| Size | 9.2MB |
|---|---|
| Type | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5 | bcfb0a4e8e3006a6b9d3de50793f1317 |
| SHA1 | 336f512aae09a4ff9f669331e231a676ca922e06 |
| SHA256 | cf2ab73af97dc276b0a5e0d2d08cd5b6ce82a48f7763fcb9a13621f7bc86c086 |
| SHA512 |
fc79fe459a8f24a79b0c9c595c5fd03d027177abcedf0b2e1bfbb85f672b835a3efb105a2be6b93dcc50c6bb58d24f14bc471252c64229c5ec883c2768809d4b
|
| CRC32 | 293203D1 |
| ssdeep | None |
| PDB Path | C:\buildAgent\work\ci_deploy_ninja_boot-x86_git\build.ninja\common\vs2019\x86\release\Installer\Windows\RobloxPlayerInstaller.pdb |
| Yara |
|
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
| Category | Started | Completed | Duration | Routing | Logs |
|---|---|---|---|---|---|
| FILE | Feb. 5, 2026, 9:18 p.m. | Feb. 5, 2026, 9:18 p.m. | 47 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2026-02-05 20:18:08,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpd0os1j 2026-02-05 20:18:08,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\EyWadzkUCTXpYHnhDv 2026-02-05 20:18:08,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\VVHfxouKQrxFMuBMBXIaQsoc 2026-02-05 20:18:08,280 [analyzer] DEBUG: Started auxiliary module Curtain 2026-02-05 20:18:08,280 [analyzer] DEBUG: Started auxiliary module DbgView 2026-02-05 20:18:08,703 [analyzer] DEBUG: Started auxiliary module Disguise 2026-02-05 20:18:08,890 [analyzer] DEBUG: Loaded monitor into process with pid 512 2026-02-05 20:18:08,890 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2026-02-05 20:18:08,890 [analyzer] DEBUG: Started auxiliary module Human 2026-02-05 20:18:08,905 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2026-02-05 20:18:08,905 [analyzer] DEBUG: Started auxiliary module Reboot 2026-02-05 20:18:08,967 [analyzer] DEBUG: Started auxiliary module RecentFiles 2026-02-05 20:18:08,967 [analyzer] DEBUG: Started auxiliary module Screenshots 2026-02-05 20:18:08,967 [analyzer] DEBUG: Started auxiliary module Sysmon 2026-02-05 20:18:08,967 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2026-02-05 20:18:09,187 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\RobloxPlayerInstaller.exe' with arguments '' and pid 812 2026-02-05 20:18:10,187 [analyzer] INFO: Process with pid 812 has terminated 2026-02-05 20:18:10,187 [analyzer] INFO: Process list is empty, terminating analysis. 2026-02-05 20:18:11,390 [analyzer] INFO: Terminating remaining processes before shutdown. 2026-02-05 20:18:11,390 [analyzer] INFO: Analysis completed.
2026-02-05 21:18:09,957 [cuckoo.core.scheduler] INFO: Task #7450845: acquired machine win7x6429 (label=win7x6429) 2026-02-05 21:18:09,958 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.229 for task #7450845 2026-02-05 21:18:10,307 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3188539 (interface=vboxnet0, host=192.168.168.229) 2026-02-05 21:18:17,967 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6429 2026-02-05 21:18:18,495 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6429 to vmcloak 2026-02-05 21:18:34,331 [cuckoo.core.guest] INFO: Starting analysis #7450845 on guest (id=win7x6429, ip=192.168.168.229) 2026-02-05 21:18:35,336 [cuckoo.core.guest] DEBUG: win7x6429: not ready yet 2026-02-05 21:18:40,361 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6429, ip=192.168.168.229) 2026-02-05 21:18:40,460 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6429, ip=192.168.168.229, monitor=latest, size=6660546) 2026-02-05 21:18:42,205 [cuckoo.core.resultserver] DEBUG: Task #7450845: live log analysis.log initialized. 2026-02-05 21:18:43,131 [cuckoo.core.resultserver] DEBUG: Task #7450845 is sending a BSON stream 2026-02-05 21:18:44,388 [cuckoo.core.resultserver] DEBUG: Task #7450845: File upload for 'shots/0001.jpg' 2026-02-05 21:18:44,405 [cuckoo.core.resultserver] DEBUG: Task #7450845 uploaded file length: 133370 2026-02-05 21:18:45,594 [cuckoo.core.resultserver] DEBUG: Task #7450845: File upload for 'curtain/1770319091.28.curtain.log' 2026-02-05 21:18:45,598 [cuckoo.core.resultserver] DEBUG: Task #7450845 uploaded file length: 36 2026-02-05 21:18:45,699 [cuckoo.core.resultserver] DEBUG: Task #7450845: File upload for 'sysmon/1770319091.39.sysmon.xml' 2026-02-05 21:18:45,703 [cuckoo.core.resultserver] DEBUG: Task #7450845 uploaded file length: 24876 2026-02-05 21:18:46,484 [cuckoo.core.resultserver] DEBUG: Task #7450845 had connection reset for <Context for LOG> 2026-02-05 21:18:47,719 [cuckoo.core.guest] INFO: win7x6429: analysis completed successfully 2026-02-05 21:18:47,732 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2026-02-05 21:18:47,763 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2026-02-05 21:18:48,760 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6429 to path /srv/cuckoo/cwd/storage/analyses/7450845/memory.dmp 2026-02-05 21:18:48,762 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6429 2026-02-05 21:18:56,416 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.229 for task #7450845 2026-02-05 21:18:56,760 [cuckoo.core.scheduler] DEBUG: Released database task #7450845 2026-02-05 21:18:56,775 [cuckoo.core.scheduler] INFO: Task #7450845: analysis procedure completed
| description | Rule to detect the presence of SQLite data in raw image | rule | with_sqlite | ||||||
| description | (no description) | rule | GenerateTLSClientHelloPacket_Test | ||||||
| description | (no description) | rule | DebuggerException__SetConsoleCtrl | ||||||
| description | (no description) | rule | Check_OutputDebugStringA_iat | ||||||
| description | Anti-debug process memory working set size check | rule | DebuggerCheck__MemoryWorkingSet | ||||||
| description | Checks if being debugged | rule | anti_dbg | ||||||
| description | Anti-Sandbox checks for ThreatExpert | rule | antisb_threatExpert | ||||||
| description | Listen for incoming communication | rule | network_tcp_listen | ||||||
| description | Communications over HTTP | rule | network_http | ||||||
| description | Communications over RAW socket | rule | network_tcp_socket | ||||||
| pdb_path | C:\buildAgent\work\ci_deploy_ninja_boot-x86_git\build.ninja\common\vs2019\x86\release\Installer\Windows\RobloxPlayerInstaller.pdb |
| resource name | PNG |