| File name: | RobloxPlayerInstaller.exe |
| Full analysis: | https://app.any.run/tasks/c43461e9-bd9b-4de1-ba42-e1fe3c3dc77a |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | April 29, 2025, 18:46:40 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | A756432AD293E8741C93180D04413A05 |
| SHA1: | 4ECC371A1DAFEAC08E6B02FD88303F52FAA2FB58 |
| SHA256: | ECF1608D7F7EB70DC731FDD4E75BFB55434BBE594F1D7A998677AB9FEE1540DB |
| SSDEEP: | 98304:ms0vJR0yznuaSoNnbtmp+/4J3GLeHOKyh+LbJ914c2CxNFInTPIDQ2/vYiGH4NLm:XzfbRYRpRy4N |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2050:01:14 14:37:06+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.29 |
| CodeSize: | 5694976 |
| InitializedDataSize: | 2381312 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x50af25 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.6.0.16041 |
| ProductVersionNumber: | 1.6.0.16041 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Roblox Corporation |
| FileDescription: | Roblox |
| FileVersion: | 1, 6, 0, 6700713 |
| LegalCopyright: | Copyright © 2020 Roblox Corporation. All rights reserved. |
| OriginalFileName: | Roblox.exe |
| ProductName: | Roblox Bootstrapper |
| ProductVersion: | 1, 6, 0, 6700713 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 536 | "C:\Program Files\Mozilla Firefox\firefox.exe" | C:\Program Files\Mozilla Firefox\firefox.exe | — | explorer.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 660 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4368 -childID 2 -isForBrowser -prefsHandle 4360 -prefMapHandle 4348 -prefsLen 36588 -prefMapSize 244583 -jsInitHandle 1512 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {a3182837-5a8b-4a64-8794-d9ca4e2fecaf} 5720 "\\.\pipe\gecko-crash-server-pipe.5720" 1fa6a514d90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1072 | "C:\Users\admin\Desktop\RobloxPlayerInstaller.exe" | C:\Users\admin\Desktop\RobloxPlayerInstaller.exe | explorer.exe | ||||||||||||
User: admin Company: Roblox Corporation Integrity Level: MEDIUM Description: Roblox Exit code: 0 Version: 1, 6, 0, 6700713 Modules
| |||||||||||||||
| 1096 | "C:\Users\admin\Desktop\RobloxPlayerInstaller.exe" | C:\Users\admin\Desktop\RobloxPlayerInstaller.exe | explorer.exe | ||||||||||||
User: admin Company: Roblox Corporation Integrity Level: MEDIUM Description: Roblox Exit code: 0 Version: 1, 6, 0, 6700713 Modules
| |||||||||||||||
| 1164 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1164 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4600 -childID 10 -isForBrowser -prefsHandle 6328 -prefMapHandle 6272 -prefsLen 31321 -prefMapSize 244583 -jsInitHandle 1428 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {8cf483a0-c34e-446e-b94d-693c99440375} 7676 "\\.\pipe\gecko-crash-server-pipe.7676" 220e2e544d0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 1184 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=3300 -childID 1 -isForBrowser -prefsHandle 3296 -prefMapHandle 3292 -prefsLen 32862 -prefMapSize 244583 -jsInitHandle 1428 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {573ebc3f-75ba-4984-8f1a-2def3660067d} 7676 "\\.\pipe\gecko-crash-server-pipe.7676" 220e3bf3f50 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 1568 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1916 -parentBuildID 20240213221259 -prefsHandle 1856 -prefMapHandle 1168 -prefsLen 31031 -prefMapSize 244583 -appDir "C:\Program Files\Mozilla Firefox\browser" - {866d6dd7-fbd9-4fa9-af62-6db9e3ea467b} 5720 "\\.\pipe\gecko-crash-server-pipe.5720" 1fa631eb110 gpu | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 1 Version: 123.0 Modules
| |||||||||||||||
| 2268 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2152 -parentBuildID 20240213221259 -prefsHandle 2144 -prefMapHandle 2140 -prefsLen 31031 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {c8e87cad-2c1b-418a-8ffc-41b31b165672} 5720 "\\.\pipe\gecko-crash-server-pipe.5720" 1fa56280f10 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 2320 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2856 -childID 1 -isForBrowser -prefsHandle 2736 -prefMapHandle 2592 -prefsLen 31447 -prefMapSize 244583 -jsInitHandle 1512 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {27a991b2-f600-43f3-88df-0d813f444d1e} 5720 "\\.\pipe\gecko-crash-server-pipe.5720" 1fa67ff2f50 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| (PID) Process: | (1072) RobloxPlayerInstaller.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\ProtocolExecute\roblox-studio |
| Operation: | write | Name: | WarnOnOpen |
Value: 0 | |||
| (PID) Process: | (1072) RobloxPlayerInstaller.exe | Key: | HKEY_CLASSES_ROOT\roblox-studio |
| Operation: | write | Name: | URL Protocol |
Value: | |||
| (PID) Process: | (1072) RobloxPlayerInstaller.exe | Key: | HKEY_CLASSES_ROOT\roblox-studio\shell\open\command |
| Operation: | write | Name: | version |
Value: version-43bb2135852549ef | |||
| (PID) Process: | (5720) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (7476) MicrosoftEdgeUpdate.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate |
| Operation: | delete value | Name: | eulaaccepted |
Value: | |||
| (PID) Process: | (5956) MicrosoftEdgeUpdateComRegisterShell64.exe | Key: | HKEY_CLASSES_ROOT\CLSID\{B29F5F83-90DF-479A-BDE7-8A9F4412E394}\InProcServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Both | |||
| (PID) Process: | (6960) MicrosoftEdgeUpdate.exe | Key: | HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{81093D63-7825-417B-BFC8-ADC63FA4E53D}\InprocServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Both | |||
| (PID) Process: | (6960) MicrosoftEdgeUpdate.exe | Key: | HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{5EA43877-C6D8-4885-B77A-C0BB27E94372}\InprocServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Both | |||
| (PID) Process: | (6960) MicrosoftEdgeUpdate.exe | Key: | HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{209222BB-556D-4EAF-9C53-4ACB9E51731C}\InprocHandler32 |
| Operation: | write | Name: | ThreadingModel |
Value: Both | |||
| (PID) Process: | (6960) MicrosoftEdgeUpdate.exe | Key: | HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{B29F5F83-90DF-479A-BDE7-8A9F4412E394}\InProcServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Both | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1072 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Local\Roblox\Versions\RobloxStudioInstaller.exe | executable | |
MD5:C2153F1F2FCC44F39457FA47EEC09A5A | SHA256:F2FBD3A595DBA1DB26E677D4D911A3A24487A3201F72B31007E9E2D12E89765E | |||
| 1072 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Local\Roblox\logs\cacert.pem | text | |
MD5:18EB55403B6BFAF4927B174FC2A3AB66 | SHA256:7570425CD2E18C5A5536887906B6C113F62A03C2744CFFA27FC6B9CA1AD91C2C | |||
| 1072 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox\Roblox Studio.lnk | binary | |
MD5:CC6F4A2B8252691EAD2BB72D104DA9DF | SHA256:CE9D492C381E3B05713F43BD538F3D08C3A254C7CFBAF22808C63C7C39202EBE | |||
| 1072 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\32622161783a33a229827a2a0261cc16 | compressed | |
MD5:32622161783A33A229827A2A0261CC16 | SHA256:631125E9AB228CCC5CA7CC723EABC683BAFA245F2E63B9FB23A55073DF017C12 | |||
| 1072 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\8bd85f4e8e0f8904501eb60e6f3bf7ee | compressed | |
MD5:8BD85F4E8E0F8904501EB60E6F3BF7EE | SHA256:2E01FCA8EA0CDFCB1E6962AE9A8DC8FAB9241441E2568D812AAD9A11E1BFF57B | |||
| 1072 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\a85a31d787316b5518fa6cef985cc022 | compressed | |
MD5:A85A31D787316B5518FA6CEF985CC022 | SHA256:BB157C0E139F65E7D43796039A257565FF6308B92DFC5A655F99BF94D78609F7 | |||
| 1072 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\2724029fd2f49fc0ba0eb8991a806a54 | compressed | |
MD5:2724029FD2F49FC0BA0EB8991A806A54 | SHA256:11FC5C2671BF8BEE224C82EEC4DF87D5CFCAE60E524A277B3DD4E22AFAF03390 | |||
| 1072 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Local\Temp\Roblox\http\8913724486d5e3c463c493b25346ca31 | binary | |
MD5:4662DE0C61DA24251EB6F5FF27022E1B | SHA256:1C58A05909F7563366D792F9BA366C4C980DE78EEA4856F0E77878A9E5F763A2 | |||
| 1072 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\c0b029a8acb8c62034cf05e53afb1591 | compressed | |
MD5:C0B029A8ACB8C62034CF05E53AFB1591 | SHA256:DEE8CDE00CB3CDC016BD0F147F05B5E1171B4B741A1F1611A90A365FEC604C05 | |||
| 1072 | RobloxPlayerInstaller.exe | C:\Users\admin\AppData\Local\Roblox\Downloads\roblox-player\1d0390337d1a4a58e5514be1a9481ad6 | compressed | |
MD5:1D0390337D1A4A58E5514BE1A9481AD6 | SHA256:C79F0EEB2BCA4905C585C50333DB3C6F727A554F5DB82E64948F93668FBC18AA | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 2.16.241.19:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 23.54.109.203:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1020 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1020 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
5720 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
5720 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
5720 | firefox.exe | POST | 200 | 184.24.77.71:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
5720 | firefox.exe | POST | 200 | 184.24.77.71:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
5720 | firefox.exe | POST | 200 | 142.250.184.195:80 | http://o.pki.goog/s/wr3/FIY | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2104 | svchost.exe | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
— | — | 2.16.241.19:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 23.219.150.101:80 | www.microsoft.com | AKAMAI-AS | CL | whitelisted |
— | — | 172.211.123.248:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
1072 | RobloxPlayerInstaller.exe | 128.116.5.3:443 | ecsv2.roblox.com | ROBLOX-PRODUCTION | US | whitelisted |
1072 | RobloxPlayerInstaller.exe | 18.172.242.115:443 | clientsettingscdn.roblox.com | — | US | whitelisted |
1072 | RobloxPlayerInstaller.exe | 23.216.77.19:443 | setup.rbxcdn.com | Akamai International B.V. | DE | whitelisted |
6544 | svchost.exe | 40.126.31.1:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
ecsv2.roblox.com |
| whitelisted |
client-telemetry.roblox.com |
| whitelisted |
clientsettingscdn.roblox.com |
| whitelisted |
setup.rbxcdn.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] hCaptcha Enterprise Challenge |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] hCaptcha Enterprise Challenge |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] hCaptcha Enterprise Challenge |
7744 | svchost.exe | Misc activity | ET INFO Packed Executable Download |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] hCaptcha Enterprise Challenge |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] hCaptcha Enterprise Challenge |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] hCaptcha Enterprise Challenge |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] hCaptcha Enterprise Challenge |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] hCaptcha Enterprise Challenge |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] hCaptcha Enterprise Challenge |