File name:

Roblox Account Manager (1).exe

Full analysis: https://app.any.run/tasks/30cf4037-a280-48e8-96a6-9ea3c26d3390
Verdict: Malicious activity
Analysis date: January 05, 2026, 09:38:39
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
github
arch-exec
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

A057FAE0C8C97EE6CF2C12FB7BCF034D

SHA1:

64FE0EB242B5C3F9C42F4F2C1685E4A36708E4F6

SHA256:

CDB0A360CCA7A5099C2D2357BE1A833E032FFDEB3F467A6FAC845F6BB77031C9

SSDEEP:

98304:b2bT1Qm7d9GP4i7q0LTWgtUmWzmSyZs9S8Z/LywnrSkqXf0Fb7WnhNMYkj7z:4Qm59q/tUhzmS9zZ/mY+kSIb7ahNMYkX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Application launched itself

      • Roblox Account Manager (1).exe (PID: 7544)
      • Auto Update.exe (PID: 8092)
      • chrome.exe (PID: 7664)
      • Roblox Account Manager.exe (PID: 7284)
    • Reads security settings of Internet Explorer

      • Roblox Account Manager (1).exe (PID: 7544)
      • Roblox Account Manager (1).exe (PID: 7632)
      • Auto Update.exe (PID: 8092)
      • Roblox Account Manager.exe (PID: 6904)
      • Roblox Account Manager.exe (PID: 7284)
    • Executable content was dropped or overwritten

      • Roblox Account Manager (1).exe (PID: 7632)
      • Auto Update.exe (PID: 7412)
      • Roblox Account Manager.exe (PID: 6904)
    • Starts itself from another location

      • Roblox Account Manager (1).exe (PID: 7632)
    • Process drops legitimate windows executable

      • Roblox Account Manager.exe (PID: 6904)
    • The process creates files with name similar to system file names

      • Roblox Account Manager.exe (PID: 6904)
    • Browser web security disabling

      • chrome.exe (PID: 7664)
  • INFO

    • Reads the computer name

      • Roblox Account Manager (1).exe (PID: 7544)
      • Roblox Account Manager (1).exe (PID: 7632)
      • Auto Update.exe (PID: 8092)
      • Roblox Account Manager.exe (PID: 7284)
      • Auto Update.exe (PID: 7412)
      • chrome.exe (PID: 7664)
      • Roblox Account Manager.exe (PID: 6904)
      • chrome.exe (PID: 4700)
      • chrome.exe (PID: 8164)
      • TextInputHost.exe (PID: 1600)
      • chrome.exe (PID: 7228)
    • Checks supported languages

      • Roblox Account Manager (1).exe (PID: 7544)
      • Roblox Account Manager (1).exe (PID: 7632)
      • Auto Update.exe (PID: 8092)
      • Auto Update.exe (PID: 7412)
      • Roblox Account Manager.exe (PID: 7284)
      • Roblox Account Manager.exe (PID: 6904)
      • chrome.exe (PID: 7664)
      • chrome.exe (PID: 7740)
      • chrome.exe (PID: 8164)
      • chrome.exe (PID: 4700)
      • chrome.exe (PID: 7444)
      • chrome.exe (PID: 4828)
      • chrome.exe (PID: 2624)
      • chrome.exe (PID: 5984)
      • TextInputHost.exe (PID: 1600)
      • chrome.exe (PID: 7228)
    • Creates files in the program directory

      • Roblox Account Manager (1).exe (PID: 7544)
      • Roblox Account Manager (1).exe (PID: 7632)
      • Auto Update.exe (PID: 7412)
      • Roblox Account Manager.exe (PID: 6904)
    • Reads the machine GUID from the registry

      • Roblox Account Manager (1).exe (PID: 7544)
      • Roblox Account Manager (1).exe (PID: 7632)
      • Auto Update.exe (PID: 8092)
      • Roblox Account Manager.exe (PID: 7284)
      • Auto Update.exe (PID: 7412)
      • Roblox Account Manager.exe (PID: 6904)
      • chrome.exe (PID: 7664)
    • Process checks computer location settings

      • Roblox Account Manager (1).exe (PID: 7544)
      • Roblox Account Manager (1).exe (PID: 7632)
      • Auto Update.exe (PID: 8092)
      • Roblox Account Manager.exe (PID: 7284)
      • chrome.exe (PID: 7664)
      • chrome.exe (PID: 4828)
      • chrome.exe (PID: 2624)
      • chrome.exe (PID: 5984)
    • Create files in a temporary directory

      • Roblox Account Manager (1).exe (PID: 7544)
      • Roblox Account Manager (1).exe (PID: 7632)
      • Auto Update.exe (PID: 7412)
      • Roblox Account Manager.exe (PID: 7284)
      • Roblox Account Manager.exe (PID: 6904)
      • chrome.exe (PID: 7664)
      • chrome.exe (PID: 8164)
    • Disables trace logs

      • Roblox Account Manager (1).exe (PID: 7632)
      • Auto Update.exe (PID: 7412)
      • Roblox Account Manager.exe (PID: 6904)
    • Checks proxy server information

      • Roblox Account Manager (1).exe (PID: 7632)
      • Auto Update.exe (PID: 7412)
      • Roblox Account Manager.exe (PID: 6904)
      • chrome.exe (PID: 7664)
    • Creates files or folders in the user directory

      • Roblox Account Manager (1).exe (PID: 7632)
      • Roblox Account Manager.exe (PID: 6904)
    • The sample compiled with english language support

      • Roblox Account Manager.exe (PID: 6904)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (56.7)
.exe | Win64 Executable (generic) (21.3)
.scr | Windows screen saver (10.1)
.dll | Win32 Dynamic Link Library (generic) (5)
.exe | Win32 Executable (generic) (3.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2047:11:22 08:58:55+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 5446656
InitializedDataSize: 31232
UninitializedDataSize: -
EntryPoint: 0x533a7e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 3.6.1.0
ProductVersionNumber: 3.6.1.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Created by ic3w0lf
CompanyName: ic3
FileDescription: Roblox Account Manager
FileVersion: 3.6.1.0
InternalName: Roblox Account Manager.exe
LegalCopyright: Copyright © ic3 2023
LegalTrademarks: -
OriginalFileName: Roblox Account Manager.exe
ProductName: Roblox Account Manager
ProductVersion: 3.6.1.0
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
164
Monitored processes
17
Malicious processes
0
Suspicious processes
5

Behavior graph

Click at the process to see the details
start roblox account manager (1).exe no specs roblox account manager (1).exe auto update.exe no specs auto update.exe roblox account manager.exe no specs roblox account manager.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs textinputhost.exe no specs chrome.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1600"C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mcaC:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Version:
123.26505.0.0
Modules
Images
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\textinputhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\vcruntime140_app.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
2624"C:\Users\admin\AppData\Local\PuppeteerSharp\Chrome\Win64-124.0.6367.201\chrome-win64\chrome.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Local\Temp\jcvldxkp.qaj" --no-appcompat-clear --disable-background-timer-throttling --disable-breakpad --enable-automation --force-color-profile=srgb --remote-debugging-port=0 --allow-pre-commit-input --enable-blink-features=IdleDetection --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=5 --field-trial-handle=3116,i,3344564723193370788,1752225405419161186,262144 --disable-features=AcceptCHFrame,MediaRouter,OptimizationHints,ProcessPerSiteUpToMainFrameThreshold,Translate --variations-seed-version --mojo-platform-channel-handle=3228 /prefetch:1C:\Users\admin\AppData\Local\PuppeteerSharp\Chrome\Win64-124.0.6367.201\chrome-win64\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome for Testing
Exit code:
0
Version:
124.0.6367.201
Modules
Images
c:\users\admin\appdata\local\puppeteersharp\chrome\win64-124.0.6367.201\chrome-win64\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\puppeteersharp\chrome\win64-124.0.6367.201\chrome-win64\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
4700"C:\Users\admin\AppData\Local\PuppeteerSharp\Chrome\Win64-124.0.6367.201\chrome-win64\chrome.exe" --type=gpu-process --disable-breakpad --user-data-dir="C:\Users\admin\AppData\Local\Temp\jcvldxkp.qaj" --no-appcompat-clear --start-stack-profiler --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAEAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --field-trial-handle=1976,i,3344564723193370788,1752225405419161186,262144 --disable-features=AcceptCHFrame,MediaRouter,OptimizationHints,ProcessPerSiteUpToMainFrameThreshold,Translate --variations-seed-version --mojo-platform-channel-handle=1944 /prefetch:2C:\Users\admin\AppData\Local\PuppeteerSharp\Chrome\Win64-124.0.6367.201\chrome-win64\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome for Testing
Exit code:
0
Version:
124.0.6367.201
Modules
Images
c:\users\admin\appdata\local\puppeteersharp\chrome\win64-124.0.6367.201\chrome-win64\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\puppeteersharp\chrome\win64-124.0.6367.201\chrome-win64\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
4828"C:\Users\admin\AppData\Local\PuppeteerSharp\Chrome\Win64-124.0.6367.201\chrome-win64\chrome.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Local\Temp\jcvldxkp.qaj" --no-appcompat-clear --start-stack-profiler --disable-background-timer-throttling --disable-breakpad --enable-automation --force-color-profile=srgb --remote-debugging-port=0 --allow-pre-commit-input --enable-blink-features=IdleDetection --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=6 --field-trial-handle=3096,i,3344564723193370788,1752225405419161186,262144 --disable-features=AcceptCHFrame,MediaRouter,OptimizationHints,ProcessPerSiteUpToMainFrameThreshold,Translate --variations-seed-version --mojo-platform-channel-handle=3132 /prefetch:1C:\Users\admin\AppData\Local\PuppeteerSharp\Chrome\Win64-124.0.6367.201\chrome-win64\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome for Testing
Exit code:
0
Version:
124.0.6367.201
Modules
Images
c:\users\admin\appdata\local\puppeteersharp\chrome\win64-124.0.6367.201\chrome-win64\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\puppeteersharp\chrome\win64-124.0.6367.201\chrome-win64\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
5984"C:\Users\admin\AppData\Local\PuppeteerSharp\Chrome\Win64-124.0.6367.201\chrome-win64\chrome.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Local\Temp\jcvldxkp.qaj" --no-appcompat-clear --disable-background-timer-throttling --disable-breakpad --enable-automation --force-color-profile=srgb --remote-debugging-port=0 --allow-pre-commit-input --disable-gpu-compositing --enable-blink-features=IdleDetection --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=7 --field-trial-handle=4008,i,3344564723193370788,1752225405419161186,262144 --disable-features=AcceptCHFrame,MediaRouter,OptimizationHints,ProcessPerSiteUpToMainFrameThreshold,Translate --variations-seed-version --mojo-platform-channel-handle=4492 /prefetch:1C:\Users\admin\AppData\Local\PuppeteerSharp\Chrome\Win64-124.0.6367.201\chrome-win64\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome for Testing
Exit code:
0
Version:
124.0.6367.201
Modules
Images
c:\users\admin\appdata\local\puppeteersharp\chrome\win64-124.0.6367.201\chrome-win64\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\puppeteersharp\chrome\win64-124.0.6367.201\chrome-win64\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
6904"C:\Users\admin\AppData\Local\Temp\Roblox Account Manager.exe" -restartC:\Users\admin\AppData\Local\Temp\Roblox Account Manager.exe
Roblox Account Manager.exe
User:
admin
Company:
ic3
Integrity Level:
MEDIUM
Description:
Roblox Account Manager
Version:
3.7.2.0
Modules
Images
c:\users\admin\appdata\local\temp\roblox account manager.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
7228"C:\Users\admin\AppData\Local\PuppeteerSharp\Chrome\Win64-124.0.6367.201\chrome-win64\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.ProcessorMetrics --lang=en-US --service-sandbox-type=none --user-data-dir="C:\Users\admin\AppData\Local\Temp\jcvldxkp.qaj" --no-appcompat-clear --field-trial-handle=4948,i,3344564723193370788,1752225405419161186,262144 --disable-features=AcceptCHFrame,MediaRouter,OptimizationHints,ProcessPerSiteUpToMainFrameThreshold,Translate --variations-seed-version --mojo-platform-channel-handle=4880 /prefetch:8C:\Users\admin\AppData\Local\PuppeteerSharp\Chrome\Win64-124.0.6367.201\chrome-win64\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome for Testing
Exit code:
0
Version:
124.0.6367.201
Modules
Images
c:\users\admin\appdata\local\puppeteersharp\chrome\win64-124.0.6367.201\chrome-win64\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\puppeteersharp\chrome\win64-124.0.6367.201\chrome-win64\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
7284"C:\Users\admin\AppData\Local\Temp\Roblox Account Manager.exe"C:\Users\admin\AppData\Local\Temp\Roblox Account Manager.exeAuto Update.exe
User:
admin
Company:
ic3
Integrity Level:
MEDIUM
Description:
Roblox Account Manager
Exit code:
0
Version:
3.7.2.0
Modules
Images
c:\users\admin\appdata\local\temp\roblox account manager.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
7412"C:\Users\admin\AppData\Local\Temp\Auto Update.exe" -updateC:\Users\admin\AppData\Local\Temp\Auto Update.exe
Auto Update.exe
User:
admin
Company:
ic3
Integrity Level:
HIGH
Description:
Roblox Account Manager
Exit code:
0
Version:
3.6.1.0
Modules
Images
c:\users\admin\appdata\local\temp\auto update.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
7444"C:\Users\admin\AppData\Local\PuppeteerSharp\Chrome\Win64-124.0.6367.201\chrome-win64\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --user-data-dir="C:\Users\admin\AppData\Local\Temp\jcvldxkp.qaj" --no-appcompat-clear --field-trial-handle=2408,i,3344564723193370788,1752225405419161186,262144 --disable-features=AcceptCHFrame,MediaRouter,OptimizationHints,ProcessPerSiteUpToMainFrameThreshold,Translate --variations-seed-version --mojo-platform-channel-handle=2420 /prefetch:8C:\Users\admin\AppData\Local\PuppeteerSharp\Chrome\Win64-124.0.6367.201\chrome-win64\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome for Testing
Exit code:
0
Version:
124.0.6367.201
Modules
Images
c:\users\admin\appdata\local\puppeteersharp\chrome\win64-124.0.6367.201\chrome-win64\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\puppeteersharp\chrome\win64-124.0.6367.201\chrome-win64\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
7 201
Read events
7 126
Write events
73
Delete events
2

Modification events

(PID) Process:(7632) Roblox Account Manager (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Roblox Account Manager (1)_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7632) Roblox Account Manager (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Roblox Account Manager (1)_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7632) Roblox Account Manager (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Roblox Account Manager (1)_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(7632) Roblox Account Manager (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Roblox Account Manager (1)_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(7632) Roblox Account Manager (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Roblox Account Manager (1)_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(7632) Roblox Account Manager (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Roblox Account Manager (1)_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(7632) Roblox Account Manager (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Roblox Account Manager (1)_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(7632) Roblox Account Manager (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Roblox Account Manager (1)_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7632) Roblox Account Manager (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Roblox Account Manager (1)_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7632) Roblox Account Manager (1).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Roblox Account Manager (1)_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
24
Suspicious files
279
Text files
82
Unknown types
7

Dropped files

PID
Process
Filename
Type
7632Roblox Account Manager (1).exeC:\Users\admin\AppData\Local\PuppeteerSharp\.local-chromium\chrome-win.zip
MD5:
SHA256:
6904Roblox Account Manager.exeC:\Users\admin\AppData\Local\PuppeteerSharp\chrome-win64.zip
MD5:
SHA256:
6904Roblox Account Manager.exeC:\Users\admin\AppData\Local\PuppeteerSharp\Chrome\Win64-124.0.6367.201\chrome-win64\chrome.dll
MD5:
SHA256:
7544Roblox Account Manager (1).exeC:\Users\admin\AppData\Local\Temp\RAMTheme.initext
MD5:F18FA783F4D27E35E54E54417334BFB4
SHA256:563EB35FD613F4298CD4DCEFF67652A13BA516A6244D9407C5709323C4CA4BB1
7632Roblox Account Manager (1).exeC:\Users\admin\AppData\Local\Temp\RAMSettings.initext
MD5:8EC667B649FC01D48534D916EB92743C
SHA256:A90DFE16AD4261034717B4B97982A84694A15607964A1750144C4F140E3D2D9F
7544Roblox Account Manager (1).exeC:\Users\admin\AppData\Local\Temp\log4.configxml
MD5:E4659AC08AF3582A23F38BF6C562F841
SHA256:E4B10630D9EC2AF508DE31752FBBC6816C7426C40A3E57F0A085CE7F42C77BD5
7632Roblox Account Manager (1).exeC:\Users\admin\AppData\Local\Temp\log.txttext
MD5:A76FC26141A68663A816FBCC57E944E5
SHA256:43BD578C61F56815FFFB1BFDFE3FB95BFF16CC066764BC6850FD3AC0E26AEEE5
7632Roblox Account Manager (1).exeC:\Users\admin\AppData\Local\Temp\Auto Update.exeexecutable
MD5:A057FAE0C8C97EE6CF2C12FB7BCF034D
SHA256:CDB0A360CCA7A5099C2D2357BE1A833E032FFDEB3F467A6FAC845F6BB77031C9
7412Auto Update.exeC:\Users\admin\AppData\Local\Temp\Update.zipcompressed
MD5:D58B79CB3D3635BA963427362F75D075
SHA256:49B2C015DA0851A2ED43820799A7BCDA08E1BC5F315E107598F87F4B1BD36DAC
7412Auto Update.exeC:\Users\admin\AppData\Local\Temp\Roblox Account Manager.exeexecutable
MD5:334728F32A1144C893FDFFC579A7709B
SHA256:BE9DDCDEDF8C36C64E6B0A32D2686B74A112913C54217CCAA46675BFD1DC82F1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
41
TCP/UDP connections
62
DNS requests
58
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7632
Roblox Account Manager (1).exe
GET
142.250.185.187:443
https://storage.googleapis.com/chromium-browser-snapshots/Win_x64/1069273/chrome-win.zip
US
whitelisted
7632
Roblox Account Manager (1).exe
GET
302
140.82.121.3:443
https://github.com/ic3w0lf22/Roblox-Account-Manager/raw/master/RBX%20Alt%20Manager/Resources/WatcherRegexMatches.txt
US
unknown
7412
Auto Update.exe
HEAD
302
140.82.121.3:443
https://github.com/ic3w0lf22/Roblox-Account-Manager/releases/download/0.0/Roblox.Account.Manager.3.7.2.zip
US
unknown
7412
Auto Update.exe
HEAD
200
185.199.108.133:443
https://release-assets.githubusercontent.com/github-production-release-asset/262147801/a1e01dfb-e698-4414-86f5-b708b37ef327?sp=r&sv=2018-11-09&sr=b&spr=https&se=2026-01-05T10%3A36%3A11Z&rscd=attachment%3B+filename%3DRoblox.Account.Manager.3.7.2.zip&rsct=application%2Foctet-stream&skoid=96c2d410-5711-43a1-aedd-ab1947aa7ab0&sktid=398a6654-997b-47e9-b12b-9515b896b4de&skt=2026-01-05T09%3A35%3A12Z&ske=2026-01-05T10%3A36%3A11Z&sks=b&skv=2018-11-09&sig=cdLm8D963UBh5Z6aRzJC%2FV5%2F%2FkhenOMj3%2Bd9MxPInhQ%3D&jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmVsZWFzZS1hc3NldHMuZ2l0aHVidXNlcmNvbnRlbnQuY29tIiwia2V5Ijoia2V5MSIsImV4cCI6MTc2NzYwNjI0MSwibmJmIjoxNzY3NjA1OTQxLCJwYXRoIjoicmVsZWFzZWFzc2V0cHJvZHVjdGlvbi5ibG9iLmNvcmUud2luZG93cy5uZXQifQ.Pw68PTSevwDngYBAbZQIHk3jmesiX6tPsaRAUfYzYIs&response-content-disposition=attachment%3B%20filename%3DRoblox.Account.Manager.3.7.2.zip&response-content-type=application%2Foctet-stream
US
whitelisted
7412
Auto Update.exe
GET
302
140.82.121.3:443
https://github.com/ic3w0lf22/Roblox-Account-Manager/releases/download/0.0/Roblox.Account.Manager.3.7.2.zip
US
unknown
6768
MoUsoCoreWorker.exe
GET
304
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop
US
whitelisted
7632
Roblox Account Manager (1).exe
GET
200
128.116.5.3:443
https://clientsettings.roblox.com/v1/client-version/WindowsPlayer
US
text
119 b
unknown
3376
svchost.exe
POST
200
20.190.160.64:443
https://login.live.com/RST2.srf
US
xml
11.1 Kb
whitelisted
7632
Roblox Account Manager (1).exe
GET
200
140.82.121.6:443
https://api.github.com/repos/ic3w0lf22/Roblox-Account-Manager/releases/latest
US
text
4.08 Kb
unknown
3376
svchost.exe
POST
200
20.190.160.64:443
https://login.live.com/RST2.srf
US
xml
10.3 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
5964
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1976
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3412
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3376
svchost.exe
20.190.160.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3376
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
7632
Roblox Account Manager (1).exe
128.116.5.3:443
clientsettings.roblox.com
ROBLOX-PRODUCTION
US
whitelisted
7632
Roblox Account Manager (1).exe
140.82.121.6:443
api.github.com
GITHUB
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
whitelisted
google.com
  • 142.251.141.78
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.160.64
  • 40.126.32.133
  • 20.190.160.130
  • 20.190.160.66
  • 20.190.160.22
  • 20.190.160.3
  • 40.126.32.76
  • 20.190.160.67
whitelisted
clientsettings.roblox.com
  • 128.116.5.3
whitelisted
github.com
  • 140.82.121.3
whitelisted
api.github.com
  • 140.82.121.6
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
storage.googleapis.com
  • 142.250.185.187
  • 142.250.185.219
  • 172.217.23.123
  • 142.251.141.123
  • 142.250.186.187
  • 142.250.184.219
  • 216.58.206.91
  • 142.250.185.251
  • 172.217.18.27
  • 142.251.208.27
  • 142.250.186.155
  • 142.251.140.187
  • 142.250.186.123
  • 216.58.206.59
  • 142.251.141.91
  • 142.250.184.251
whitelisted
raw.githubusercontent.com
  • 185.199.110.133
  • 185.199.109.133
  • 185.199.111.133
  • 185.199.108.133
whitelisted

Threats

PID
Process
Class
Message
2292
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
2292
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access release user assets on GitHub
Process
Message
chrome.exe
RecursiveDirectoryCreate( C:\Users\admin\AppData\Local\Temp\jcvldxkp.qaj directory exists )