| File name: | RobloxPlayerInstaller.exe |
| Full analysis: | https://app.any.run/tasks/7ceb016f-4aa4-482d-b738-ceacc701a6ae |
| Verdict: | Malicious activity |
| Analysis date: | April 29, 2025, 18:38:05 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | A756432AD293E8741C93180D04413A05 |
| SHA1: | 4ECC371A1DAFEAC08E6B02FD88303F52FAA2FB58 |
| SHA256: | ECF1608D7F7EB70DC731FDD4E75BFB55434BBE594F1D7A998677AB9FEE1540DB |
| SSDEEP: | 98304:ms0vJR0yznuaSoNnbtmp+/4J3GLeHOKyh+LbJ914c2CxNFInTPIDQ2/vYiGH4NLm:XzfbRYRpRy4N |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2050:01:14 14:37:06+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.29 |
| CodeSize: | 5694976 |
| InitializedDataSize: | 2381312 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x50af25 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.6.0.16041 |
| ProductVersionNumber: | 1.6.0.16041 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Roblox Corporation |
| FileDescription: | Roblox |
| FileVersion: | 1, 6, 0, 6700713 |
| LegalCopyright: | Copyright © 2020 Roblox Corporation. All rights reserved. |
| OriginalFileName: | Roblox.exe |
| ProductName: | Roblox Bootstrapper |
| ProductVersion: | 1, 6, 0, 6700713 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 456 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5580 -childID 6 -isForBrowser -prefsHandle 5664 -prefMapHandle 5660 -prefsLen 31248 -prefMapSize 244583 -jsInitHandle 1300 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {2f9a22b7-865f-49b5-a6b6-ccfe69ee4951} 7732 "\\.\pipe\gecko-crash-server-pipe.7732" 20cc7a96f50 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 2320 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4160 -childID 2 -isForBrowser -prefsHandle 4152 -prefMapHandle 4148 -prefsLen 36588 -prefMapSize 244583 -jsInitHandle 1300 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {19438ad8-9612-4722-ba0a-4d97f673fe78} 7732 "\\.\pipe\gecko-crash-server-pipe.7732" 20ccb273690 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 2644 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4980 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 5044 -prefMapHandle 5040 -prefsLen 36588 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {7d9309ac-7c98-4249-ad42-dcd81239aeb6} 7732 "\\.\pipe\gecko-crash-server-pipe.7732" 20cccbb4f10 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 4528 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2952 -childID 1 -isForBrowser -prefsHandle 2944 -prefMapHandle 2920 -prefsLen 31447 -prefMapSize 244583 -jsInitHandle 1300 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {b81cf723-c7d6-4059-a014-871302ce4b1f} 7732 "\\.\pipe\gecko-crash-server-pipe.7732" 20cc8baed90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 5376 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4664 -childID 3 -isForBrowser -prefsHandle 4636 -prefMapHandle 4652 -prefsLen 31144 -prefMapSize 244583 -jsInitHandle 1300 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {7d3592ee-4133-425e-b3d0-9db341181d54} 7732 "\\.\pipe\gecko-crash-server-pipe.7732" 20ccc6b4a10 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 7432 | "C:\Users\admin\Desktop\RobloxPlayerInstaller.exe" | C:\Users\admin\Desktop\RobloxPlayerInstaller.exe | explorer.exe | ||||||||||||
User: admin Company: Roblox Corporation Integrity Level: MEDIUM Description: Roblox Version: 1, 6, 0, 6700713 Modules
| |||||||||||||||
| 7524 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7628 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 7652 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | — | SppExtComObj.Exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7732 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | firefox.exe | ||||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| (PID) Process: | (7432) RobloxPlayerInstaller.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\ProtocolExecute\roblox-studio |
| Operation: | write | Name: | WarnOnOpen |
Value: 0 | |||
| (PID) Process: | (7432) RobloxPlayerInstaller.exe | Key: | HKEY_CLASSES_ROOT\roblox-studio |
| Operation: | write | Name: | URL Protocol |
Value: | |||
| (PID) Process: | (7432) RobloxPlayerInstaller.exe | Key: | HKEY_CLASSES_ROOT\roblox-studio\shell\open\command |
| Operation: | write | Name: | version |
Value: version-43bb2135852549ef | |||
| (PID) Process: | (7732) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7732 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 7432 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Local\Roblox\Versions\RobloxStudioInstaller.exe | executable | |
MD5:C2153F1F2FCC44F39457FA47EEC09A5A | SHA256:F2FBD3A595DBA1DB26E677D4D911A3A24487A3201F72B31007E9E2D12E89765E | |||
| 7432 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Local\Temp\Roblox\http\8913724486d5e3c463c493b25346ca31 | binary | |
MD5:4AC5B92FCD6854E411CE03A69208A200 | SHA256:D7161C54A8742D32C56C4DFF94F4C535BFB2290F415E6C25A0E4D13383BAF424 | |||
| 7732 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\urlCache-current.bin | binary | |
MD5:297E88D7CEB26E549254EC875649F4EB | SHA256:8B75D4FB1845BAA06122888D11F6B65E6A36B140C54A72CC13DF390FD7C95702 | |||
| 7432 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\32622161783a33a229827a2a0261cc16 | compressed | |
MD5:32622161783A33A229827A2A0261CC16 | SHA256:631125E9AB228CCC5CA7CC723EABC683BAFA245F2E63B9FB23A55073DF017C12 | |||
| 7432 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox\Roblox Studio.lnk | binary | |
MD5:1D154BB4067EAE489A09FDC07AA974C4 | SHA256:F53604528DD5433D69A3DFCEB547FF9CD7A469A1C118B2E3114F21FD9A4BF2BE | |||
| 7432 | RobloxPlayerInstaller.exe | C:\Users\admin\Desktop\Roblox Studio.lnk | binary | |
MD5:610F4FF6EFCD33CDFC32532853BC10FD | SHA256:9C00AB4179D4E30BAF91225DDFC295D69360360CB57B0B7CF18ADA1AB12E61B2 | |||
| 7432 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Local\Roblox\logs\cacert.pem | text | |
MD5:18EB55403B6BFAF4927B174FC2A3AB66 | SHA256:7570425CD2E18C5A5536887906B6C113F62A03C2744CFFA27FC6B9CA1AD91C2C | |||
| 7432 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\c674cf486d4b5d0db8c7fa6ca9fb5a6b | compressed | |
MD5:C674CF486D4B5D0DB8C7FA6CA9FB5A6B | SHA256:E8E72EFE8943A858D1E0347C460ADBBF6FA936E2A2011808D64D6688144553ED | |||
| 7732 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-child-current.bin | binary | |
MD5:C95DDC2B1A525D1A243E4C294DA2F326 | SHA256:3A5919E086BFB31E36110CF636D2D5109EB51F2C410B107F126126AB25D67363 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
7732 | firefox.exe | POST | 200 | 95.101.54.114:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
7732 | firefox.exe | POST | 200 | 95.101.54.114:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
7732 | firefox.exe | POST | 200 | 142.250.186.131:80 | http://o.pki.goog/s/wr3/FIY | unknown | — | — | whitelisted |
7732 | firefox.exe | POST | 200 | 184.24.77.45:80 | http://r10.o.lencr.org/ | unknown | — | — | whitelisted |
7732 | firefox.exe | POST | 200 | 184.24.77.45:80 | http://r10.o.lencr.org/ | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.19.11.120:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7732 | firefox.exe | POST | 200 | 142.250.186.131:80 | http://o.pki.goog/we2 | unknown | — | — | whitelisted |
7732 | firefox.exe | POST | 200 | 95.101.54.114:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
6544 | svchost.exe | 20.190.160.65:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 172.211.123.249:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | FR | unknown |
— | — | 2.19.11.120:80 | crl.microsoft.com | Elisa Oyj | NL | whitelisted |
— | — | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
7432 | RobloxPlayerInstaller.exe | 128.116.5.3:443 | ecsv2.roblox.com | ROBLOX-PRODUCTION | US | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
7432 | RobloxPlayerInstaller.exe | 52.222.236.113:443 | clientsettingscdn.roblox.com | AMAZON-02 | US | whitelisted |
7432 | RobloxPlayerInstaller.exe | 2.19.11.108:443 | setup.rbxcdn.com | Elisa Oyj | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
login.live.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
ecsv2.roblox.com |
| whitelisted |
client-telemetry.roblox.com |
| whitelisted |
clientsettingscdn.roblox.com |
| whitelisted |
setup.rbxcdn.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Not Suspicious Traffic | INFO [ANY.RUN] hCaptcha Enterprise Challenge |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] hCaptcha Enterprise Challenge |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] hCaptcha Enterprise Challenge |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] hCaptcha Enterprise Challenge |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] hCaptcha Enterprise Challenge |
— | — | Misc activity | ET INFO Packed Executable Download |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] hCaptcha Enterprise Challenge |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] hCaptcha Enterprise Challenge |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] hCaptcha Enterprise Challenge |