Windows Analysis Report
RobloxPlayer DevBuildV2.653.952.exe

Overview

General Information

Sample name: RobloxPlayer DevBuildV2.653.952.exe
Analysis ID: 1592103
MD5: e7736af7896880469cfbc57674cf65f7
SHA1: 213c71cacc1bd2a9231929f91ebc866243326119
SHA256: b635de9bd72ea6ae83689339fba8c921472dabb68c11f811d54a6a399d86cad3
Tags: exeuser-JaffaCakes118
Infos:

Detection

Score: 52
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Multi AV Scanner detection for submitted file
Installs new ROOT certificates
IP address seen in connection with other malware
PE file contains more sections than normal
PE file contains sections with non-standard names
Sample file is different than original file name gathered from version info
Stores large binary data to the registry

Classification

AV Detection

barindex
Source: RobloxPlayer DevBuildV2.653.952.exe Virustotal: Detection: 8% Perma Link
Source: RobloxPlayer DevBuildV2.653.952.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Joe Sandbox View IP Address: 162.159.136.234 162.159.136.234
Source: Joe Sandbox View IP Address: 162.159.136.232 162.159.136.232
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /api/v9/gateway HTTP/1.1Host: discord.comUser-Agent: DiscordBot (https://github.com/bwmarrin/discordgo, v0.28.1)Authorization: Bot MTMyMTgyMzQzOTc4NjM0NDQ0OQ.GVfsKt.LoO5L0UyUxXZCymHOU66LRKf5AFk8624Ax9a3kAccept-Encoding: gzip
Source: global traffic HTTP traffic detected: GET /?v=9&encoding=json HTTP/1.1Host: gateway.discord.ggUser-Agent: Go-http-client/1.1Accept-Encoding: zlibConnection: UpgradeSec-WebSocket-Key: FBohGiWfJwFpXpKYVislTg==Sec-WebSocket-Version: 13Upgrade: websocket
Source: global traffic DNS traffic detected: DNS query: discord.com
Source: global traffic DNS traffic detected: DNS query: gateway.discord.gg
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 15 Jan 2025 18:03:09 GMTContent-Length: 0Connection: closeCF-Cache-Status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=ma7Zrhfc%2BnW08r%2FoY1AtTfiPA9Twzkou4BCBiBgq19bivukFSvRdqoSXHX6EjzXJi1YXN8YWYTNqiQSHncs1ekcPMwfJJL3vcRXti3p0taLFgp1WyApvRQwbxorj2KPl1K5Djg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Strict-Transport-Security: max-age=31536000; includeSubDomains; preloadX-Content-Type-Options: nosniffServer: cloudflareCF-RAY: 9027c7e92a4e80df-EWR
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://cdn.discordapp.com/attachments/
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://cdn.discordapp.com/avatars/
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://cdn.discordapp.com/banners/
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://cdn.discordapp.com/channel-icons/
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://cdn.discordapp.com/guilds/
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://cdn.discordapp.com/icons/
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://cdn.discordapp.com/role-icons/
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://cdn.discordapp.com/splashes/
Source: RobloxPlayer DevBuildV2.653.952.exe String found in binary or memory: https://curl.se/docs/caextract.html
Source: RobloxPlayer DevBuildV2.653.952.exe String found in binary or memory: https://discord.com/MESSAGE_REACTION_ADDTHREAD_MEMBER_UPDATEunmarshall
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C000090000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9//sticker-packs
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9//voice/
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9//voice/regions
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C000090000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/09Az~~kernel32.dllREQUEST_METHODiphlpapi.dll
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/applications
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/channels/
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/gateway
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/gateway/bot
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/guilds
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/guilds/
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/guilds/https://discord.com/api/v9/channels/https://discord.com/api/v9/use
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/oauth2/
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/oauth2/applications
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/stage-instances
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/stickers/
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/users/
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000B2000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://discord.com/api/v9/webhooks/
Source: RobloxPlayer DevBuildV2.653.952.exe String found in binary or memory: https://github.com/bwmarrin/discordgo
Source: RobloxPlayer DevBuildV2.653.952.exe String found in binary or memory: https://go.micro
Source: RobloxPlayer DevBuildV2.653.952.exe String found in binary or memory: https://hg.mozilla.org/releases/mozilla-release/raw-file/default/security/nss/lib/ckfw/builtins/c
Source: RobloxPlayer DevBuildV2.653.952.exe String found in binary or memory: https://hg.mozilla.org/releases/mozilla-release/raw-file/default/security/nss/lib/ckfw/builtins/cert
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000C4000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://status.discord.com/api/v2/scheduled-maintenances/
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000C6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://status.discord.com/api/v2/scheduled-maintenances/active.json
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000C6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://status.discord.com/api/v2/scheduled-maintenances/active.jsonhttps://status.discord.com/api/v
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1748933159.000000C0000C6000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: https://status.discord.com/api/v2/scheduled-maintenances/upcoming.json
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49730
Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49730 -> 443
Source: RobloxPlayer DevBuildV2.653.952.exe Static PE information: Number of sections : 16 > 10
Source: RobloxPlayer DevBuildV2.653.952.exe Binary or memory string: OriginalFilename vs RobloxPlayer DevBuildV2.653.952.exe
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000000.1727912934.0000000001168000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenameRoblox.exeH vs RobloxPlayer DevBuildV2.653.952.exe
Source: RobloxPlayer DevBuildV2.653.952.exe Binary or memory string: OriginalFilenameRoblox.exeH vs RobloxPlayer DevBuildV2.653.952.exe
Source: RobloxPlayer DevBuildV2.653.952.exe Static PE information: Section: /19 ZLIB complexity 0.9993589839990376
Source: RobloxPlayer DevBuildV2.653.952.exe Static PE information: Section: /32 ZLIB complexity 0.9931508059954751
Source: RobloxPlayer DevBuildV2.653.952.exe Static PE information: Section: /65 ZLIB complexity 0.9993939853742302
Source: RobloxPlayer DevBuildV2.653.952.exe Static PE information: Section: /78 ZLIB complexity 0.9912943918665668
Source: classification engine Classification label: mal52.winEXE@2/0@2/2
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7292:120:WilError_03
Source: RobloxPlayer DevBuildV2.653.952.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: RobloxPlayer DevBuildV2.653.952.exe Virustotal: Detection: 8%
Source: RobloxPlayer DevBuildV2.653.952.exe String found in binary or memory: error connecting to udp addr %s, %serror sending disconnect packet, %ssuccessfully reconnected to gateway1776356839400250464677810668945312588817841970012523233890533447265625ryuFtoaFixed32 called with prec > 9reflect.MakeSlice of non-slice typepersistentalloc: align is too large/memory/classes/heap/released:bytesgreyobject: obj not pointer-alignedmismatched begin/end of activeSweepmheap.freeSpanLocked - invalid freefailed to get or create weak handleattempt to clear non-empty span setruntime: close polldesc w/o unblockruntime: inconsistent read deadlineNtCreateWaitCompletionPacket failedfindrunnable: netpoll with spinningpidleput: P has non-empty run queuetraceback did not unwind completelyruntime: createevent failed; errno=file type does not support deadlinehttp: server closed idle connectionCONTINUATION frame with stream ID 0invalid utf8 payload in close framebad successive approximation valuesSubscribeServiceChangeNotificationsunsupported signature algorithm: %vtls: too many non-advancing recordstls: server selected an invalid PSKtls: invalid Kyber server key sharemime: bogus characters after %%: %qhpack: invalid Huffman-encoded datadynamic table size update too largeflate: corrupt input before offset hash/crc32: invalid hash state sizetoo many Questions to pack (>65535)bigmod: modulus is smaller than natx509: malformed extension OID fieldx509: wrong Ed25519 public key sizex509: invalid authority info accessmlkem768: invalid ciphertext lengthcrypto/md5: invalid hash state size'_' must separate successive digitsP224 point is the point at infinityP256 point is the point at infinityP384 point is the point at infinityP521 point is the point at infinitysuperfluous leading zeros in lengthchacha20: output smaller than inputtransform: short destination bufferstrings.Builder.Grow: negative countstrings: Join output length overflowaccessing a corrupted shared libraryTime.UnmarshalBinary: invalid lengthShardID must be less than ShardCounterror dispatching internal event, %scannot specify both Embed and Embedserror reconnecting to channel %s, %serror closing session connection, %serror decoding websocket message, %ssending heartbeat in response to Op1444089209850062616169452667236328125ryuFtoaFixed64 called with prec > 180123456789abcdefghijklmnopqrstuvwxyzmethod ABI and value ABI don't alignlfstack node allocated from the heap) is larger than maximum page size (key size not a multiple of key alignruntime: invalid typeBitsBulkBarrieruncaching span but s.allocCount == 0/memory/classes/metadata/other:bytes/sched/pauses/stopping/other:secondsuser arena span is on the wrong listruntime: marked free object in span runtime: unblock on closing polldescruntime: inconsistent write deadlineUnable to determine system directoryruntime: VirtualQuery failed; errno=runtime: sudog with non-nil waitlinkruntime: mcall called on m->g0 stackstartm: P required for spinning=true) is not Grunnable or Gscanrunnable
Source: RobloxPlayer DevBuildV2.653.952.exe String found in binary or memory: error connecting to udp addr %s, %serror sending disconnect packet, %ssuccessfully reconnected to gateway1776356839400250464677810668945312588817841970012523233890533447265625ryuFtoaFixed32 called with prec > 9reflect.MakeSlice of non-slice typepersistentalloc: align is too large/memory/classes/heap/released:bytesgreyobject: obj not pointer-alignedmismatched begin/end of activeSweepmheap.freeSpanLocked - invalid freefailed to get or create weak handleattempt to clear non-empty span setruntime: close polldesc w/o unblockruntime: inconsistent read deadlineNtCreateWaitCompletionPacket failedfindrunnable: netpoll with spinningpidleput: P has non-empty run queuetraceback did not unwind completelyruntime: createevent failed; errno=file type does not support deadlinehttp: server closed idle connectionCONTINUATION frame with stream ID 0invalid utf8 payload in close framebad successive approximation valuesSubscribeServiceChangeNotificationsunsupported signature algorithm: %vtls: too many non-advancing recordstls: server selected an invalid PSKtls: invalid Kyber server key sharemime: bogus characters after %%: %qhpack: invalid Huffman-encoded datadynamic table size update too largeflate: corrupt input before offset hash/crc32: invalid hash state sizetoo many Questions to pack (>65535)bigmod: modulus is smaller than natx509: malformed extension OID fieldx509: wrong Ed25519 public key sizex509: invalid authority info accessmlkem768: invalid ciphertext lengthcrypto/md5: invalid hash state size'_' must separate successive digitsP224 point is the point at infinityP256 point is the point at infinityP384 point is the point at infinityP521 point is the point at infinitysuperfluous leading zeros in lengthchacha20: output smaller than inputtransform: short destination bufferstrings.Builder.Grow: negative countstrings: Join output length overflowaccessing a corrupted shared libraryTime.UnmarshalBinary: invalid lengthShardID must be less than ShardCounterror dispatching internal event, %scannot specify both Embed and Embedserror reconnecting to channel %s, %serror closing session connection, %serror decoding websocket message, %ssending heartbeat in response to Op1444089209850062616169452667236328125ryuFtoaFixed64 called with prec > 180123456789abcdefghijklmnopqrstuvwxyzmethod ABI and value ABI don't alignlfstack node allocated from the heap) is larger than maximum page size (key size not a multiple of key alignruntime: invalid typeBitsBulkBarrieruncaching span but s.allocCount == 0/memory/classes/metadata/other:bytes/sched/pauses/stopping/other:secondsuser arena span is on the wrong listruntime: marked free object in span runtime: unblock on closing polldescruntime: inconsistent write deadlineUnable to determine system directoryruntime: VirtualQuery failed; errno=runtime: sudog with non-nil waitlinkruntime: mcall called on m->g0 stackstartm: P required for spinning=true) is not Grunnable or Gscanrunnable
Source: RobloxPlayer DevBuildV2.653.952.exe String found in binary or memory: C:/Program Files/Go/src/net/addrselect.go
Source: unknown Process created: C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe "C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe"
Source: C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe Section loaded: gpapi.dll Jump to behavior
Source: RobloxPlayer DevBuildV2.653.952.exe Static PE information: Virtual size of .text is bigger than: 0x100000
Source: RobloxPlayer DevBuildV2.653.952.exe Static file information: File size 10351616 > 1048576
Source: RobloxPlayer DevBuildV2.653.952.exe Static PE information: Raw size of .text is bigger than: 0x100000 < 0x2ee200
Source: RobloxPlayer DevBuildV2.653.952.exe Static PE information: Raw size of .rdata is bigger than: 0x100000 < 0x317200
Source: RobloxPlayer DevBuildV2.653.952.exe Static PE information: Raw size of /65 is bigger than: 0x100000 < 0x107e00
Source: RobloxPlayer DevBuildV2.653.952.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: RobloxPlayer DevBuildV2.653.952.exe Static PE information: section name: .xdata
Source: RobloxPlayer DevBuildV2.653.952.exe Static PE information: section name: /4
Source: RobloxPlayer DevBuildV2.653.952.exe Static PE information: section name: /19
Source: RobloxPlayer DevBuildV2.653.952.exe Static PE information: section name: /32
Source: RobloxPlayer DevBuildV2.653.952.exe Static PE information: section name: /46
Source: RobloxPlayer DevBuildV2.653.952.exe Static PE information: section name: /65
Source: RobloxPlayer DevBuildV2.653.952.exe Static PE information: section name: /78
Source: RobloxPlayer DevBuildV2.653.952.exe Static PE information: section name: /90
Source: RobloxPlayer DevBuildV2.653.952.exe Static PE information: section name: .symtab

Persistence and Installation Behavior

barindex
Source: C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 Blob Jump to behavior
Source: C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 Blob Jump to behavior
Source: C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 Blob Jump to behavior
Source: C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: RobloxPlayer DevBuildV2.653.952.exe Binary or memory string: MDALj2aTPs+9xYa9+bG3tD60B8jzljHz7aRP+KNOjSkVWLjVb3/ubCK1sK9IRQq9qEmUv4RDsNuE
Source: RobloxPlayer DevBuildV2.653.952.exe Binary or memory string: s+9xYa9+bG3tD60B8jzljHz7aRP+KNOjSkVWLjVb3/ubCK1sK9IRQq9qEmUv4RDsNuE SgMjGWdqb8FuvAY5N9GIIvejQjBAMA8GA1UdEwEB/wQFMAMBAf8wDgYDVR0PAQH/BAQDAgEGMB0G A1UdDgQWBBTmGHX/72DehKT1RsfeSlXjMjZ59TAKBggqhkjOPQQDAwNnADBkAjAmc0l6tqvmSfR9 Uj/UQQSugEODZXW5hYA4O9Zv5JOGq4/nich
Source: RobloxPlayer DevBuildV2.653.952.exe, 00000000.00000002.1750725903.000002B668D2B000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll4
Source: C:\Users\user\Desktop\RobloxPlayer DevBuildV2.653.952.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs