.16.164.72
  • 2.16.164.120
  • 23.48.23.38
  • 23.48.23.30
  • 23.48.23.32
  • 23.48.23.35
  • 23.48.23.24
  • 23.48.23.10
whitelisted
go.microsoft.com
  • 88.221.169.205
whitelisted

Threats

PID
Process
Class
Message
7428
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
8088
powershell.exe
Not Suspicious Traffic
ET INFO Windows Powershell User-Agent Usage
8088
powershell.exe
Not Suspicious Traffic
ET INFO Windows Powershell User-Agent Usage
8088
powershell.exe
Misc activity
ET INFO Request for EXE via Powershell
8088
powershell.exe
Misc activity
ET INFO Packed Executable Download
5164
svchost.exe
Misc activity
ET INFO Packed Executable Download
1820
msedgewebview2.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
1820
msedgewebview2.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
2292
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
488
firefox.exe
Potentially Bad Traffic
ET INFO PE EXE or DLL Windows file download HTTP
Process
Message
msedgewebview2.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local\net.wearedevs directory exists )
RobloxStudioBeta.exe
2026-02-16T21:59:38.172Z,0.172147,22e4,6 [FLog::Output] Command line: C:\Users\admin\AppData\Local\Roblox\Versions\version-6df69e4610344376\RobloxStudioBeta.exe -startEvent www.roblox.com/robloxQTStudioStartedEvent -firstLaunch
RobloxStudioBeta.exe
RobloxStudioBeta.exe
RobloxStudioBeta.exe
RobloxStudioBeta.exe
2026-02-16T21:59:38.171Z,0.171147,22e4,6 [FLog::Output] RobloxGitHash: 676d7e3fb13953ac5bb8dd743870ae758bb1f92f
RobloxStudioBeta.exe
2026-02-16T21:59:38.172Z,0.172147,22e4,6 [FLog::Output] Creating PolicyContext(Root)
RobloxStudioBeta.exe
2026-02-16T21:59:38.173Z,0.173147,22e4,6 [FLog::Output] BaseUrl: https://www.roblox.com
RobloxStudioBeta.exe
2026-02-16T21:59:38.173Z,0.173147,22e4,6,Debug [FLog::BackendConfigCacheManager] Header version / timestamp is empty
RobloxStudioBeta.exe