Resubmissions
05-07-2024 20:49
240705-zmg84avgrq 602-07-2024 22:50
240702-2sljtayapr 602-07-2024 21:03
240702-zv7tqaygqe 601-07-2024 21:08
240701-zyw7dstdmj 628-06-2024 21:21
240628-z7jmnasdmd 1028-06-2024 21:19
240628-z6e8vasdke 428-06-2024 21:18
240628-z5zwvssdka 128-06-2024 21:16
240628-z4fftsvfrq 428-06-2024 21:11
240628-z1wnmssckh 1Analysis
-
max time kernel
717s -
max time network
2043s -
platform
windows10-1703_x64 -
resource
win10-20240404-en -
resource tags
arch:x64arch:x86image:win10-20240404-enlocale:en-usos:windows10-1703-x64system -
submitted
02-07-2024 22:50
Static task
static1
Behavioral task
behavioral1
Sample
RobloxStudioInstaller (2).exe
Resource
win10-20240404-en
General
-
Target
RobloxStudioInstaller (2).exe
-
Size
4.5MB
-
MD5
34b2fd7c0a35ee46a8fc3a38ac18d489
-
SHA1
f0b1446847d05f8a28c98f1d0204d632644f5721
-
SHA256
7d30dad6bc7c79e0ee043bdc8dfd2b64d8b1ea19687b332683ed57bb55331118
-
SHA512
2d126018df5c0bdbf9e6906431a3fe988593080d6ce3077e7d7f85f564ad24f4c1a081bc0709900623604c76ed1f6037bf8f670e0334d2b0b146eea13196ffbb
-
SSDEEP
98304:n5vhdKHivtGeJKrsS3wA6RgN0VbTbcXC8I42nSbhh/A:1hSivEStS3ogN26InS4
Malware Config
Signatures
-
Processes:
RobloxStudioBeta.exeRobloxStudioInstaller (2).exeRobloxStudioBeta.exedescription ioc process Key value queried \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA RobloxStudioBeta.exe Key value queried \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA RobloxStudioInstaller (2).exe Key value queried \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA RobloxStudioBeta.exe -
Downloads MZ/PE file
-
Drops desktop.ini file(s) 1 IoCs
Processes:
bcastdvr.exedescription ioc process File opened for modification C:\Users\Admin\Videos\Captures\desktop.ini bcastdvr.exe -
Event Triggered Execution: Image File Execution Options Injection 1 TTPs 4 IoCs
Processes:
MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exedescription ioc process Key created \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdate.exe Set value (int) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MicrosoftEdgeUpdate.exe\DisableExceptionChainValidation = "0" MicrosoftEdgeUpdate.exe Key created \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdate.exe Set value (int) \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MicrosoftEdgeUpdate.exe\DisableExceptionChainValidation = "0" MicrosoftEdgeUpdate.exe -
Checks computer location settings 2 TTPs 4 IoCs
Looks up country code configured in the registry, likely geofence.
Processes:
msedgewebview2.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exedescription ioc process Key value queried \REGISTRY\USER\S-1-5-21-160447019-1232603106-4168707212-1000\Control Panel\International\Geo\Nation msedgewebview2.exe Key value queried \REGISTRY\USER\S-1-5-21-160447019-1232603106-4168707212-1000\Control Panel\International\Geo\Nation msedgewebview2.exe Key value queried \REGISTRY\USER\S-1-5-21-160447019-1232603106-4168707212-1000\Control Panel\International\Geo\Nation msedgewebview2.exe Key value queried \REGISTRY\USER\S-1-5-21-160447019-1232603106-4168707212-1000\Control Panel\International\Geo\Nation msedgewebview2.exe -
Drops file in System32 directory 18 IoCs
Processes:
MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exedescription ioc process File opened for modification C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE MicrosoftEdgeUpdate.exe File opened for modification C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content MicrosoftEdgeUpdate.exe File opened for modification C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 MicrosoftEdgeUpdate.exe File opened for modification C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache MicrosoftEdgeUpdate.exe File opened for modification C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\counters2.dat MicrosoftEdgeUpdate.exe File opened for modification C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\counters2.dat MicrosoftEdgeUpdate.exe File opened for modification C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\counters2.dat MicrosoftEdgeUpdate.exe File opened for modification C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 MicrosoftEdgeUpdate.exe File opened for modification C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCookies MicrosoftEdgeUpdate.exe File opened for modification C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft MicrosoftEdgeUpdate.exe File opened for modification C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 MicrosoftEdgeUpdate.exe File opened for modification C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64A MicrosoftEdgeUpdate.exe File opened for modification C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64A MicrosoftEdgeUpdate.exe File opened for modification C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\counters2.dat MicrosoftEdgeUpdate.exe File opened for modification C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5 MicrosoftEdgeUpdate.exe File opened for modification C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData MicrosoftEdgeUpdate.exe File opened for modification C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04 MicrosoftEdgeUpdate.exe File opened for modification C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04 MicrosoftEdgeUpdate.exe -
Event Triggered Execution: Component Object Model Hijacking 1 TTPs
Adversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM) objects.
-
Checks installed software on the system 1 TTPs
Looks up Uninstall key entries in the registry to enumerate software on the system.
-
Checks system information in the registry 2 TTPs 20 IoCs
System information is often read in order to detect sandboxing environments.
Processes:
MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exemsedgewebview2.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exedescription ioc process Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer MicrosoftEdgeUpdate.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer MicrosoftEdgeUpdate.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer MicrosoftEdgeUpdate.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName MicrosoftEdgeUpdate.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName MicrosoftEdgeUpdate.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer msedgewebview2.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName MicrosoftEdgeUpdate.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer MicrosoftEdgeUpdate.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName MicrosoftEdgeUpdate.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName MicrosoftEdgeUpdate.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName MicrosoftEdgeUpdate.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer MicrosoftEdgeUpdate.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer MicrosoftEdgeUpdate.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer MicrosoftEdgeUpdate.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer MicrosoftEdgeUpdate.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName MicrosoftEdgeUpdate.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName MicrosoftEdgeUpdate.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName msedgewebview2.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemManufacturer MicrosoftEdgeUpdate.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\SystemInformation\SystemProductName MicrosoftEdgeUpdate.exe -
Drops file in Program Files directory 64 IoCs
Processes:
RobloxStudioInstaller (2).exeMicrosoftEdgeUpdateSetup_X86_1.3.187.41.exedescription ioc process File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\studio_svg_textures\Lua\StyleEditor\Dark\Standard\[email protected] RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\studio_svg_textures\Shared\InsertableObjects\Dark\Standard\[email protected] RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\studio_svg_textures\Shared\InsertableObjects\Light\Standard\GroundController.png RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\scripts\CoreScripts\Modules\ErrorTestSets.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\scripts\CoreScripts\Modules\Settings\Pages\ShareGamePlaceholderPage.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\scripts\CoreScripts\Modules\VoiceChatPrompt\Components\VoiceChatPromptFrame.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Packages\_Index\UIBlox\UIBlox\App\SelectionCursor\Cursors\AnimatedGradient.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\textures\transformTwentyTwoDegrees.png RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\studio_svg_textures\Shared\Alerts\Dark\Standard\[email protected] RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\studio_svg_textures\Shared\Ribbon\Dark\Standard\RibbonNotificationMuteSmall.png RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\scripts\CoreScripts\Modules\Flags\GetFFlagDisableChromeFollowupFTUX.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\scripts\CoreScripts\Modules\InGameMenu\Components\App.spec.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Packages\_Index\Rhodium\Rhodium\VirtualInput.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Workspace\Packages\_Workspace\ExperienceService\SharedFlags.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Workspace\Packages\_Workspace\TenFootUiShell\LinkingProtocol.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\textures\TerrainTools\radio_button_frame.png RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\textures\ui\Controls\xboxLB.png RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\avatar\meshes\leftarm.mesh RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\studio_svg_textures\Shared\InsertableObjects\Dark\Standard\[email protected] RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\studio_svg_textures\Shared\Ribbon\Dark\Medium\RibbonConstraint_Spring.png RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Packages\_Index\PrettyFormat-2.4.1\PrettyFormat\plugins\ReactElement.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Packages\_Index\RoduxGames-ffcfa086-ca9547e2\RoduxGames\Reducers\Games\playabilityByGameId.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\Qml\QtQuick\Controls\Styles\Base\BasicTableViewStyle.qml RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\Qml\QtQuick\Controls.2\Material\SwipeView.qml RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\fonts\families\Oswald.json RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\studio_svg_textures\Shared\InsertableObjects\Dark\Standard\[email protected] RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\studio_svg_textures\Shared\InsertableObjects\Light\Standard\[email protected] RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\msvcp140_2.dll RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\scripts\CoreScripts\Modules\TrustAndSafety\Components\ReportAnything\ScreenshotDialog.spec.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Packages\_Index\RoduxPresence-fc5b9ccb-dc416d59\Cryo.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Workspace\Packages\_Workspace\GameInvite\Promise.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Workspace\Packages\_Workspace\IdentityProtocol\Promise.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Workspace\Packages\_Workspace\TenFootUiTesting\Localization.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\scripts\PlayerScripts\StarterPlayerScripts_old\CameraScript\RootCamera\VRCamera.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Packages\_Index\JestCircus\JestCircus\circus\legacy-code-todo-rewrite\temporarySnapshotData.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Packages\_Index\llama\llama\Dictionary\includes.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Packages\_Index\llama\llama\Set\intersect.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Packages\_Index\RoduxNetworking\RoduxNetworking\Action.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Packages\_Index\UIBlox\UIBlox\App\Tile\ItemTile\ItemTileStatus.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Workspace\Packages\_Workspace\AppChat\AppChatNetworking.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\textures\ui\TopBar\[email protected] RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\studio_svg_textures\Shared\InsertableObjects\Dark\Standard\SpecialMesh.png RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\studio_svg_textures\Shared\InsertableObjects\Light\Large\[email protected] RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\textures\ui\Controls\DesignSystem\[email protected] RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\studio_svg_textures\Shared\Ribbon\Light\Standard\[email protected] RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\scripts\CoreScripts\Modules\PurchasePrompt\Thunks\initiatePurchasePrecheck.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\Qml\QtQuick\Controls.2\designer\images\toolseparator-icon.png RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\studio_svg_textures\Lua\Notifications\Light\Large\[email protected] RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\studio_svg_textures\Shared\InsertableObjects\Dark\Standard\[email protected] RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Packages\_Index\IAPExperience\IAPExperience\Generic\PurchaseErrorType.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Microsoft\Temp\EUDA1B.tmp\msedgeupdateres_lo.dll MicrosoftEdgeUpdateSetup_X86_1.3.187.41.exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\Qml\QtQuick\Dialogs\images\crosshairs.png RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\BuiltInPlugins\DepFiles\AssetImporter.d RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Packages\_Index\LuauPolyfill-0.4.2\LuauPolyfill\Array\map.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Workspace\Packages\_Workspace\Squads\Dev\Rhodium.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Microsoft\Temp\EUDA1B.tmp\msedgeupdateres_de.dll MicrosoftEdgeUpdateSetup_X86_1.3.187.41.exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\studio_svg_textures\Shared\InsertableObjects\Dark\Standard\[email protected] RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Packages\_Index\roblox_genericpagination\genericpagination\inspect.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Workspace\Packages\_Workspace\ProfilePlatform\Dev\RobloxAppUIBloxConfig.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\textures\PluginManagement\allowed.png RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\studio_svg_textures\Shared\InsertableObjects\Light\Standard\[email protected] RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Packages\_Index\Console\lock.toml RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\ExtraContent\LuaPackages\Workspace\Packages\_Workspace\AppBlox\React.lua RobloxStudioInstaller (2).exe File created C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\content\textures\9SliceEditor\[email protected] RobloxStudioInstaller (2).exe -
Executes dropped EXE 49 IoCs
Processes:
MicrosoftEdgeWebview2Setup.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdge_X64_126.0.2592.87.exesetup.exesetup.exeMicrosoftEdgeUpdate.exeRobloxStudioBeta.exeRobloxCrashHandler.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdateSetup_X86_1.3.187.41.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exeRobloxStudioBeta.exeRobloxCrashHandler.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exepid process 1504 MicrosoftEdgeWebview2Setup.exe 2164 MicrosoftEdgeUpdate.exe 2792 MicrosoftEdgeUpdate.exe 4100 MicrosoftEdgeUpdate.exe 2476 MicrosoftEdgeUpdateComRegisterShell64.exe 2860 MicrosoftEdgeUpdateComRegisterShell64.exe 4688 MicrosoftEdgeUpdateComRegisterShell64.exe 4752 MicrosoftEdgeUpdate.exe 4464 MicrosoftEdgeUpdate.exe 1356 MicrosoftEdgeUpdate.exe 2152 MicrosoftEdgeUpdate.exe 648 MicrosoftEdge_X64_126.0.2592.87.exe 3776 setup.exe 4348 setup.exe 4064 MicrosoftEdgeUpdate.exe 4960 RobloxStudioBeta.exe 1104 RobloxCrashHandler.exe 4472 msedgewebview2.exe 3020 msedgewebview2.exe 3316 msedgewebview2.exe 4560 msedgewebview2.exe 5036 msedgewebview2.exe 3440 msedgewebview2.exe 4384 msedgewebview2.exe 624 msedgewebview2.exe 920 msedgewebview2.exe 5080 msedgewebview2.exe 2632 msedgewebview2.exe 1708 msedgewebview2.exe 2508 msedgewebview2.exe 4500 msedgewebview2.exe 4412 msedgewebview2.exe 2420 msedgewebview2.exe 2152 msedgewebview2.exe 3308 MicrosoftEdgeUpdate.exe 3812 MicrosoftEdgeUpdate.exe 2892 MicrosoftEdgeUpdateSetup_X86_1.3.187.41.exe 2540 MicrosoftEdgeUpdate.exe 5048 MicrosoftEdgeUpdate.exe 4696 MicrosoftEdgeUpdate.exe 4408 MicrosoftEdgeUpdate.exe 3640 MicrosoftEdgeUpdateComRegisterShell64.exe 1020 MicrosoftEdgeUpdateComRegisterShell64.exe 4240 MicrosoftEdgeUpdateComRegisterShell64.exe 3444 MicrosoftEdgeUpdate.exe 5668 RobloxStudioBeta.exe 2916 RobloxCrashHandler.exe 8364 MicrosoftEdgeUpdate.exe 8488 MicrosoftEdgeUpdate.exe -
Loads dropped DLL 64 IoCs
Processes:
MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeRobloxStudioBeta.exeRobloxCrashHandler.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exemsedgewebview2.exepid process 2164 MicrosoftEdgeUpdate.exe 2476 MicrosoftEdgeUpdateComRegisterShell64.exe 4100 MicrosoftEdgeUpdate.exe 2860 MicrosoftEdgeUpdateComRegisterShell64.exe 4100 MicrosoftEdgeUpdate.exe 4688 MicrosoftEdgeUpdateComRegisterShell64.exe 4100 MicrosoftEdgeUpdate.exe 1356 MicrosoftEdgeUpdate.exe 4464 MicrosoftEdgeUpdate.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 1104 RobloxCrashHandler.exe 1104 RobloxCrashHandler.exe 1104 RobloxCrashHandler.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4472 msedgewebview2.exe 3020 msedgewebview2.exe 4472 msedgewebview2.exe 4472 msedgewebview2.exe 3316 msedgewebview2.exe 3316 msedgewebview2.exe 4560 msedgewebview2.exe 5036 msedgewebview2.exe 4560 msedgewebview2.exe 5036 msedgewebview2.exe 3316 msedgewebview2.exe 3316 msedgewebview2.exe 3316 msedgewebview2.exe 3316 msedgewebview2.exe 3440 msedgewebview2.exe 3440 msedgewebview2.exe 3440 msedgewebview2.exe 4384 msedgewebview2.exe 4384 msedgewebview2.exe 4384 msedgewebview2.exe 624 msedgewebview2.exe 624 msedgewebview2.exe 624 msedgewebview2.exe 4472 msedgewebview2.exe 4472 msedgewebview2.exe 4472 msedgewebview2.exe 920 msedgewebview2.exe 920 msedgewebview2.exe 5080 msedgewebview2.exe -
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Checks SCSI registry key(s) 3 TTPs 4 IoCs
SCSI information is often read in order to detect sandboxing environments.
Processes:
GamePanel.exedescription ioc process Key opened \REGISTRY\MACHINE\SYSTEM\ControlSet001\Enum\SCSI\CDROM&VEN_QEMU&PROD_QEMU_DVD-ROM\4&215468A5&0&010000 GamePanel.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Enum\SCSI\CdRom&Ven_QEMU&Prod_QEMU_DVD-ROM\4&215468a5&0&010000\ConfigFlags GamePanel.exe Key opened \REGISTRY\MACHINE\SYSTEM\ControlSet001\Enum\SCSI\DISK&VEN_QEMU&PROD_HARDDISK\4&215468A5&0&000000 GamePanel.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Enum\SCSI\Disk&Ven_QEMU&Prod_HARDDISK\4&215468a5&0&000000\ConfigFlags GamePanel.exe -
Checks processor information in registry 2 TTPs 5 IoCs
Processor information is often read in order to detect sandboxing environments.
Processes:
firefox.exedescription ioc process Key opened \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0 firefox.exe Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Update Signature firefox.exe Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\Update Revision firefox.exe Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\~Mhz firefox.exe Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0\VendorIdentifier firefox.exe -
Enumerates system info in registry 2 TTPs 7 IoCs
Processes:
RobloxStudioBeta.exemsedgewebview2.exeRobloxStudioBeta.exedescription ioc process Key opened \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\BIOS RobloxStudioBeta.exe Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\BIOS\BaseBoardManufacturer RobloxStudioBeta.exe Key opened \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\BIOS msedgewebview2.exe Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\BIOS\SystemProductName msedgewebview2.exe Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\BIOS\SystemManufacturer msedgewebview2.exe Key opened \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\BIOS RobloxStudioBeta.exe Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\BIOS\BaseBoardManufacturer RobloxStudioBeta.exe -
Processes:
RobloxStudioInstaller (2).exedescription ioc process Key created \REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\ProtocolExecute\roblox-studio RobloxStudioInstaller (2).exe Set value (int) \REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\ProtocolExecute\roblox-studio\WarnOnOpen = "0" RobloxStudioInstaller (2).exe Key created \REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\ProtocolExecute\roblox-studio-auth RobloxStudioInstaller (2).exe Set value (int) \REGISTRY\MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\ProtocolExecute\roblox-studio-auth\WarnOnOpen = "0" RobloxStudioInstaller (2).exe -
Modifies data under HKEY_USERS 64 IoCs
Processes:
MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exemsedgewebview2.exedescription ioc process Key created \REGISTRY\USER\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\trust\CTLs MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix = "Visited:" MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\CTLs MicrosoftEdgeUpdate.exe Set value (int) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName = "1" MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\trust\CRLs MicrosoftEdgeUpdate.exe Set value (data) \REGISTRY\USER\.DEFAULT\Software\Classes\Local Settings\MuiCache\1a\52C64B7E\LanguageList = 65006e002d0055005300000065006e0000000000 MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing MicrosoftEdgeUpdate.exe Set value (int) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass = "1" MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\OnDemandInterfaceCache MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\Root\CRLs MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed\Certificates MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\windows\CurrentVersion\Internet Settings MicrosoftEdgeUpdate.exe Set value (int) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect = "0" MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\CRLs MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\Root MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix = "Visited:" MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\Root\CTLs MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\Root\CRLs MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\CA\Certificates MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA\CTLs MicrosoftEdgeUpdate.exe Set value (int) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect = "0" MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\CA\CRLs MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople MicrosoftEdgeUpdate.exe Set value (int) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet = "1" MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix = "Cookie:" MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\OnDemandInterfaceCache MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix = "Cookie:" MicrosoftEdgeUpdate.exe Set value (int) \REGISTRY\USER\S-1-5-19\Software\Microsoft\Cryptography\TPM\Telemetry\TraceTimeLast = "133644344538509791" msedgewebview2.exe Set value (int) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass = "1" MicrosoftEdgeUpdate.exe Set value (int) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet = "1" MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\OnDemandInterfaceCache MicrosoftEdgeUpdate.exe Set value (data) \REGISTRY\USER\.DEFAULT\Software\Classes\Local Settings\MuiCache\1a\52C64B7E\LanguageList = 65006e002d0055005300000065006e0000000000 MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\trust\Certificates MicrosoftEdgeUpdate.exe Set value (int) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass = "1" MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\CA MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\Root MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\trust\CTLs MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\Certificates MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\CTLs MicrosoftEdgeUpdate.exe Set value (data) \REGISTRY\USER\.DEFAULT\Software\Classes\Local Settings\MuiCache\1a\52C64B7E\LanguageList = 65006e002d0055005300000065006e0000000000 MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\Root\Certificates MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust\CRLs MicrosoftEdgeUpdate.exe Set value (int) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MigrateProxy = "1" MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\Root\CTLs MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\Root\Certificates MicrosoftEdgeUpdate.exe Key created \REGISTRY\USER\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs MicrosoftEdgeUpdate.exe Set value (int) \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName = "1" MicrosoftEdgeUpdate.exe -
Modifies registry class 64 IoCs
Processes:
MicrosoftEdgeUpdate.exeMicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdateComRegisterShell64.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exedescription ioc process Key created \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{7584D24A-E056-4EB1-8E7B-632F2B0ADC69}\ProxyStubClsid32 MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{AB4F4A7E-977C-4E23-AD8F-626A491715DF}\NumMethods\ = "41" MicrosoftEdgeUpdateComRegisterShell64.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{3805CA06-AC83-4F00-8A02-271DCD89BDEB}\NumMethods\ = "27" MicrosoftEdgeUpdateComRegisterShell64.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{AB4F4A7E-977C-4E23-AD8F-626A491715DF} MicrosoftEdgeUpdateComRegisterShell64.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{C853632E-36CA-4999-B992-EC0D408CF5AB}\NumMethods MicrosoftEdgeUpdateComRegisterShell64.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{2EC826CB-5478-4533-9015-7580B3B5E03A}\ProxyStubClsid32 MicrosoftEdgeUpdateComRegisterShell64.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\MicrosoftEdgeUpdate.PolicyStatusMachine\CurVer\ = "MicrosoftEdgeUpdate.PolicyStatusMachine.1.0" MicrosoftEdgeUpdate.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{177CAE89-4AD6-42F4-A458-00EC3389E3FE}\NumMethods MicrosoftEdgeUpdateComRegisterShell64.exe Set value (int) \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{492E1C30-A1A2-4695-87C8-7A8CAD6F936F}\Elevation\Enabled = "1" MicrosoftEdgeUpdate.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\MicrosoftEdgeUpdate.ProcessLauncher\CurVer MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{5F6A18BB-6231-424B-8242-19E5BB94F8ED}\ = "Microsoft Edge Update CredentialDialog" MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{C853632E-36CA-4999-B992-EC0D408CF5AB}\ = "IPackage" MicrosoftEdgeUpdateComRegisterShell64.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{DDD4B5D4-FD54-497C-8789-0830F29A60EE}\NumMethods MicrosoftEdgeUpdateComRegisterShell64.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{A6556DFF-AB15-4DC3-A890-AB54120BEAEC} MicrosoftEdgeUpdateComRegisterShell64.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{D1E8B1A6-32CE-443C-8E2E-EBA90C481353}\LocalizedString = "@C:\\Program Files (x86)\\Microsoft\\EdgeUpdate\\1.3.187.41\\msedgeupdate.dll,-3000" MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{F7B3738C-9BCA-4B14-90B7-89D0F3A3E497}\ProxyStubClsid32\ = "{8B15189E-5465-4166-933D-1EABAD9648CB}" MicrosoftEdgeUpdateComRegisterShell64.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{A5135E58-384F-4244-9A5F-30FA9259413C}\NumMethods MicrosoftEdgeUpdateComRegisterShell64.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{7B3B7A69-7D88-4847-A6BC-90E246A41F69}\ProxyStubClsid32\ = "{0DD41A78-E3D4-44A8-9EAE-697BCF1781A3}" MicrosoftEdgeUpdateComRegisterShell64.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{E55B90F1-DA33-400B-B09E-3AFF7D46BD83}\ProxyStubClsid32 MicrosoftEdgeUpdateComRegisterShell64.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{D9AA3288-4EA7-4E67-AE60-D18EADCB923D}\ = "IJobObserver2" MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{F7B3738C-9BCA-4B14-90B7-89D0F3A3E497}\NumMethods\ = "26" MicrosoftEdgeUpdate.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{9A6B447A-35E2-4F6B-A87B-5DEEBBFDAD17}\NumMethods MicrosoftEdgeUpdateComRegisterShell64.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{8B15189E-5465-4166-933D-1EABAD9648CB}\InProcServer32\ThreadingModel = "Both" MicrosoftEdgeUpdateComRegisterShell64.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{177CAE89-4AD6-42F4-A458-00EC3389E3FE}\NumMethods\ = "24" MicrosoftEdgeUpdateComRegisterShell64.exe Key deleted \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{E3D94CEB-EC11-46BE-8872-7DDCE37FABFA} MicrosoftEdgeUpdateComRegisterShell64.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0DD41A78-E3D4-44A8-9EAE-697BCF1781A3}\InProcServer32\ = "C:\\Program Files (x86)\\Microsoft\\EdgeUpdate\\1.3.187.41\\psmachine.dll" MicrosoftEdgeUpdate.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{2603C88B-F971-4167-9DE1-871EE4A3DC84}\ProxyStubClsid32 MicrosoftEdgeUpdateComRegisterShell64.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{E421557C-0628-43FB-BF2B-7C9F8A4D067C}\LocalServer32 MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{77857D02-7A25-4B67-9266-3E122A8F39E4}\ = "Google Update Policy Status Class" MicrosoftEdgeUpdate.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{79E0C401-B7BC-4DE5-8104-71350F3A9B67} MicrosoftEdgeUpdateComRegisterShell64.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{A5135E58-384F-4244-9A5F-30FA9259413C}\ = "IProcessLauncher" MicrosoftEdgeUpdate.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{3E102DC6-1EDB-46A1-8488-61F71B35ED5F}\NumMethods MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{5F6A18BB-6231-424B-8242-19E5BB94F8ED}\VersionIndependentProgID\ = "MicrosoftEdgeUpdate.CredentialDialogMachine" MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{7B3B7A69-7D88-4847-A6BC-90E246A41F69}\ProxyStubClsid32\ = "{8B15189E-5465-4166-933D-1EABAD9648CB}" MicrosoftEdgeUpdateComRegisterShell64.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\MicrosoftEdgeUpdate.ProcessLauncher\CurVer\ = "MicrosoftEdgeUpdate.ProcessLauncher.1.0" MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\MicrosoftEdgeUpdate.Update3WebMachineFallback\CurVer\ = "MicrosoftEdgeUpdate.Update3WebMachineFallback.1.0" MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{77857D02-7A25-4B67-9266-3E122A8F39E4}\Elevation\IconReference = "@C:\\Program Files (x86)\\Microsoft\\EdgeUpdate\\1.3.171.39\\msedgeupdate.dll,-1004" MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{3A49F783-1C7D-4D35-8F63-5C1C206B9B6E}\ProxyStubClsid32\ = "{8B15189E-5465-4166-933D-1EABAD9648CB}" MicrosoftEdgeUpdateComRegisterShell64.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{AB4F4A7E-977C-4E23-AD8F-626A491715DF}\ = "IAppBundle" MicrosoftEdgeUpdateComRegisterShell64.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{E3D94CEB-EC11-46BE-8872-7DDCE37FABFA} MicrosoftEdgeUpdateComRegisterShell64.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\AppID\{A6B716CB-028B-404D-B72C-50E153DD68DA}\ = "ServiceModule" MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{AB4F4A7E-977C-4E23-AD8F-626A491715DF}\NumMethods\ = "41" MicrosoftEdgeUpdateComRegisterShell64.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{C06EE550-7248-488E-971E-B60C0AB3A6E4}\NumMethods MicrosoftEdgeUpdate.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{2EC826CB-5478-4533-9015-7580B3B5E03A}\NumMethods MicrosoftEdgeUpdateComRegisterShell64.exe Set value (int) \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{E421557C-0628-43FB-BF2B-7C9F8A4D067C}\Elevation\Enabled = "1" MicrosoftEdgeUpdate.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID\{8B15189E-5465-4166-933D-1EABAD9648CB} MicrosoftEdgeUpdateComRegisterShell64.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{AB4EE1FC-0A81-4F56-B0E2-248FB78051AF}\ProxyStubClsid32\ = "{8B15189E-5465-4166-933D-1EABAD9648CB}" MicrosoftEdgeUpdateComRegisterShell64.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{DDD4B5D4-FD54-497C-8789-0830F29A60EE} MicrosoftEdgeUpdateComRegisterShell64.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{7B3B7A69-7D88-4847-A6BC-90E246A41F69}\ = "IAppVersion" MicrosoftEdgeUpdateComRegisterShell64.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{7E29BE61-5809-443F-9B5D-CF22156694EB}\NumMethods\ = "12" MicrosoftEdgeUpdateComRegisterShell64.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{FF419FF9-90BE-4D9F-B410-A789F90E5A7C}\ProgID MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{60355531-5BFD-45AB-942C-7912628752C7}\ = "IPolicyStatus3" MicrosoftEdgeUpdateComRegisterShell64.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{60355531-5BFD-45AB-942C-7912628752C7}\ProxyStubClsid32 MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{F7B3738C-9BCA-4B14-90B7-89D0F3A3E497}\ = "IPolicyStatus4" MicrosoftEdgeUpdate.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{C20433B3-0D4B-49F6-9B6C-6EE0FAE07837} MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{450CF5FF-95C4-4679-BECA-22680389ECB9}\NumMethods\ = "10" MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{492E1C30-A1A2-4695-87C8-7A8CAD6F936F}\VersionIndependentProgID\ = "MicrosoftEdgeUpdate.Update3WebMachine" MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{A5135E58-384F-4244-9A5F-30FA9259413C}\NumMethods\ = "6" MicrosoftEdgeUpdateComRegisterShell64.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{AB4F4A7E-977C-4E23-AD8F-626A491715DF}\ = "IAppBundle" MicrosoftEdgeUpdateComRegisterShell64.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\MicrosoftEdgeUpdate.CoreMachineClass.1\CLSID\ = "{2E1DD7EF-C12D-4F8E-8AD8-CF8CC265BAD0}" MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{8F09CD6C-5964-4573-82E3-EBFF7702865B}\AppID = "{A6B716CB-028B-404D-B72C-50E153DD68DA}" MicrosoftEdgeUpdate.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{D9AA3288-4EA7-4E67-AE60-D18EADCB923D}\ = "IJobObserver2" MicrosoftEdgeUpdateComRegisterShell64.exe Key created \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{FEA2518F-758F-4B95-A59F-97FCEEF1F5D0} MicrosoftEdgeUpdateComRegisterShell64.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Classes\Interface\{2EC826CB-5478-4533-9015-7580B3B5E03A}\ProxyStubClsid32\ = "{0DD41A78-E3D4-44A8-9EAE-697BCF1781A3}" MicrosoftEdgeUpdateComRegisterShell64.exe -
Suspicious behavior: AddClipboardFormatListener 2 IoCs
Processes:
RobloxStudioBeta.exeRobloxStudioBeta.exepid process 4960 RobloxStudioBeta.exe 5668 RobloxStudioBeta.exe -
Suspicious behavior: EnumeratesProcesses 64 IoCs
Processes:
RobloxStudioInstaller (2).exeMicrosoftEdgeUpdate.exeRobloxStudioBeta.exepid process 2912 RobloxStudioInstaller (2).exe 2912 RobloxStudioInstaller (2).exe 2164 MicrosoftEdgeUpdate.exe 2164 MicrosoftEdgeUpdate.exe 2164 MicrosoftEdgeUpdate.exe 2164 MicrosoftEdgeUpdate.exe 2164 MicrosoftEdgeUpdate.exe 2164 MicrosoftEdgeUpdate.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe 4960 RobloxStudioBeta.exe -
Suspicious behavior: GetForegroundWindowSpam 2 IoCs
Processes:
RobloxStudioBeta.exeRobloxStudioBeta.exepid process 4960 RobloxStudioBeta.exe 5668 RobloxStudioBeta.exe -
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary 3 IoCs
Processes:
msedgewebview2.exepid process 4472 msedgewebview2.exe 4472 msedgewebview2.exe 4472 msedgewebview2.exe -
Suspicious use of AdjustPrivilegeToken 14 IoCs
Processes:
MicrosoftEdgeUpdate.exeAUDIODG.EXEMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exefirefox.exeMicrosoftEdgeUpdate.exedescription pid process Token: SeDebugPrivilege 2164 MicrosoftEdgeUpdate.exe Token: SeDebugPrivilege 2164 MicrosoftEdgeUpdate.exe Token: 33 4540 AUDIODG.EXE Token: SeIncBasePriorityPrivilege 4540 AUDIODG.EXE Token: SeDebugPrivilege 3308 MicrosoftEdgeUpdate.exe Token: SeDebugPrivilege 3812 MicrosoftEdgeUpdate.exe Token: SeDebugPrivilege 5048 MicrosoftEdgeUpdate.exe Token: SeDebugPrivilege 2976 firefox.exe Token: SeDebugPrivilege 2976 firefox.exe Token: SeDebugPrivilege 2976 firefox.exe Token: SeDebugPrivilege 2976 firefox.exe Token: SeDebugPrivilege 2976 firefox.exe Token: SeDebugPrivilege 2976 firefox.exe Token: SeDebugPrivilege 8364 MicrosoftEdgeUpdate.exe -
Suspicious use of FindShellTrayWindow 4 IoCs
Processes:
firefox.exepid process 2976 firefox.exe 2976 firefox.exe 2976 firefox.exe 2976 firefox.exe -
Suspicious use of SendNotifyMessage 3 IoCs
Processes:
firefox.exepid process 2976 firefox.exe 2976 firefox.exe 2976 firefox.exe -
Suspicious use of SetWindowsHookEx 15 IoCs
Processes:
RobloxStudioBeta.exefirefox.exeRobloxStudioBeta.exepid process 4960 RobloxStudioBeta.exe 2976 firefox.exe 2976 firefox.exe 2976 firefox.exe 2976 firefox.exe 2976 firefox.exe 2976 firefox.exe 2976 firefox.exe 5668 RobloxStudioBeta.exe 5668 RobloxStudioBeta.exe 5668 RobloxStudioBeta.exe 5668 RobloxStudioBeta.exe 5668 RobloxStudioBeta.exe 5668 RobloxStudioBeta.exe 5668 RobloxStudioBeta.exe -
Suspicious use of WriteProcessMemory 64 IoCs
Processes:
RobloxStudioInstaller (2).exeMicrosoftEdgeWebview2Setup.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdgeUpdate.exeMicrosoftEdge_X64_126.0.2592.87.exesetup.exeRobloxStudioBeta.exemsedgewebview2.exedescription pid process target process PID 2912 wrote to memory of 1504 2912 RobloxStudioInstaller (2).exe MicrosoftEdgeWebview2Setup.exe PID 2912 wrote to memory of 1504 2912 RobloxStudioInstaller (2).exe MicrosoftEdgeWebview2Setup.exe PID 2912 wrote to memory of 1504 2912 RobloxStudioInstaller (2).exe MicrosoftEdgeWebview2Setup.exe PID 1504 wrote to memory of 2164 1504 MicrosoftEdgeWebview2Setup.exe MicrosoftEdgeUpdate.exe PID 1504 wrote to memory of 2164 1504 MicrosoftEdgeWebview2Setup.exe MicrosoftEdgeUpdate.exe PID 1504 wrote to memory of 2164 1504 MicrosoftEdgeWebview2Setup.exe MicrosoftEdgeUpdate.exe PID 2164 wrote to memory of 2792 2164 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdate.exe PID 2164 wrote to memory of 2792 2164 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdate.exe PID 2164 wrote to memory of 2792 2164 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdate.exe PID 2164 wrote to memory of 4100 2164 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdate.exe PID 2164 wrote to memory of 4100 2164 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdate.exe PID 2164 wrote to memory of 4100 2164 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdate.exe PID 4100 wrote to memory of 2476 4100 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdateComRegisterShell64.exe PID 4100 wrote to memory of 2476 4100 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdateComRegisterShell64.exe PID 4100 wrote to memory of 2860 4100 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdateComRegisterShell64.exe PID 4100 wrote to memory of 2860 4100 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdateComRegisterShell64.exe PID 4100 wrote to memory of 4688 4100 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdateComRegisterShell64.exe PID 4100 wrote to memory of 4688 4100 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdateComRegisterShell64.exe PID 2164 wrote to memory of 4752 2164 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdate.exe PID 2164 wrote to memory of 4752 2164 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdate.exe PID 2164 wrote to memory of 4752 2164 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdate.exe PID 2164 wrote to memory of 4464 2164 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdate.exe PID 2164 wrote to memory of 4464 2164 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdate.exe PID 2164 wrote to memory of 4464 2164 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdate.exe PID 1356 wrote to memory of 2152 1356 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdate.exe PID 1356 wrote to memory of 2152 1356 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdate.exe PID 1356 wrote to memory of 2152 1356 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdate.exe PID 1356 wrote to memory of 648 1356 MicrosoftEdgeUpdate.exe MicrosoftEdge_X64_126.0.2592.87.exe PID 1356 wrote to memory of 648 1356 MicrosoftEdgeUpdate.exe MicrosoftEdge_X64_126.0.2592.87.exe PID 648 wrote to memory of 3776 648 MicrosoftEdge_X64_126.0.2592.87.exe setup.exe PID 648 wrote to memory of 3776 648 MicrosoftEdge_X64_126.0.2592.87.exe setup.exe PID 3776 wrote to memory of 4348 3776 setup.exe setup.exe PID 3776 wrote to memory of 4348 3776 setup.exe setup.exe PID 1356 wrote to memory of 4064 1356 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdate.exe PID 1356 wrote to memory of 4064 1356 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdate.exe PID 1356 wrote to memory of 4064 1356 MicrosoftEdgeUpdate.exe MicrosoftEdgeUpdate.exe PID 2912 wrote to memory of 4960 2912 RobloxStudioInstaller (2).exe RobloxStudioBeta.exe PID 2912 wrote to memory of 4960 2912 RobloxStudioInstaller (2).exe RobloxStudioBeta.exe PID 4960 wrote to memory of 1104 4960 RobloxStudioBeta.exe RobloxCrashHandler.exe PID 4960 wrote to memory of 1104 4960 RobloxStudioBeta.exe RobloxCrashHandler.exe PID 4960 wrote to memory of 4472 4960 RobloxStudioBeta.exe msedgewebview2.exe PID 4960 wrote to memory of 4472 4960 RobloxStudioBeta.exe msedgewebview2.exe PID 4472 wrote to memory of 3020 4472 msedgewebview2.exe msedgewebview2.exe PID 4472 wrote to memory of 3020 4472 msedgewebview2.exe msedgewebview2.exe PID 4472 wrote to memory of 3316 4472 msedgewebview2.exe msedgewebview2.exe PID 4472 wrote to memory of 3316 4472 msedgewebview2.exe msedgewebview2.exe PID 4472 wrote to memory of 3316 4472 msedgewebview2.exe msedgewebview2.exe PID 4472 wrote to memory of 3316 4472 msedgewebview2.exe msedgewebview2.exe PID 4472 wrote to memory of 3316 4472 msedgewebview2.exe msedgewebview2.exe PID 4472 wrote to memory of 3316 4472 msedgewebview2.exe msedgewebview2.exe PID 4472 wrote to memory of 3316 4472 msedgewebview2.exe msedgewebview2.exe PID 4472 wrote to memory of 3316 4472 msedgewebview2.exe msedgewebview2.exe PID 4472 wrote to memory of 3316 4472 msedgewebview2.exe msedgewebview2.exe PID 4472 wrote to memory of 3316 4472 msedgewebview2.exe msedgewebview2.exe PID 4472 wrote to memory of 3316 4472 msedgewebview2.exe msedgewebview2.exe PID 4472 wrote to memory of 3316 4472 msedgewebview2.exe msedgewebview2.exe PID 4472 wrote to memory of 3316 4472 msedgewebview2.exe msedgewebview2.exe PID 4472 wrote to memory of 3316 4472 msedgewebview2.exe msedgewebview2.exe PID 4472 wrote to memory of 3316 4472 msedgewebview2.exe msedgewebview2.exe PID 4472 wrote to memory of 3316 4472 msedgewebview2.exe msedgewebview2.exe PID 4472 wrote to memory of 3316 4472 msedgewebview2.exe msedgewebview2.exe PID 4472 wrote to memory of 3316 4472 msedgewebview2.exe msedgewebview2.exe PID 4472 wrote to memory of 3316 4472 msedgewebview2.exe msedgewebview2.exe PID 4472 wrote to memory of 3316 4472 msedgewebview2.exe msedgewebview2.exe -
System policy modification 1 TTPs 1 IoCs
Processes:
msedgewebview2.exedescription ioc process Key created \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\DataCollection msedgewebview2.exe -
Uses Task Scheduler COM API 1 TTPs
The Task Scheduler COM API can be used to schedule applications to run on boot or at set times.
Processes
-
C:\Users\Admin\AppData\Local\Temp\RobloxStudioInstaller (2).exe"C:\Users\Admin\AppData\Local\Temp\RobloxStudioInstaller (2).exe"1⤵
- Checks whether UAC is enabled
- Drops file in Program Files directory
- Modifies Internet Explorer settings
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of WriteProcessMemory
-
C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\WebView2RuntimeInstaller\MicrosoftEdgeWebview2Setup.exeMicrosoftEdgeWebview2Setup.exe /silent /install2⤵
- Executes dropped EXE
- Suspicious use of WriteProcessMemory
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\MicrosoftEdgeUpdate.exe"C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\MicrosoftEdgeUpdate.exe" /silent /install "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers"3⤵
- Event Triggered Execution: Image File Execution Options Injection
- Checks system information in the registry
- Executes dropped EXE
- Loads dropped DLL
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regsvc4⤵
- Executes dropped EXE
- Modifies registry class
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserver4⤵
- Executes dropped EXE
- Loads dropped DLL
- Modifies registry class
- Suspicious use of WriteProcessMemory
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.171.39\MicrosoftEdgeUpdateComRegisterShell64.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.171.39\MicrosoftEdgeUpdateComRegisterShell64.exe"5⤵
- Executes dropped EXE
- Loads dropped DLL
- Modifies registry class
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.171.39\MicrosoftEdgeUpdateComRegisterShell64.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.171.39\MicrosoftEdgeUpdateComRegisterShell64.exe"5⤵
- Executes dropped EXE
- Loads dropped DLL
- Modifies registry class
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.171.39\MicrosoftEdgeUpdateComRegisterShell64.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.171.39\MicrosoftEdgeUpdateComRegisterShell64.exe"5⤵
- Executes dropped EXE
- Loads dropped DLL
- Modifies registry class
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xNzEuMzkiIHNoZWxsX3ZlcnNpb249IjEuMy4xNzEuMzkiIGlzbWFjaGluZT0iMSIgc2Vzc2lvbmlkPSJ7RUEyNjQxNDctMjk4RS00QzVFLTg4QjEtRjE0QUQ3MTY1Qjg1fSIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiByZXF1ZXN0aWQ9IntFMTE3MjJFNy1ERTM5LTQwNEMtOTU1Ri01M0RDNjg1QkM4QjB9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iOCIgcGh5c21lbW9yeT0iOCIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE1MDYzLjAiIHNwPSIiIGFyY2g9Ing2NCIgcHJvZHVjdF90eXBlPSI0OCIgaXNfd2lwPSIwIi8-PG9lbSBwcm9kdWN0X21hbnVmYWN0dXJlcj0iUUVNVSIgcHJvZHVjdF9uYW1lPSJTdGFuZGFyZCBQQyAoUTM1ICsgSUNIOSwgMjAwOSkiLz48ZXhwIGV0YWc9IiIvPjxhcHAgYXBwaWQ9IntGM0M0RkUwMC1FRkQ1LTQwM0ItOTU2OS0zOThBMjBGMUJBNEF9IiB2ZXJzaW9uPSIiIG5leHR2ZXJzaW9uPSIxLjMuMTcxLjM5IiBsYW5nPSIiIGJyYW5kPSIiIGNsaWVudD0iIj48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSI1MDE5NDgzOTI3IiBpbnN0YWxsX3RpbWVfbXM9IjUxOSIvPjwvYXBwPjwvcmVxdWVzdD44⤵
- Checks system information in the registry
- Executes dropped EXE
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /handoff "appguid={F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}&appname=Microsoft%20Edge%20Webview2%20Runtime&needsadmin=prefers" /installsource otherinstallcmd /sessionid "{EA264147-298E-4C5E-88B1-F14AD7165B85}" /silent4⤵
- Executes dropped EXE
- Loads dropped DLL
-
C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\RobloxStudioBeta.exe"C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\RobloxStudioBeta.exe" -startEvent www.roblox.com/robloxQTStudioStartedEvent -firstLaunch2⤵
- Checks whether UAC is enabled
- Executes dropped EXE
- Loads dropped DLL
- Enumerates system info in registry
- Suspicious behavior: AddClipboardFormatListener
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: GetForegroundWindowSpam
- Suspicious use of SetWindowsHookEx
- Suspicious use of WriteProcessMemory
-
C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\RobloxCrashHandler.exe"C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\RobloxCrashHandler.exe" --no-rate-limit --crashCounter Win-ROBLOXStudio-Crash --baseUrl https://www.roblox.com --attachment=attachment_0.631.1.6310472_20240702T225404Z_Studio_A79F2_last.log=C:\Users\Admin\AppData\Local\Roblox\logs\0.631.1.6310472_20240702T225404Z_Studio_A79F2_last.log --attachment=attachment_log_0.631.1.6310472_20240702T225404Z_Studio_A79F2_csg3.log=C:\Users\Admin\AppData\Local\Roblox\logs\log_0.631.1.6310472_20240702T225404Z_Studio_A79F2_csg3.log --database=C:\Users\Admin\AppData\Local\Roblox\logs\crashes --metrics-dir=C:\Users\Admin\AppData\Local\Roblox\logs\crashes --url=https://upload.crashes.rbxinfra.com/post?format=minidump --annotation=AppVersion=0.631.1.6310472 --annotation=Format=minidump --annotation=HardwareModel= --annotation=HasBootstrapper=true --annotation=InstallFolder=ProgramFilesX86 --annotation=OSPlatform=Windows --annotation=RobloxChannel=production --annotation=RobloxGitHash=cb5e1ef861e0b94bbfd3c1c166285778889972be --annotation=RobloxProduct=RobloxStudio --annotation=StudioVersion=0.631.1.6310472 --annotation=UniqueId=8834379687577422141 --annotation=UseCrashpad=True --annotation=app_arch=x86_64 --annotation=application.version=0.631.1.6310472 --annotation=host_arch=x86_64 --initial-client-data=0x4e8,0x4ec,0x4f0,0x42c,0x4c4,0x7ff753b5e708,0x7ff753b5e720,0x7ff753b5e7383⤵
- Executes dropped EXE
- Loads dropped DLL
-
C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe"C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe" --embedded-browser-webview=1 --webview-exe-name=RobloxStudioBeta.exe --webview-exe-version="0, 631, 1, 6310472" --user-data-dir="C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView" --noerrdialogs --embedded-browser-webview-dpi-awareness=2 --enable-features=MojoIpcz --mojo-named-platform-channel-pipe=4960.1724.176499314752450964653⤵
- Checks computer location settings
- Checks system information in the registry
- Executes dropped EXE
- Loads dropped DLL
- Enumerates system info in registry
- Modifies data under HKEY_USERS
- Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
- Suspicious use of WriteProcessMemory
- System policy modification
-
C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe"C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe" --type=crashpad-handler --user-data-dir=C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Crashpad --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=126.0.6478.127 "--annotation=exe=C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe" --annotation=plat=Win64 "--annotation=prod=Edge WebView2" --annotation=ver=126.0.2592.87 --initial-client-data=0x7c,0x120,0x124,0x114,0x12c,0x7ffbd2f70148,0x7ffbd2f70154,0x7ffbd2f701604⤵
- Executes dropped EXE
- Loads dropped DLL
-
C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe"C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe" --type=gpu-process --noerrdialogs --user-data-dir="C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView" --webview-exe-name=RobloxStudioBeta.exe --webview-exe-version="0, 631, 1, 6310472" --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAEAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --field-trial-handle=1680,i,11487306248321944511,3766159634979059685,262144 --enable-features=MojoIpcz --variations-seed-version --mojo-platform-channel-handle=1676 /prefetch:24⤵
- Executes dropped EXE
- Loads dropped DLL
-
C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe"C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView" --webview-exe-name=RobloxStudioBeta.exe --webview-exe-version="0, 631, 1, 6310472" --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --field-trial-handle=1588,i,11487306248321944511,3766159634979059685,262144 --enable-features=MojoIpcz --variations-seed-version --mojo-platform-channel-handle=1816 /prefetch:34⤵
- Executes dropped EXE
- Loads dropped DLL
-
C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe"C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView" --webview-exe-name=RobloxStudioBeta.exe --webview-exe-version="0, 631, 1, 6310472" --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --field-trial-handle=1616,i,11487306248321944511,3766159634979059685,262144 --enable-features=MojoIpcz --variations-seed-version --mojo-platform-channel-handle=1972 /prefetch:84⤵
- Executes dropped EXE
- Loads dropped DLL
-
C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe"C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe" --type=renderer --noerrdialogs --user-data-dir="C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView" --webview-exe-name=RobloxStudioBeta.exe --webview-exe-version="0, 631, 1, 6310472" --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --lang=en-US --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=5 --js-flags="--harmony-weak-refs-with-cleanup-some --expose-gc --ms-user-locale=" --field-trial-handle=3248,i,11487306248321944511,3766159634979059685,262144 --enable-features=MojoIpcz --variations-seed-version --mojo-platform-channel-handle=3272 /prefetch:14⤵
- Checks computer location settings
- Executes dropped EXE
- Loads dropped DLL
-
C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe"C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe" --type=renderer --noerrdialogs --user-data-dir="C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView" --webview-exe-name=RobloxStudioBeta.exe --webview-exe-version="0, 631, 1, 6310472" --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --lang=en-US --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=6 --js-flags="--harmony-weak-refs-with-cleanup-some --expose-gc --ms-user-locale=" --field-trial-handle=3556,i,11487306248321944511,3766159634979059685,262144 --enable-features=MojoIpcz --variations-seed-version --mojo-platform-channel-handle=3532 /prefetch:14⤵
- Checks computer location settings
- Executes dropped EXE
- Loads dropped DLL
-
C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe"C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe" --type=renderer --noerrdialogs --user-data-dir="C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView" --webview-exe-name=RobloxStudioBeta.exe --webview-exe-version="0, 631, 1, 6310472" --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --lang=en-US --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=7 --js-flags="--harmony-weak-refs-with-cleanup-some --expose-gc --ms-user-locale=" --field-trial-handle=3272,i,11487306248321944511,3766159634979059685,262144 --enable-features=MojoIpcz --variations-seed-version --mojo-platform-channel-handle=3384 /prefetch:14⤵
- Checks computer location settings
- Executes dropped EXE
- Loads dropped DLL
-
C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe"C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView" --webview-exe-name=RobloxStudioBeta.exe --webview-exe-version="0, 631, 1, 6310472" --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --field-trial-handle=4700,i,11487306248321944511,3766159634979059685,262144 --enable-features=MojoIpcz --variations-seed-version --mojo-platform-channel-handle=4688 /prefetch:84⤵
- Executes dropped EXE
- Loads dropped DLL
-
C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe"C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView" --webview-exe-name=RobloxStudioBeta.exe --webview-exe-version="0, 631, 1, 6310472" --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --field-trial-handle=4724,i,11487306248321944511,3766159634979059685,262144 --enable-features=MojoIpcz --variations-seed-version --mojo-platform-channel-handle=4720 /prefetch:84⤵
- Executes dropped EXE
- Loads dropped DLL
-
C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe"C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView" --webview-exe-name=RobloxStudioBeta.exe --webview-exe-version="0, 631, 1, 6310472" --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --field-trial-handle=4824,i,11487306248321944511,3766159634979059685,262144 --enable-features=MojoIpcz --variations-seed-version --mojo-platform-channel-handle=4788 /prefetch:84⤵
- Executes dropped EXE
-
C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe"C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView" --webview-exe-name=RobloxStudioBeta.exe --webview-exe-version="0, 631, 1, 6310472" --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --field-trial-handle=4644,i,11487306248321944511,3766159634979059685,262144 --enable-features=MojoIpcz --variations-seed-version --mojo-platform-channel-handle=4848 /prefetch:84⤵
- Executes dropped EXE
-
C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe"C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView" --webview-exe-name=RobloxStudioBeta.exe --webview-exe-version="0, 631, 1, 6310472" --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --field-trial-handle=4532,i,11487306248321944511,3766159634979059685,262144 --enable-features=MojoIpcz --variations-seed-version --mojo-platform-channel-handle=4528 /prefetch:84⤵
- Executes dropped EXE
-
C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe"C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView" --webview-exe-name=RobloxStudioBeta.exe --webview-exe-version="0, 631, 1, 6310472" --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --field-trial-handle=4808,i,11487306248321944511,3766159634979059685,262144 --enable-features=MojoIpcz --variations-seed-version --mojo-platform-channel-handle=4200 /prefetch:84⤵
- Executes dropped EXE
-
C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe"C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=4318 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.15063.0 --noerrdialogs --user-data-dir="C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView" --webview-exe-name=RobloxStudioBeta.exe --webview-exe-version="0, 631, 1, 6310472" --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --gpu-preferences=WAAAAAAAAADoAAAMAAAAAAAAAAAAAAAAAABgAAEAAAA4AAAAAAAAAAAAAACEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --field-trial-handle=4624,i,11487306248321944511,3766159634979059685,262144 --enable-features=MojoIpcz --variations-seed-version --mojo-platform-channel-handle=4200 /prefetch:84⤵
- Executes dropped EXE
-
C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe"C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView" --webview-exe-name=RobloxStudioBeta.exe --webview-exe-version="0, 631, 1, 6310472" --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --field-trial-handle=4688,i,11487306248321944511,3766159634979059685,262144 --enable-features=MojoIpcz --variations-seed-version --mojo-platform-channel-handle=4400 /prefetch:84⤵
- Executes dropped EXE
-
C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe"C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.87\msedgewebview2.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView" --webview-exe-name=RobloxStudioBeta.exe --webview-exe-version="0, 631, 1, 6310472" --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --field-trial-handle=4344,i,11487306248321944511,3766159634979059685,262144 --enable-features=MojoIpcz --variations-seed-version --mojo-platform-channel-handle=4900 /prefetch:84⤵
- Executes dropped EXE
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc1⤵
- Checks system information in the registry
- Executes dropped EXE
- Loads dropped DLL
- Modifies data under HKEY_USERS
- Suspicious use of WriteProcessMemory
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xNzEuMzkiIHNoZWxsX3ZlcnNpb249IjEuMy4xNzEuMzkiIGlzbWFjaGluZT0iMSIgc2Vzc2lvbmlkPSJ7RUEyNjQxNDctMjk4RS00QzVFLTg4QjEtRjE0QUQ3MTY1Qjg1fSIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiByZXF1ZXN0aWQ9Ins3RjM5MjU4MS1FQ0EzLTQ5NTUtODQxNy1BMTkzQ0I1MjQ2NkV9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iOCIgcGh5c21lbW9yeT0iOCIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE1MDYzLjAiIHNwPSIiIGFyY2g9Ing2NCIgcHJvZHVjdF90eXBlPSI0OCIgaXNfd2lwPSIwIi8-PG9lbSBwcm9kdWN0X21hbnVmYWN0dXJlcj0iUUVNVSIgcHJvZHVjdF9uYW1lPSJTdGFuZGFyZCBQQyAoUTM1ICsgSUNIOSwgMjAwOSkiLz48ZXhwIGV0YWc9IiIvPjxhcHAgYXBwaWQ9Ins4QTY5RDM0NS1ENTY0LTQ2M2MtQUZGMS1BNjlEOUU1MzBGOTZ9IiB2ZXJzaW9uPSIxMDYuMC41MjQ5LjExOSIgbmV4dHZlcnNpb249IjEwNi4wLjUyNDkuMTE5IiBsYW5nPSJlbiIgYnJhbmQ9IkdHTFMiIGNsaWVudD0iIj48ZXZlbnQgZXZlbnR0eXBlPSIzMSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMyIgc3lzdGVtX3VwdGltZV90aWNrcz0iNTAyMjY1Mzg0MiIvPjwvYXBwPjwvcmVxdWVzdD42⤵
- Drops file in System32 directory
- Checks system information in the registry
- Executes dropped EXE
- Modifies data under HKEY_USERS
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\Install\{96D26A33-D04A-4CB8-B76D-872CB9A95699}\MicrosoftEdge_X64_126.0.2592.87.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\Install\{96D26A33-D04A-4CB8-B76D-872CB9A95699}\MicrosoftEdge_X64_126.0.2592.87.exe" --msedgewebview --verbose-logging --do-not-launch-msedge --system-level2⤵
- Executes dropped EXE
- Suspicious use of WriteProcessMemory
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\Install\{96D26A33-D04A-4CB8-B76D-872CB9A95699}\EDGEMITMP_5ACA0.tmp\setup.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\Install\{96D26A33-D04A-4CB8-B76D-872CB9A95699}\EDGEMITMP_5ACA0.tmp\setup.exe" --install-archive="C:\Program Files (x86)\Microsoft\EdgeUpdate\Install\{96D26A33-D04A-4CB8-B76D-872CB9A95699}\MicrosoftEdge_X64_126.0.2592.87.exe" --msedgewebview --verbose-logging --do-not-launch-msedge --system-level3⤵
- Executes dropped EXE
- Suspicious use of WriteProcessMemory
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\Install\{96D26A33-D04A-4CB8-B76D-872CB9A95699}\EDGEMITMP_5ACA0.tmp\setup.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\Install\{96D26A33-D04A-4CB8-B76D-872CB9A95699}\EDGEMITMP_5ACA0.tmp\setup.exe" --type=crashpad-handler /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Program Files\MsEdgeCrashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=126.0.6478.127 "--annotation=exe=C:\Program Files (x86)\Microsoft\EdgeUpdate\Install\{96D26A33-D04A-4CB8-B76D-872CB9A95699}\EDGEMITMP_5ACA0.tmp\setup.exe" --annotation=plat=Win64 "--annotation=prod=Microsoft Edge" --annotation=ver=126.0.2592.87 --initial-client-data=0x210,0x214,0x218,0x1ec,0x21c,0x7ff63986aa40,0x7ff63986aa4c,0x7ff63986aa584⤵
- Executes dropped EXE
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xNzEuMzkiIHNoZWxsX3ZlcnNpb249IjEuMy4xNzEuMzkiIGlzbWFjaGluZT0iMSIgc2Vzc2lvbmlkPSJ7RUEyNjQxNDctMjk4RS00QzVFLTg4QjEtRjE0QUQ3MTY1Qjg1fSIgaW5zdGFsbHNvdXJjZT0ib3RoZXJpbnN0YWxsY21kIiByZXF1ZXN0aWQ9Ins3NTIxOTBBNC1FMEMwLTRBOEQtQTQyOS04MDVFRUMzMkI0OTV9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iOCIgcGh5c21lbW9yeT0iOCIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE1MDYzLjAiIHNwPSIiIGFyY2g9Ing2NCIgcHJvZHVjdF90eXBlPSI0OCIgaXNfd2lwPSIwIi8-PG9lbSBwcm9kdWN0X21hbnVmYWN0dXJlcj0iUUVNVSIgcHJvZHVjdF9uYW1lPSJTdGFuZGFyZCBQQyAoUTM1ICsgSUNIOSwgMjAwOSkiLz48ZXhwIGV0YWc9IiZxdW90O1ZQUW9QMUYrZnExNXdSemgxa1BMNFBNcFdoOE9STUI1aXp2ck9DL2NoalE9JnF1b3Q7Ii8-PGFwcCBhcHBpZD0ie0YzMDE3MjI2LUZFMkEtNDI5NS04QkRGLTAwQzNBOUE3RTRDNX0iIHZlcnNpb249IiIgbmV4dHZlcnNpb249IjEyNi4wLjI1OTIuODciIGxhbmc9IiIgYnJhbmQ9IiIgY2xpZW50PSIiIGV4cGVyaW1lbnRzPSJjb25zZW50PWZhbHNlIiBpbnN0YWxsYWdlPSItMSIgaW5zdGFsbGRhdGU9Ii0xIj48dXBkYXRlY2hlY2svPjxldmVudCBldmVudHR5cGU9IjkiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIHN5c3RlbV91cHRpbWVfdGlja3M9IjUwNTc1MDM4NDIiIGRvbmVfYmVmb3JlX29vYmVfY29tcGxldGU9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSI1IiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSI1MDU3NTQ0MDY5IiBkb25lX2JlZm9yZV9vb2JlX2NvbXBsZXRlPSIwIi8-PGV2ZW50IGV2ZW50dHlwZT0iMSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iNTQwOTUwOTM1OSIgc291cmNlX3VybF9pbmRleD0iMCIgZG9uZV9iZWZvcmVfb29iZV9jb21wbGV0ZT0iMCIgZG93bmxvYWRlcj0iYml0cyIgdXJsPSJodHRwOi8vbXNlZGdlLmYudGx1LmRsLmRlbGl2ZXJ5Lm1wLm1pY3Jvc29mdC5jb20vZmlsZXN0cmVhbWluZ3NlcnZpY2UvZmlsZXMvYmRlNjRmNDctOGZhMy00ZjZjLThiY2UtZDI3NDI0MWI2YTJiP1AxPTE3MjA1NjU1NjgmYW1wO1AyPTQwNCZhbXA7UDM9MiZhbXA7UDQ9WXliOCUyYk1vcjE0ZzUxdzFqWCUyZlJZcWEyUTJaelJIWmxJSWRHNDdrcXI5a1FmJTJmTXBnZlo4cXpaeFR3MzNSRGRhdUlkbGJQMU5hZzlDSzlaaWR3U0pOc3clM2QlM2QiIHNlcnZlcl9pcF9oaW50PSIiIGNkbl9jaWQ9Ii0xIiBjZG5fY2NjPSIiIGNkbl9tc2VkZ2VfcmVmPSIiIGNkbl9henVyZV9yZWZfb3JpZ2luX3NoaWVsZD0iIiBjZG5fY2FjaGU9IiIgY2RuX3AzcD0iIiBkb3dubG9hZGVkPSIxNzMwNDEyMjQiIHRvdGFsPSIxNzMwNDEyMjQiIGRvd25sb2FkX3RpbWVfbXM9IjMxMjA4Ii8-PGV2ZW50IGV2ZW50dHlwZT0iMSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iNTQwOTU2OTM5NSIgc291cmNlX3VybF9pbmRleD0iMCIgZG9uZV9iZWZvcmVfb29iZV9jb21wbGV0ZT0iMCIvPjxldmVudCBldmVudHR5cGU9IjYiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIHN5c3RlbV91cHRpbWVfdGlja3M9IjU0MjM3NzkzNjciIGRvbmVfYmVmb3JlX29vYmVfY29tcGxldGU9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIxOTY3NTciIHN5c3RlbV91cHRpbWVfdGlja3M9IjU4MTk0Mjk4NjkiIHNvdXJjZV91cmxfaW5kZXg9IjAiIGRvbmVfYmVmb3JlX29vYmVfY29tcGxldGU9IjAiIHVwZGF0ZV9jaGVja190aW1lX21zPSIzNTYiIGRvd25sb2FkX3RpbWVfbXM9IjM1MTg3IiBkb3dubG9hZGVkPSIxNzMwNDEyMjQiIHRvdGFsPSIxNzMwNDEyMjQiIHBhY2thZ2VfY2FjaGVfcmVzdWx0PSIwIiBpbnN0YWxsX3RpbWVfbXM9IjM5NTY0Ii8-PC9hcHA-PC9yZXF1ZXN0Pg2⤵
- Drops file in System32 directory
- Checks system information in the registry
- Executes dropped EXE
- Modifies data under HKEY_USERS
-
C:\Windows\System32\GameBarPresenceWriter.exe"C:\Windows\System32\GameBarPresenceWriter.exe" -ServerName:Windows.Gaming.GameBar.Internal.PresenceWriterServer1⤵
-
C:\Windows\System32\GamePanel.exe"C:\Windows\System32\GamePanel.exe" 00000000000C002E /startuptips1⤵
-
C:\Windows\system32\AUDIODG.EXEC:\Windows\system32\AUDIODG.EXE 0x3fc1⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ua /installsource scheduler1⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc1⤵
- Checks system information in the registry
- Executes dropped EXE
- Modifies data under HKEY_USERS
- Suspicious use of AdjustPrivilegeToken
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\Install\{39314D3D-7106-4DFD-9856-BE7A4515A569}\MicrosoftEdgeUpdateSetup_X86_1.3.187.41.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\Install\{39314D3D-7106-4DFD-9856-BE7A4515A569}\MicrosoftEdgeUpdateSetup_X86_1.3.187.41.exe" /update /sessionid "{36C24F23-9075-48A9-A29A-5E328D6B5B2E}"2⤵
- Drops file in Program Files directory
- Executes dropped EXE
-
C:\Program Files (x86)\Microsoft\Temp\EUDA1B.tmp\MicrosoftEdgeUpdate.exe"C:\Program Files (x86)\Microsoft\Temp\EUDA1B.tmp\MicrosoftEdgeUpdate.exe" /update /sessionid "{36C24F23-9075-48A9-A29A-5E328D6B5B2E}"3⤵
- Event Triggered Execution: Image File Execution Options Injection
- Checks system information in the registry
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regsvc4⤵
- Executes dropped EXE
- Modifies registry class
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /regserver4⤵
- Executes dropped EXE
- Modifies registry class
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.187.41\MicrosoftEdgeUpdateComRegisterShell64.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.187.41\MicrosoftEdgeUpdateComRegisterShell64.exe"5⤵
- Executes dropped EXE
- Modifies registry class
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.187.41\MicrosoftEdgeUpdateComRegisterShell64.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.187.41\MicrosoftEdgeUpdateComRegisterShell64.exe"5⤵
- Executes dropped EXE
- Modifies registry class
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.187.41\MicrosoftEdgeUpdateComRegisterShell64.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\1.3.187.41\MicrosoftEdgeUpdateComRegisterShell64.exe"5⤵
- Executes dropped EXE
- Modifies registry class
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xODcuNDEiIHNoZWxsX3ZlcnNpb249IjEuMy4xNzEuMzkiIGlzbWFjaGluZT0iMSIgc2Vzc2lvbmlkPSJ7MzZDMjRGMjMtOTA3NS00OEE5LUEyOUEtNUUzMjhENkI1QjJFfSIgdXNlcmlkPSJ7Rjc2QjE5ODktNEM2Ri00NTAxLTg2REItRDI0ODNBNkQ4OUFEfSIgaW5zdGFsbHNvdXJjZT0ic2VsZnVwZGF0ZSIgcmVxdWVzdGlkPSJ7MjBGMkQ2ODgtQUFBMC00MDY4LUJBMjktNjkxODQ4MUUzRUQ2fSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBsb2dpY2FsX2NwdXM9IjgiIHBoeXNtZW1vcnk9IjgiIGRpc2tfdHlwZT0iMiIgc3NlPSIxIiBzc2UyPSIxIiBzc2UzPSIxIiBzc3NlMz0iMSIgc3NlNDE9IjEiIHNzZTQyPSIxIiBhdng9IjEiLz48b3MgcGxhdGZvcm09IndpbiIgdmVyc2lvbj0iMTAuMC4xNTA2My4wIiBzcD0iIiBhcmNoPSJ4NjQiIHByb2R1Y3RfdHlwZT0iNDgiIGlzX3dpcD0iMCIgaXNfaW5fbG9ja2Rvd25fbW9kZT0iMCIvPjxvZW0gcHJvZHVjdF9tYW51ZmFjdHVyZXI9IlFFTVUiIHByb2R1Y3RfbmFtZT0iU3RhbmRhcmQgUEMgKFEzNSArIElDSDksIDIwMDkpIi8-PGV4cCBldGFnPSImcXVvdDtyNDUydDErazJUZ3EvSFh6anZGTkJSaG9wQldSOXNialh4cWVVREg5dVgwPSZxdW90OyIvPjxhcHAgYXBwaWQ9IntGM0M0RkUwMC1FRkQ1LTQwM0ItOTU2OS0zOThBMjBGMUJBNEF9IiB2ZXJzaW9uPSIxLjMuMTcxLjM5IiBuZXh0dmVyc2lvbj0iMS4zLjE4Ny40MSIgbGFuZz0iIiBicmFuZD0iR0dMUyIgY2xpZW50PSIiIGluc3RhbGxhZ2U9IjAiIGluc3RhbGxkYXRlPSI2MzkxIiBpbnN0YWxsZGF0ZXRpbWU9IjE3MTk5NjA3NjMiPjxldmVudCBldmVudHR5cGU9IjMiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIHN5c3RlbV91cHRpbWVfdGlja3M9IjgyNTYzMDM2MDMiLz48L2FwcD48L3JlcXVlc3Q-4⤵
- Drops file in System32 directory
- Checks system information in the registry
- Executes dropped EXE
- Modifies data under HKEY_USERS
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xNzEuMzkiIHNoZWxsX3ZlcnNpb249IjEuMy4xNzEuMzkiIGlzbWFjaGluZT0iMSIgc2Vzc2lvbmlkPSJ7MzZDMjRGMjMtOTA3NS00OEE5LUEyOUEtNUUzMjhENkI1QjJFfSIgdXNlcmlkPSJ7Rjc2QjE5ODktNEM2Ri00NTAxLTg2REItRDI0ODNBNkQ4OUFEfSIgaW5zdGFsbHNvdXJjZT0ic2NoZWR1bGVyIiByZXF1ZXN0aWQ9InszQTM4MzIwNi0xNkU2LTQ3MjYtODVENi0zNTU0NDIxNEYyMzB9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iOCIgcGh5c21lbW9yeT0iOCIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE1MDYzLjAiIHNwPSIiIGFyY2g9Ing2NCIgcHJvZHVjdF90eXBlPSI0OCIgaXNfd2lwPSIwIi8-PG9lbSBwcm9kdWN0X21hbnVmYWN0dXJlcj0iUUVNVSIgcHJvZHVjdF9uYW1lPSJTdGFuZGFyZCBQQyAoUTM1ICsgSUNIOSwgMjAwOSkiLz48ZXhwIGV0YWc9IiZxdW90O3I0NTJ0MStrMlRncS9IWHpqdkZOQlJob3BCV1I5c2JqWHhxZVVESDl1WDA9JnF1b3Q7Ii8-PGFwcCBhcHBpZD0ie0YzQzRGRTAwLUVGRDUtNDAzQi05NTY5LTM5OEEyMEYxQkE0QX0iIHZlcnNpb249IjEuMy4xNzEuMzkiIG5leHR2ZXJzaW9uPSIxLjMuMTg3LjQxIiBsYW5nPSIiIGJyYW5kPSJHR0xTIiBjbGllbnQ9IiIgZXhwZXJpbWVudHM9ImNvbnNlbnQ9ZmFsc2UiIGluc3RhbGxhZ2U9IjAiPjx1cGRhdGVjaGVjay8-PGV2ZW50IGV2ZW50dHlwZT0iMTIiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIHN5c3RlbV91cHRpbWVfdGlja3M9IjgxOTk1OTM1NzYiIGRvbmVfYmVmb3JlX29vYmVfY29tcGxldGU9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSIxMyIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iODE5OTYxMzYzNyIgZG9uZV9iZWZvcmVfb29iZV9jb21wbGV0ZT0iMCIvPjxldmVudCBldmVudHR5cGU9IjE0IiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIiBzeXN0ZW1fdXB0aW1lX3RpY2tzPSI4MjA4ODAzNTY2IiBzb3VyY2VfdXJsX2luZGV4PSIwIiBkb25lX2JlZm9yZV9vb2JlX2NvbXBsZXRlPSIwIiBkb3dubG9hZGVyPSJiaXRzIiB1cmw9Imh0dHA6Ly9tc2VkZ2UuYi50bHUuZGwuZGVsaXZlcnkubXAubWljcm9zb2Z0LmNvbS9maWxlc3RyZWFtaW5nc2VydmljZS9maWxlcy80YWQ5Y2I2ZS04MjQ1LTRlNDctYjI5OC0xZmY0YjA0MjU2ZTE_UDE9MTcyMDU2NTg4MiZhbXA7UDI9NDA0JmFtcDtQMz0yJmFtcDtQND1jWThSNzd4anNwcnJlVWZZNHpMSFA3ZTIzWDc0SlklMmJnZzVSZnR1a2F6dmFkaSUyYlBCMWNXaVRWVllTUFZQZGkxYVZ4ZFc4Y2IwQ1YwMjVqM2NkR2w4MVElM2QlM2QiIHNlcnZlcl9pcF9oaW50PSIiIGNkbl9jaWQ9Ii0xIiBjZG5fY2NjPSIiIGNkbl9tc2VkZ2VfcmVmPSIiIGNkbl9henVyZV9yZWZfb3JpZ2luX3NoaWVsZD0iIiBjZG5fY2FjaGU9IiIgY2RuX3AzcD0iIiBkb3dubG9hZGVkPSIxNjM0Mzc2IiB0b3RhbD0iMTYzNDM3NiIgZG93bmxvYWRfdGltZV9tcz0iODM2Ii8-PGV2ZW50IGV2ZW50dHlwZT0iMTQiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjAiIHN5c3RlbV91cHRpbWVfdGlja3M9IjgyMDg4MTM2MzEiIHNvdXJjZV91cmxfaW5kZXg9IjAiIGRvbmVfYmVmb3JlX29vYmVfY29tcGxldGU9IjAiLz48ZXZlbnQgZXZlbnR0eXBlPSIxNSIgZXZlbnRyZXN1bHQ9IjEiIGVycm9yY29kZT0iMCIgZXh0cmFjb2RlMT0iMCIgc3lzdGVtX3VwdGltZV90aWNrcz0iODIxNDAwOTAyMiIgZG9uZV9iZWZvcmVfb29iZV9jb21wbGV0ZT0iMCIvPjxwaW5nIHI9Ii0xIiByZD0iLTEiLz48L2FwcD48YXBwIGFwcGlkPSJ7RjMwMTcyMjYtRkUyQS00Mjk1LThCREYtMDBDM0E5QTdFNEM1fSIgdmVyc2lvbj0iMTI2LjAuMjU5Mi44NyIgbmV4dHZlcnNpb249IiIgbGFuZz0iIiBicmFuZD0iR0dMUyIgY2xpZW50PSIiIGluc3RhbGxhZ2U9IjAiIGluc3RhbGxkYXRlPSI2MzkxIiBsYXN0X2xhdW5jaF90aW1lPSIxMzM2NDQzNDQ0OTE5Mjk3ODAiPjx1cGRhdGVjaGVjay8-PHBpbmcgYWN0aXZlPSIxIiBhPSItMSIgcj0iLTEiIGFkPSItMSIgcmQ9Ii0xIiBwaW5nX2ZyZXNobmVzcz0iezU4NjBEMDU5LUFCNzEtNDBFNy1BRUE1LTUyMzI1RThFM0I2OH0iLz48L2FwcD48L3JlcXVlc3Q-2⤵
- Drops file in System32 directory
- Checks system information in the registry
- Executes dropped EXE
- Modifies data under HKEY_USERS
-
C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe"1⤵
-
C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe"2⤵
- Checks processor information in registry
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
- Suspicious use of SetWindowsHookEx
-
C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2976.0.251228101\248580640" -parentBuildID 20221007134813 -prefsHandle 1744 -prefMapHandle 1700 -prefsLen 20747 -prefMapSize 233444 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c7aeebd0-7163-40e0-bde5-0b94ef0b3dae} 2976 "\\.\pipe\gecko-crash-server-pipe.2976" 1824 148b9ed6e58 gpu3⤵
-
C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2976.1.1217724528\787554586" -parentBuildID 20221007134813 -prefsHandle 2160 -prefMapHandle 2156 -prefsLen 20828 -prefMapSize 233444 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {97430ca3-49c1-497d-a740-1656084b85c2} 2976 "\\.\pipe\gecko-crash-server-pipe.2976" 2180 148aede3458 socket3⤵
-
C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2976.2.445982275\1847909736" -childID 1 -isForBrowser -prefsHandle 2844 -prefMapHandle 2840 -prefsLen 20931 -prefMapSize 233444 -jsInitHandle 1136 -jsInitLen 246848 -a11yResourceId 64 -parentBuildID 20221007134813 -appDir "C:\Program Files\Mozilla Firefox\browser" - {a7c6e1a8-77fc-4c59-a498-d8f82d2ef42b} 2976 "\\.\pipe\gecko-crash-server-pipe.2976" 2784 148b9e62858 tab3⤵
-
C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2976.3.588782958\980821766" -childID 2 -isForBrowser -prefsHandle 3496 -prefMapHandle 3492 -prefsLen 26109 -prefMapSize 233444 -jsInitHandle 1136 -jsInitLen 246848 -a11yResourceId 64 -parentBuildID 20221007134813 -appDir "C:\Program Files\Mozilla Firefox\browser" - {fed767c9-0117-4bca-9333-bfb516cb4e71} 2976 "\\.\pipe\gecko-crash-server-pipe.2976" 3500 148be530e58 tab3⤵
-
C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2976.4.636394611\1134563283" -childID 3 -isForBrowser -prefsHandle 4216 -prefMapHandle 4212 -prefsLen 26168 -prefMapSize 233444 -jsInitHandle 1136 -jsInitLen 246848 -a11yResourceId 64 -parentBuildID 20221007134813 -appDir "C:\Program Files\Mozilla Firefox\browser" - {e43bcf4d-5567-415e-9f83-df8ff13cb5e7} 2976 "\\.\pipe\gecko-crash-server-pipe.2976" 4220 148bfd27858 tab3⤵
-
C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2976.5.742678659\2115488841" -childID 4 -isForBrowser -prefsHandle 4768 -prefMapHandle 4780 -prefsLen 26168 -prefMapSize 233444 -jsInitHandle 1136 -jsInitLen 246848 -a11yResourceId 64 -parentBuildID 20221007134813 -appDir "C:\Program Files\Mozilla Firefox\browser" - {ac0c4c98-fced-4414-b693-182563c6da44} 2976 "\\.\pipe\gecko-crash-server-pipe.2976" 4680 148be52d258 tab3⤵
-
C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2976.6.729177613\1870595777" -childID 5 -isForBrowser -prefsHandle 4872 -prefMapHandle 4876 -prefsLen 26168 -prefMapSize 233444 -jsInitHandle 1136 -jsInitLen 246848 -a11yResourceId 64 -parentBuildID 20221007134813 -appDir "C:\Program Files\Mozilla Firefox\browser" - {448908f7-07a5-444b-a9b5-d2a27f93bb65} 2976 "\\.\pipe\gecko-crash-server-pipe.2976" 4956 148c04b6958 tab3⤵
-
C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2976.7.1589253888\81666763" -childID 6 -isForBrowser -prefsHandle 5096 -prefMapHandle 5100 -prefsLen 26168 -prefMapSize 233444 -jsInitHandle 1136 -jsInitLen 246848 -a11yResourceId 64 -parentBuildID 20221007134813 -appDir "C:\Program Files\Mozilla Firefox\browser" - {da9e6802-636f-4095-929a-f7d4e56a2f92} 2976 "\\.\pipe\gecko-crash-server-pipe.2976" 5084 148c04b6c58 tab3⤵
-
C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2976.8.2062838371\2114017383" -childID 7 -isForBrowser -prefsHandle 5744 -prefMapHandle 5736 -prefsLen 26249 -prefMapSize 233444 -jsInitHandle 1136 -jsInitLen 246848 -a11yResourceId 64 -parentBuildID 20221007134813 -appDir "C:\Program Files\Mozilla Firefox\browser" - {59c06aaf-869c-4145-802f-c5626456e12d} 2976 "\\.\pipe\gecko-crash-server-pipe.2976" 5760 148c24ee558 tab3⤵
-
C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2976.9.1959816631\1009404568" -childID 8 -isForBrowser -prefsHandle 8708 -prefMapHandle 8828 -prefsLen 27468 -prefMapSize 233444 -jsInitHandle 1136 -jsInitLen 246848 -a11yResourceId 64 -parentBuildID 20221007134813 -appDir "C:\Program Files\Mozilla Firefox\browser" - {eac28fc6-9d48-49d2-a3e9-091d6115a7b8} 2976 "\\.\pipe\gecko-crash-server-pipe.2976" 8880 148c90c7158 tab3⤵
-
C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2976.10.249034107\615869929" -parentBuildID 20221007134813 -prefsHandle 8476 -prefMapHandle 8472 -prefsLen 27468 -prefMapSize 233444 -appDir "C:\Program Files\Mozilla Firefox\browser" - {c2d57202-1f1a-4b80-8b2c-3e953262f91c} 2976 "\\.\pipe\gecko-crash-server-pipe.2976" 8496 148c94fee58 rdd3⤵
-
C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\RobloxStudioBeta.exe"C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\RobloxStudioBeta.exe" roblox-studio:1+launchtime:1719961319061+avatar+browsertrackerid:1719961115800002+robloxLocale:en-US+gameLocale:en-US+channel:+browser:firefox+userId:2659602565+distributorType:Global+launchmode:edit+task:EditPlace+placeId:18308851254+universeId:62070176741⤵
- Checks whether UAC is enabled
- Executes dropped EXE
- Enumerates system info in registry
- Suspicious behavior: AddClipboardFormatListener
- Suspicious behavior: GetForegroundWindowSpam
- Suspicious use of SetWindowsHookEx
-
C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\RobloxCrashHandler.exe"C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\RobloxCrashHandler.exe" --no-rate-limit --crashCounter Win-ROBLOXStudio-Crash --baseUrl https://www.roblox.com --attachment=attachment_0.631.1.6310472_20240702T230203Z_Studio_08F14_last.log=C:\Users\Admin\AppData\Local\Roblox\logs\0.631.1.6310472_20240702T230203Z_Studio_08F14_last.log --attachment=attachment_log_0.631.1.6310472_20240702T230203Z_Studio_08F14_csg3.log=C:\Users\Admin\AppData\Local\Roblox\logs\log_0.631.1.6310472_20240702T230203Z_Studio_08F14_csg3.log --database=C:\Users\Admin\AppData\Local\Roblox\logs\crashes --metrics-dir=C:\Users\Admin\AppData\Local\Roblox\logs\crashes --url=https://upload.crashes.rbxinfra.com/post?format=minidump --annotation=AppVersion=0.631.1.6310472 --annotation=Format=minidump --annotation=HardwareModel= --annotation=HasBootstrapper=true --annotation=InstallFolder=ProgramFilesX86 --annotation=OSPlatform=Windows --annotation=RobloxChannel=production --annotation=RobloxGitHash=cb5e1ef861e0b94bbfd3c1c166285778889972be --annotation=RobloxProduct=RobloxStudio --annotation=StudioVersion=0.631.1.6310472 --annotation=UniqueId=8590842540993267337 --annotation=UseCrashpad=True --annotation=app_arch=x86_64 --annotation=application.version=0.631.1.6310472 --annotation=host_arch=x86_64 --initial-client-data=0x4d4,0x4d8,0x4dc,0x4b0,0x4e4,0x7ff753b5e708,0x7ff753b5e720,0x7ff753b5e7382⤵
- Executes dropped EXE
-
C:\Windows\System32\GamePanel.exe"C:\Windows\System32\GamePanel.exe" 0000000000020240 /startuptips1⤵
- Checks SCSI registry key(s)
-
C:\Windows\System32\bcastdvr.exe"C:\Windows\System32\bcastdvr.exe" -ServerName:Windows.Media.Capture.Internal.BroadcastDVRServer1⤵
- Drops desktop.ini file(s)
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ua /installsource scheduler1⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /svc1⤵
- Executes dropped EXE
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xODcuNDEiIHNoZWxsX3ZlcnNpb249IjEuMy4xNzEuMzkiIGlzbWFjaGluZT0iMSIgc2Vzc2lvbmlkPSJ7MDM4REQ5RkMtNDAyMC00REVELTg2RDMtOENGMjJDNzREOTc3fSIgdXNlcmlkPSJ7Rjc2QjE5ODktNEM2Ri00NTAxLTg2REItRDI0ODNBNkQ4OUFEfSIgaW5zdGFsbHNvdXJjZT0ibGltaXRlZCIgcmVxdWVzdGlkPSJ7QTAyOUJFMjAtQUFCNi00NzkyLUFFRUYtNkZFODUwREIzNzlFfSIgZGVkdXA9ImNyIiBkb21haW5qb2luZWQ9IjAiPjxodyBsb2dpY2FsX2NwdXM9IjgiIHBoeXNtZW1vcnk9IjgiIGRpc2tfdHlwZT0iMiIgc3NlPSIxIiBzc2UyPSIxIiBzc2UzPSIxIiBzc3NlMz0iMSIgc3NlNDE9IjEiIHNzZTQyPSIxIiBhdng9IjEiLz48b3MgcGxhdGZvcm09IndpbiIgdmVyc2lvbj0iMTAuMC4xNTA2My4wIiBzcD0iIiBhcmNoPSJ4NjQiIHByb2R1Y3RfdHlwZT0iNDgiIGlzX3dpcD0iMCIgaXNfaW5fbG9ja2Rvd25fbW9kZT0iMCIvPjxvZW0gcHJvZHVjdF9tYW51ZmFjdHVyZXI9IlFFTVUiIHByb2R1Y3RfbmFtZT0iU3RhbmRhcmQgUEMgKFEzNSArIElDSDksIDIwMDkpIi8-PGV4cCBldGFnPSImcXVvdDt0eGdVQkhvbzZBUVNBL2Z5RTQ4c3lFWHF4MkorL3FzcWxHV3hpNHVmSFlrPSZxdW90OyIvPjxhcHAgYXBwaWQ9Ins4QTY5RDM0NS1ENTY0LTQ2M2MtQUZGMS1BNjlEOUU1MzBGOTZ9IiB2ZXJzaW9uPSIxMDYuMC41MjQ5LjExOSIgbmV4dHZlcnNpb249IiIgbGFuZz0iZW4iIGJyYW5kPSJHR0xTIiBjbGllbnQ9IiIgaW5zdGFsbGFnZT0iODkiIGluc3RhbGxkYXRldGltZT0iMTcxMjIzMzcwOCIgb29iZV9pbnN0YWxsX3RpbWU9IjEzMzU2NzA2NTg0Njc3MzI0MCI-PGV2ZW50IGV2ZW50dHlwZT0iMzEiIGV2ZW50cmVzdWx0PSIxIiBlcnJvcmNvZGU9IjAiIGV4dHJhY29kZTE9IjIxMTQzMjUiIHN5c3RlbV91cHRpbWVfdGlja3M9IjExODAwNzc4NzYyIi8-PC9hcHA-PC9yZXF1ZXN0Pg2⤵
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe"C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB1cGRhdGVyPSJPbWFoYSIgdXBkYXRlcnZlcnNpb249IjEuMy4xODcuNDEiIHNoZWxsX3ZlcnNpb249IjEuMy4xNzEuMzkiIGlzbWFjaGluZT0iMSIgc2Vzc2lvbmlkPSJ7MDM4REQ5RkMtNDAyMC00REVELTg2RDMtOENGMjJDNzREOTc3fSIgdXNlcmlkPSJ7Rjc2QjE5ODktNEM2Ri00NTAxLTg2REItRDI0ODNBNkQ4OUFEfSIgaW5zdGFsbHNvdXJjZT0ic2NoZWR1bGVyIiByZXF1ZXN0aWQ9Ins5RjU2NEZCQi1ENEJBLTQ3QTgtQTk0RC1GQzkxNDBBQjQzMzR9IiBkZWR1cD0iY3IiIGRvbWFpbmpvaW5lZD0iMCI-PGh3IGxvZ2ljYWxfY3B1cz0iOCIgcGh5c21lbW9yeT0iOCIgZGlza190eXBlPSIyIiBzc2U9IjEiIHNzZTI9IjEiIHNzZTM9IjEiIHNzc2UzPSIxIiBzc2U0MT0iMSIgc3NlNDI9IjEiIGF2eD0iMSIvPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSIxMC4wLjE1MDYzLjAiIHNwPSIiIGFyY2g9Ing2NCIgcHJvZHVjdF90eXBlPSI0OCIgaXNfd2lwPSIwIiBpc19pbl9sb2NrZG93bl9tb2RlPSIwIi8-PG9lbSBwcm9kdWN0X21hbnVmYWN0dXJlcj0iUUVNVSIgcHJvZHVjdF9uYW1lPSJTdGFuZGFyZCBQQyAoUTM1ICsgSUNIOSwgMjAwOSkiLz48ZXhwIGV0YWc9IiZxdW90O1ZQUW9QMUYrZnExNXdSemgxa1BMNFBNcFdoOE9STUI1aXp2ck9DL2NoalE9JnF1b3Q7Ii8-PGFwcCBhcHBpZD0ie0YzQzRGRTAwLUVGRDUtNDAzQi05NTY5LTM5OEEyMEYxQkE0QX0iIHZlcnNpb249IjEuMy4xODcuNDEiIG5leHR2ZXJzaW9uPSIiIGxhbmc9IiIgYnJhbmQ9IkdHTFMiIGNsaWVudD0iIiBleHBlcmltZW50cz0iY29uc2VudD1mYWxzZSIgaW5zdGFsbGFnZT0iMCIgaW5zdGFsbGRhdGU9IjYzOTEiIGNvaG9ydD0icnJmQDAuMDEiPjx1cGRhdGVjaGVjay8-PHBpbmcgcmQ9IjYzOTIiIHBpbmdfZnJlc2huZXNzPSJ7RjFEM0I3MEUtREM5Ny00ODc2LUE1OEItMzEyNjg2QUNBRTJEfSIvPjwvYXBwPjxhcHAgYXBwaWQ9IntGMzAxNzIyNi1GRTJBLTQyOTUtOEJERi0wMEMzQTlBN0U0QzV9IiB2ZXJzaW9uPSIxMjYuMC4yNTkyLjg3IiBuZXh0dmVyc2lvbj0iIiBsYW5nPSIiIGJyYW5kPSJHR0xTIiBjbGllbnQ9IiIgaW5zdGFsbGFnZT0iMCIgaW5zdGFsbGRhdGU9IjYzOTEiIGNvaG9ydD0icnJmQDAuNDUiIGxhc3RfbGF1bmNoX2NvdW50PSIxIiBsYXN0X2xhdW5jaF90aW1lPSIxMzM2NDQzNDQ0OTE5Mjk3ODAiPjx1cGRhdGVjaGVjay8-PHBpbmcgYWN0aXZlPSIwIiByZD0iNjM5MiIgcGluZ19mcmVzaG5lc3M9InswQjMxNjZENC0zNjU5LTQ2M0QtQkY5MS02NDUwMTlGRDU3MTd9Ii8-PC9hcHA-PC9yZXF1ZXN0Pg2⤵
Network
MITRE ATT&CK Matrix ATT&CK v13
Persistence
Event Triggered Execution
2Image File Execution Options Injection
1Component Object Model Hijacking
1Privilege Escalation
Event Triggered Execution
2Image File Execution Options Injection
1Component Object Model Hijacking
1Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Program Files (x86)\Microsoft\EdgeCore\126.0.2592.87\Installer\setup.exeFilesize
6.5MB
MD544bab1ba8bbc80a6f11a59a921ade1fe
SHA171292aa421fc9cefd9eeade06fc5af52f71e8dc2
SHA256a03c11b73af7ccf83f2a4bc1995f9083f8415174d1e8f6d6465e9192aabb542a
SHA512fcb6f75c3367b91da92b3d866ae6b85428d8c2ef13499344e80ddd3bb30f47d1243120aa41eba519756bcb6ff5f9708e7fe7281265c4c32766231765aa8104e2
-
C:\Program Files (x86)\Microsoft\EdgeUpdate\Download\{F3C4FE00-EFD5-403B-9569-398A20F1BA4A}\1.3.187.41\MicrosoftEdgeUpdateSetup_X86_1.3.187.41.exeFilesize
1.6MB
MD5a9ad77a4111f44c157a1a37bb29fd2b9
SHA1f1348bcbc950532ac2b48b18acd91533f3ac0be2
SHA256200a59abdeb32cc4d2cec4079be205f18b5f45bae42acb7940151f9780569889
SHA51268f58a15ef5ba5d49d8476bee4a488e9a721f703a645ddd29148915d555ca2eb451635c3b762e5a0f786d69bb5cba9bffac3eeee196f1ec7ad669e2d729fe898
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\EdgeUpdate.datFilesize
12KB
MD5369bbc37cff290adb8963dc5e518b9b8
SHA1de0ef569f7ef55032e4b18d3a03542cc2bbac191
SHA2563d7ec761bef1b1af418b909f1c81ce577c769722957713fdafbc8131b0a0c7d3
SHA5124f8ec1fd4de8d373a4973513aa95e646dfc5b1069549fafe0d125614116c902bfc04b0e6afd12554cc13ca6c53e1f258a3b14e54ac811f6b06ed50c9ac9890b1
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\MicrosoftEdgeComRegisterShellARM64.exeFilesize
179KB
MD57a160c6016922713345454265807f08d
SHA1e36ee184edd449252eb2dfd3016d5b0d2edad3c6
SHA25635a14bd84e74dd6d8e2683470243fb1bb9071178d9283b12ebbfb405c8cd4aa9
SHA512c0f1d5c8455cf14f2088ede062967d6dfa7c39ca2ac9636b10ed46dfbea143f64106a4f03c285e89dd8cf4405612f1eef25a8ec4f15294ca3350053891fc3d7e
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\MicrosoftEdgeUpdate.exeFilesize
201KB
MD54dc57ab56e37cd05e81f0d8aaafc5179
SHA1494a90728d7680f979b0ad87f09b5b58f16d1cd5
SHA25687c6f7d9b58f136aeb33c96dbfe3702083ec519aafca39be66778a9c27a68718
SHA512320eeed88d7facf8c1f45786951ef81708c82cb89c63a3c820ee631c52ea913e64c4e21f0039c1b277cfb710c4d81cd2191878320d00fd006dd777c727d9dc2b
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\MicrosoftEdgeUpdateComRegisterShell64.exeFilesize
212KB
MD560dba9b06b56e58f5aea1a4149c743d2
SHA1a7e456acf64dd99ca30259cf45b88cf2515a69b3
SHA2564d01f5531f93ab2af9e92c4f998a145c94f36688c3793845d528c8675697e112
SHA512e98088a368d4c4468e325a1d62bee49661f597e5c1cd1fe2dabad3911b8ac07e1cc4909e7324cb4ab39f30fa32a34807685fcfba767f88884ef84ca69a0049e7
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\MicrosoftEdgeUpdateCore.exeFilesize
257KB
MD5c044dcfa4d518df8fc9d4a161d49cece
SHA191bd4e933b22c010454fd6d3e3b042ab6e8b2149
SHA2569f79fe09f57002ca07ae0b2a196e8cc002d2be6d5540ee857217e99b33fa4bb2
SHA512f26b89085aa22ac62a28610689e81b4dfe3c38a9015ec56dfeaff02fdb6fa64e784b86a961509b52ad968400faa1ef0487f29f07a41e37239fe4c3262a11ac2c
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\NOTICE.TXTFilesize
4KB
MD56dd5bf0743f2366a0bdd37e302783bcd
SHA1e5ff6e044c40c02b1fc78304804fe1f993fed2e6
SHA25691d3fc490565ded7621ff5198960e501b6db857d5dd45af2fe7c3ecd141145f5
SHA512f546c1dff8902a3353c0b7c10ca9f69bb77ebd276e4d5217da9e0823a0d8d506a5267773f789343d8c56b41a0ee6a97d4470a44bbd81ceaa8529e5e818f4951e
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdate.dllFilesize
2.0MB
MD5965b3af7886e7bf6584488658c050ca2
SHA172daabdde7cd500c483d0eeecb1bd19708f8e4a5
SHA256d80c512d99765586e02323a2e18694965eafb903e9bc13f0e0b4265f86b21a19
SHA5121c57dc7b89e7f13f21eaec7736b724cd864c443a2f09829308a4f23cb03e9a5f2a1e5bcdc441301e33119767e656a95d0f9ede0e5114bf67f5dce6e55de7b0a4
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_af.dllFilesize
28KB
MD5567aec2d42d02675eb515bbd852be7db
SHA166079ae8ac619ff34e3ddb5fb0823b1790ba7b37
SHA256a881788359b2a7d90ac70a76c45938fb337c2064487dcb8be00b9c311d10c24c
SHA5123a7414e95c2927d5496f29814556d731aef19efa531fb58988079287669dfc033f3e04c8740697571df76bfecfe3b75659511783ce34682d2a2ea704dfa115b3
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_am.dllFilesize
24KB
MD5f6c1324070b6c4e2a8f8921652bfbdfa
SHA1988e6190f26e4ca8f7ea3caabb366cf1edcdcbbf
SHA256986b0654a8b5f7b23478463ff051bffe1e9bbdeb48744e4aa1bd3d89a7520717
SHA51263092cf13e8a19966181df695eb021b0a9993afe8f98b1309973ea999fdf4cd9b6ffd609968d4aa0b2cde41e872688a283fd922d8b22cb5ad06339fe18221100
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_ar.dllFilesize
26KB
MD5570efe7aa117a1f98c7a682f8112cb6d
SHA1536e7c49e24e9aa068a021a8f258e3e4e69fa64f
SHA256e2cc8017bc24e73048c7ee68d3787ed63c3898eec61299a9ca1bab8aeaa8da01
SHA5125e963dd55a5739a1da19cec7277dc3d07afdb682330998fd8c33a1b5949942019521967d8b5af0752a7a8e2cf536faa7e62982501170319558ceaa21ed657ae8
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_as.dllFilesize
28KB
MD5a8d3210e34bf6f63a35590245c16bc1b
SHA1f337f2cbec05b7e20ca676d7c2b1a8d5ae8bf693
SHA2563b82de846ad028544013383e3c9fb570d2a09abf2c854e8a4d641bd7fc3b3766
SHA5126e47ffe8f7c2532e7854dcae3cbd4e6533f0238815cb6af5ea85087c51017ea284542b988f07692d0297ebab1bad80d7613bf424ff532e10b01c8e528ab1043a
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_az.dllFilesize
29KB
MD57937c407ebe21170daf0975779f1aa49
SHA14c2a40e76209abd2492dfaaf65ef24de72291346
SHA2565ab96e4e6e065dbce3b643c6be2c668f5570984ead1a8b3578bbd2056fbad4e9
SHA5128670746941660e6573732077f5ed1b630f94a825cf4ac9dbe5018772eaac1c48216334757a2aeaa561034b4d907162a370b8f0bae83b34a09457fafe165fb5d7
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_bg.dllFilesize
29KB
MD58375b1b756b2a74a12def575351e6bbd
SHA1802ec096425dc1cab723d4cf2fd1a868315d3727
SHA256a12df15afac4eb2695626d7a8a2888bdf54c8db671043b0677180f746d8ad105
SHA512aec4bb94fde884db79a629abcff27fd8afb7f229d055514f51fa570fb47a85f8dfc9a54a8f69607d2bcaf82fae1ec7ffab0b246795a77a589be11fad51b24d19
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_bn-IN.dllFilesize
29KB
MD5a94cf5e8b1708a43393263a33e739edd
SHA11068868bdc271a52aaae6f749028ed3170b09cce
SHA2565b01fe11016610d5606f815281c970c86025732fc597b99c031a018626cd9f3c
SHA512920f7fed1b720afdb569aec2961bd827a6fc54b4598c0704f65da781d142b1707e5106a459f0c289e0f476b054d93c0b733806af036b68f46377dde0541af2e7
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_bn.dllFilesize
29KB
MD57dc58c4e27eaf84ae9984cff2cc16235
SHA13f53499ddc487658932a8c2bcf562ba32afd3bda
SHA256e32f77ed3067d7735d10f80e5a0aa0c50c993b59b82dc834f2583c314e28fa98
SHA512bdec1300cf83ea06dfd351fe1252b850fecea08f9ef9cb1207fce40ce30742348db953107ade6cdb0612af2e774345faf03a8a6476f2f26735eb89153b4256dc
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_bs.dllFilesize
28KB
MD5e338dccaa43962697db9f67e0265a3fc
SHA14c6c327efc12d21c4299df7b97bf2c45840e0d83
SHA25699b1b7e25fbc2c64489c0607cef0ae5ff720ab529e11093ed9860d953adeba04
SHA512e0c15b166892433ef31ddf6b086680c55e1a515bed89d51edbdf526fcac71fb4e8cb2fadc739ac75ae5c2d9819fc985ca873b0e9e2a2925f82e0a456210898f9
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_ca-Es-VALENCIA.dllFilesize
29KB
MD52929e8d496d95739f207b9f59b13f925
SHA17c1c574194d9e31ca91e2a21a5c671e5e95c734c
SHA2562726c48a468f8f6debc2d9a6a0706b640b2852c885e603e6b2dec638756160df
SHA512ea459305d3c3fa7a546194f649722b76072f31e75d59da149c57ff05f4af8f38a809066054df809303937bbca917e67441da2f0e1ea37b50007c25ae99429957
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_ca.dllFilesize
30KB
MD539551d8d284c108a17dc5f74a7084bb5
SHA16e43fc5cec4b4b0d44f3b45253c5e0b032e8e884
SHA2568dbd55ed532073874f4fe006ef456e31642317145bd18ddc30f681ce9e0c8e07
SHA5126fa5013a9ce62deca9fa90a98849401b6e164bbad8bef00a8a8b228427520dd584e28cba19c71e2c658692390fe29be28f0398cb6c0f9324c56290bb245d06d2
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_cs.dllFilesize
28KB
MD516c84ad1222284f40968a851f541d6bb
SHA1bc26d50e15ccaed6a5fbe801943117269b3b8e6b
SHA256e0f0026ddcbeafc6c991da6ba7c52927d050f928dba4a7153552efcea893a35b
SHA512d3018619469ed25d84713bd6b6515c9a27528810765ed41741ac92caf0a3f72345c465a5bda825041df69e1264aada322b62e10c7ed20b3d1bcde82c7e146b7e
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_cy.dllFilesize
28KB
MD534d991980016595b803d212dc356d765
SHA1e3a35df6488c3463c2a7adf89029e1dd8308f816
SHA256252b6f9bf5a9cb59ad1c072e289cc9695c0040b363d4bfbcc9618a12df77d18e
SHA5128a6cbcf812af37e3ead789fbec6cba9c4e1829dbeea6200f0abbdae15efd1eda38c3a2576e819d95ed2df0aafd2370480daa24a3fe6aeb8081a936d5e1f8d8ed
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_da.dllFilesize
28KB
MD5d34380d302b16eab40d5b63cfb4ed0fe
SHA11d3047119e353a55dc215666f2b7b69f0ede775b
SHA256fd98159338d1f3b03814af31440d37d15ab183c1a230e6261fbb90e402f85d5f
SHA51245ce58f4343755e392037a9c6fc301ad9392e280a72b9d4b6d328866fe26877b2988c39e05c4e7f1d5b046c0864714b897d35285e222fd668f0d71b7b10e6538
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_de.dllFilesize
30KB
MD5aab01f0d7bdc51b190f27ce58701c1da
SHA11a21aabab0875651efd974100a81cda52c462997
SHA256061a7cdaff9867ddb0bd3de2c0760d6919d8d2ca7c7f889ec2d32265d7e7a75c
SHA5125edbda45205b61ac48ea6e874411bb1031989001539650de6e424528f72ec8071bd709c037c956450bb0558ee37d026c26fdb966efceb990ed1219f135b09e6e
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_el.dllFilesize
30KB
MD5ac275b6e825c3bd87d96b52eac36c0f6
SHA129e537d81f5d997285b62cd2efea088c3284d18f
SHA256223d2db0bc2cc82bda04a0a2cd2b7f6cb589e2fa5c0471a2d5eb04d2ffcfcfa0
SHA512bba581412c4297c4daf245550a2656cdc2923f77158b171e0eacf6e933c174eac84580864813cf6d75d73d1a58e0caf46170aee3cee9d84dc468379252b16679
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_en-GB.dllFilesize
27KB
MD5d749e093f263244d276b6ffcf4ef4b42
SHA169f024c769632cdbb019943552bac5281d4cbe05
SHA256fd90699e7f29b6028a2e8e6f3ae82d26cdc6942bd39c4f07b221d87c5dbbfe1e
SHA51248d51b006ce0cd903154fa03d17e76591db739c4bfb64243725d21d4aa17db57a852077be00b9a51815d09664d18f9e6ad61d9bc41b3d013ed24aaec8f477ad9
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_en.dllFilesize
27KB
MD54a1e3cf488e998ef4d22ac25ccc520a5
SHA1dc568a6e3c9465474ef0d761581c733b3371b1cd
SHA2569afbbe2a591250b80499f0bf02715f02dbcd5a80088e129b1f670f1a3167a011
SHA512ce3bffb6568ff2ef83ef7c89fd668f6b5972f1484ce3fbd5597dcac0eaec851d5705ed17a5280dd08cd9812d6faec58a5561217b897c9209566545db2f3e1245
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_es-419.dllFilesize
29KB
MD528fefc59008ef0325682a0611f8dba70
SHA1f528803c731c11d8d92c5660cb4125c26bb75265
SHA25655a69ce2d6fc4109d16172ba6d9edb59dbadbc8af6746cc71dc4045aa549022d
SHA5122ec71244303beac7d5ce0905001fe5b0fb996ad1d1c35e63eecd4d9b87751f0633a281554b3f0aa02ee44b8ceaad85a671ef6c34589055797912324e48cc23ed
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_es.dllFilesize
28KB
MD59db7f66f9dc417ebba021bc45af5d34b
SHA16815318b05019f521d65f6046cf340ad88e40971
SHA256e652159a75cbab76217ecbb4340020f277175838b316b32cf71e18d83da4a819
SHA512943d8fc0d308c5ccd5ab068fc10e799b92465a22841ce700c636e7ae1c12995d99c0a93ab85c1ae27fefce869eabadbeafee0f2f5f010ad3b35fa4f748b54952
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_et.dllFilesize
28KB
MD5b78cba3088ecdc571412955742ea560b
SHA1bc04cf9014cec5b9f240235b5ff0f29dbdb22926
SHA256f0a4cfd96c85f2d98a3c9ecfadd41c0c139fdb20470c8004f4c112dd3d69e085
SHA51204c8ab8e62017df63e411a49fb6218c341672f348cb9950b1f0d2b2a48016036f395b4568da70989f038e8e28efea65ddd284dfd490e93b6731d9e3e0e0813cf
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_eu.dllFilesize
28KB
MD5a7e1f4f482522a647311735699bec186
SHA13b4b4b6e6a5e0c1981c62b6b33a0ca78f82b7bbd
SHA256e5615c838a71b533b26d308509954907bcc0eb4032cdbaa3db621eede5e6bfa4
SHA51222131600bbac8d9c2dab358e244ec85315a1aaebfc0fb62aaa1493c418c8832c3a6fbf24a6f8cf4704fdc4bc10a66c88839a719116b4a3d85264b7ad93c54d57
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_fa.dllFilesize
27KB
MD5cbe3454843ce2f36201460e316af1404
SHA10883394c28cb60be8276cb690496318fcabea424
SHA256c66c4024847d353e9985eb9b2f060b2d84f12cc77fb6479df5ffc55dbda97e59
SHA512f39e660f3bfab288871d3ec40135c16d31c6eb1a84136e065b54ff306f6f8016a788c713d4d8e46ad62e459f9073d2307a6ed650919b2dd00577bbfd04e5bd73
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_fi.dllFilesize
28KB
MD5d45f2d476ed78fa3e30f16e11c1c61ea
SHA18c8c5d5f77cd8764c4ca0c389daee89e658dfd5e
SHA256acf42b90190110ccf30bcfb2626dd999a14e42a72a3983928cba98d44f0a72e2
SHA5122a876e0313a03e75b837d43e9c5bb10fcec385fbb0638faa984ee4bb68b485b04d14c59cd4ed561aaa7f746975e459954e276e73fc3f5f4605ae7f333ce85f1b
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_fil.dllFilesize
29KB
MD57c66526dc65de144f3444556c3dba7b8
SHA16721a1f45ac779e82eecc9a584bcf4bcee365940
SHA256e622823096fc656f63d5a7bbdf3744745ef389c92ec1b804d3b874578e18c89d
SHA512dbc803c593ae0b18fd989fdc5e9e6aee8f16b893ae8d17e9d88436e2cd8cae23d06e32e4c8a8bf67fc5311b6f2a184c4e6795fed6d15b3d766ef5affc8923e2f
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_fr-CA.dllFilesize
30KB
MD5b534e068001e8729faf212ad3c0da16c
SHA1999fa33c5ea856d305cc359c18ea8e994a83f7a9
SHA256445051ef15c6c872bed6d904169793837e41029a8578eaf81d78a4641ef53511
SHA512e937d2e0f43ade3f4a5e9cdeb6dd8c8ad8b5b50a7b6b779bda727a4fe1ced93abd06720395cc69a274ce3b0f7c6b65e1eba1ecf069db64edb80d007fbb4eedbb
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_fr.dllFilesize
30KB
MD564c47a66830992f0bdfd05036a290498
SHA188b1b8faa511ee9f4a0e944a0289db48a8680640
SHA256a9b72fcb3bdb5e021b8d23b2de0caeca80ddc50420088b988a5b7503f2d7c961
SHA512426546310c12aeb80d56e6b40973a5f4dffef72e14d1ac79e3f267e4df2a0022b89e08bba8ab2ffa24f90b0c035a009bed3066201e30fe961d84ed854e48f9c5
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_ga.dllFilesize
28KB
MD53b8a5301c4cf21b439953c97bd3c441c
SHA18a7b48bb3d75279de5f5eb88b5a83437c9a2014a
SHA256abc9822ee193c9a98a21202648a48ecd69b0cb19ff31c9bbf0c79dab5f9609b0
SHA512068166cfdf879caf4e54fe43c5265a692fcaf6a9dcbf151335fd054bbec06260bc5ed489de6d46ca3fc0044bc61fa1468fea85373c6c66349620618ee869383a
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_gd.dllFilesize
30KB
MD5c90f33303c5bd706776e90c12aefabee
SHA11965550fe34b68ea37a24c8708eef1a0d561fb11
SHA256e3acc61d06942408369c85365ac0d731c5f3c9bc26e3f1e3bb24226d0879ad9c
SHA512b0c1a9d7df57d68e5daf527703f0b6154a2ef72af1a3933bda2804408f6684b5b09b822522193243fd0756f80f13d3ab0647c90d2bed1a57b4a9fea933b0aa9a
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_gl.dllFilesize
28KB
MD584a1cea9a31be831155aa1e12518e446
SHA1670f4edd4dc8df97af8925f56241375757afb3da
SHA256e4eb716f1041160fd323b0f229b88851e153025d5d79f49b7d6ecb7eb2442c57
SHA5125f1318119102fcee1c828565737ce914493ff86e2a18a94f5ff2b6b394d584ace75c37258d589cce1d5afd8e37d617168a7d7372cfd68dd6a2afcd4577a0bc51
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_gu.dllFilesize
28KB
MD5f9646357cf6ce93d7ba9cfb3fa362928
SHA1a072cc350ea8ea6d8a01af335691057132b04025
SHA256838ccd8243caa1a5d9e72eb1179ac8ae59d2acb453ed86be01e0722a8e917150
SHA512654c4a5200f20411c56c59dbb30a63bfe2da27781c081e2049b31f0371a31d679e3c9378c7eb9cf0fb9166a3f0fba33a58c3268193119b06f91bebe164a82528
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_hi.dllFilesize
28KB
MD534cbaeb5ec7984362a3dabe5c14a08ec
SHA1d88ec7ac1997b7355e81226444ec4740b69670d7
SHA256024c5eae16e45abe2237c2a5d868563550ac596f1f7d777e25234c17d9461dd9
SHA512008c8443a3e93c4643a9e8735a1c59c24ba2f7a789606a86da54c921c34cbc0cb11c88594544d8509a8e71b6a287c043b1ffe2d39b90af53b4cde3847d891ba8
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_hr.dllFilesize
29KB
MD50b475965c311203bf3a592be2f5d5e00
SHA1b5ff1957c0903a93737666dee0920b1043ddaf70
SHA25665915ad11b9457d145795a1e8d151f898ec2dcb8b136967e6592884699867eb0
SHA512bec513125f272c24477b9ddbaa5706d1e1bb958babac46829b28df99fa1dd82f3f1e3c7066dc2fe3e59118c536675a22fc2128de916ca4c478950b9992372007
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_hu.dllFilesize
29KB
MD5f4976c580ba37fc9079693ebf5234fea
SHA17326d2aa8f6109084728323d44a7fb975fc1ed3f
SHA256b16755fdbcc796ef4eb937759fe2c3518c694f5d186970d55a5a5e5d906cb791
SHA512e43636d8c947e981258e649712ad43f37c1aab01916539b93c082959fb5c6764c9c44979650092202839e812e6f252c6c3eaf66d3d195c1efd39c74c81ad1981
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_id.dllFilesize
27KB
MD503d4c35b188204f62fc1c46320e80802
SHA107efb737c8b072f71b3892b807df8c895b20868c
SHA256192585d7f4a8a0cd95e338863c14233cdd8150f9f6f7dd8a405da0670110ee95
SHA5127e67ea953ea58ff43e049ce519ae077eec631325604896479526627d688f2fa3bfc855a55ac23a76b1c9ef8cd75274265b8238423b95a2437be7250db0db31b1
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_is.dllFilesize
28KB
MD55664c7a059ceb096d4cdaae6e2b96b8f
SHA1bf0095cd7470bf4d7c9566ba0fd3b75c8b9e57ec
SHA256a3a2947064267d17474c168d3189b0d372e36e53bf0efb9c228d314fc802d98e
SHA512015dcb17b297a0aaad41c7b0b2199187e435855fd3977d16402be774622cc4f6b55d04ba9159a89e26e350c5602928c76dd9386be3974437b41888a0cfdddfa8
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_it.dllFilesize
30KB
MD5497ca0a8950ae5c8c31c46eb91819f58
SHA101e7e61c04de64d2df73322c22208a87d6331fc8
SHA256abe2360a585b6671ec3a69d14077b43ae8f9e92b6077b80a147dfe36792bb1b7
SHA512070398af980f193ff90b4afaecb3822534ef3171eca7228bce395af11ca38364bc47cab7df1e71187ef291f90978bdc37a8611d2992b1800cd1de6aa7fda09d9
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_iw.dllFilesize
25KB
MD545e971cdc476b8ea951613dbd96e8943
SHA18d87b4edfce31dfa4eebdcc319268e81c1e01356
SHA256fd5ba39c8b319c6ba2febf896c6947a0a7bae6aa0b4957bd124d55589f41849d
SHA512f1c9fccf742fa450be249dbbf7e551a426c050ae4af3d2e909f9750068a2bdc801f618eb77a6a82d13421d27949c9f2a9681a44bcb410ccdeec66b24a70f6a9a
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_ja.dllFilesize
24KB
MD5b507a146eb5de3b02271106218223b93
SHA10f1faddb06d775bcabbe8c7d83840505e094b8d6
SHA2565f4234e2b965656e3d6e127660f52e370dc133632d451ef04975f3b70194b2ed
SHA51254864e9130b91b6fd68b1947968c446f45a582f22714716bfd70b6dc814841fffe939bc2f573a257ec8c62b4ff939643211fb29cabc0c45b78a6cc70eaa3752c
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_ka.dllFilesize
29KB
MD53bc0d9dd2119a72a1dc705d794dc6507
SHA15c3947e9783b90805d4d3a305dd2d0f2b2e03461
SHA2564449ee24c676e34fea4d151b3a752e8d0e7c82f419884e80da60d4d4c1b0f8cb
SHA5128df01ad484bf2924892129c59317f3da4f79611be2ca29e208114e5ed2cb96a63f753511dc4fe97e281417366246f2fb576cc6ef2618a67803ae7ac01be7b067
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_kk.dllFilesize
28KB
MD5bcb1c5f3ef6c633e35603eade528c0f2
SHA184fac96d72341dc8238a0aa2b98eb7631b1eaf4e
SHA256fdd6bffdb9eca4542975f3afe3ac68feac190b8963f0a7244b4b8fa6382381d1
SHA512ecd79ddd9f3e6db1d0471132c453c324ab55bdead21de77392f418281bc8a2dd43e9009912896ffa3d55d4d3ef17b0aa847a084369b619eb04a2d2313641d520
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_km.dllFilesize
27KB
MD52ea1200fdfb4fcc368cea7d0cdc32bc2
SHA14acb60908e6e974c9fa0f19be94cb295494ee989
SHA2566fd21b94f62ee7474b3c3029590ddf06936105508f9bf3509620c42dc37486c3
SHA512e63b80a5929200c85c7a30a3054bd51eee2f27e603501f105073868690906f4619a27a52e58c90ac2ab5d5c34a4739dfdd2a511574afeb7d0118de88c5544f42
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_kn.dllFilesize
29KB
MD560dfe673999d07f1a52716c57ba425a8
SHA1019ce650320f90914e83010f77347351ec9958ab
SHA256ef749f70e71424d7f548d5c12283be70a6d6c59cffb1c8101b74f37ecacb64af
SHA51246bfe77a49f14293988863a8e4dd0543202b954b670940d9ad5dc6d2b46e46104d8d6206be08a941f7e02b8ff3e2e2366b7b795d02352cff18971f8d0df5fcdc
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_ko.dllFilesize
23KB
MD5cf91a1f111762d2bc01f8a002bd9544d
SHA1db2603af55b08538a41c51fc0676bc0ed041d284
SHA256baa9fae4fb8939e0b5fe0c7f393ab1ca40b52534f37bf2158a9a36331a221e75
SHA5129db864dbd194885b46f7bed9875f1e531e48f7644ce4494b8dc482c7516a6f783cd35129d2565b272dc674491a08c844a6da88bf9fa7843fcf89c96b4e0af799
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_kok.dllFilesize
28KB
MD5ca3465347e57624ee2a5dd2299d4f4cd
SHA1551a151a8d49489c90400e18c34633aa2c2b8a4b
SHA2565b9509a1ae34d89c89c8e657742495037d28cd03e1cd48aef4dfaa7aeebe29f0
SHA512a4bdd458a7628a9f0664e1000512e056718cc924510a21704ff8c69b0b251a5a1c7f6f267d66325cadda1536aaee78440348be128d082112c71732e485ac93f3
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_lb.dllFilesize
30KB
MD5269e84b82973e7b9ee03a5b2ef475e4d
SHA14021af3bfde8c52040ad4f9390eb29ae2a69104b
SHA256c3fb0cae3dc5cdd86518d60f998c3adec1c0c5804a74ffbb9a346a73d598af07
SHA512db716e2f6527af2dfeba4c22ff00e159d7cc0b482fc126e87b8b3d35b714bb382676066097352b6ebb87c8dfe7f6144e83100f0c9a9990b0d23c810b6c575c21
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_lo.dllFilesize
27KB
MD5864edbc77831a64a3e3ab972291233bb
SHA1fa1f3eb3320c1b1a329cbe786abecf2a8e625cbe
SHA256aecab1eb46075d1a1432b3e14537f860a2ded49a13ca82f17fac44b40ad2da51
SHA5123d54efd01d6317fb4746b55db2c847a506f594cff055f0db84a72ede02dbe3aa03d8e65ea06c5ae365f44312a26cdbc45ad5f9a0de46d2b9c878aeeb24566b89
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_lt.dllFilesize
27KB
MD57071c732cf3e4b3144cf07c49d8eb44f
SHA13800bf304b44d9d27ac26bed6ccc899669dc3b4f
SHA2569c75ef5c3f53c643d7bb8c5907a0cba6ca2d1d64e6bea39ce06b4ad5a20454b6
SHA512be3a0942e2af843adeb8e9b6acc7cd8adec956b761f71d8eb0a02835ee5be115ac064fda7088b0813d40ec3a24e7bb77816e9b67ef0cbdce1562c36880b15049
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_lv.dllFilesize
28KB
MD530849a9c16061b9a46a66e8e7d42ff81
SHA12d0e86535d964acce8912c6bef3cc12346b22a6c
SHA256b8075c09d33cc6b6ff22fdb29ccc3dd319ce867f4b77a1d165f6f8d8cb4977e9
SHA512298ee10ff6cab7ff38d31e3a7826dedeab8e9ccc616eae4ca2e5ec333f42e5c6744650857031d8bf35034bd46c7c01a2646362ffbbef1f421995c73ba999ff0b
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_mi.dllFilesize
28KB
MD51866ddadd9397dbf01c82c73496b6bff
SHA1b210a9df7d6a5e116fe7a9ff8d455b6cbfb5663b
SHA2569b4bb2ca3366a1935b4869796efc0601f94356b45e8613d28e023dd516f48d17
SHA51276fa5cade101d79d012e00904bf18692f85967ceea0ed7e81da4df65b85afc125a00127d9e06c8c59ffbfd2dcdc88488157b61922960559fa17d13dedca3ee59
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_mk.dllFilesize
29KB
MD5064035858a1df697913f06c972461901
SHA1b6be99ae8e55207949076955389bc8fec81937fd
SHA2564850260d2cbb4b4ff3490eb90ce55a412268ad699f946b1cd686ddf9f0403bd6
SHA5129459056e919854213117b874e61b526af4ba35c3c3e195b204c5c3e59cc4dfa2b4a45c32551e1de144842844f246f5e0d025cdcc78dbf7265ba5e26e7209cd91
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_ml.dllFilesize
30KB
MD57e90d4306c5768dfd1160ad9e2168a19
SHA14f7b17843ad226d51cfb0090235b55a29b5a674a
SHA2568ebe88477b1493733140f1fced91903276ec69c7302deed3281054b49573eb3c
SHA512f6d8b538915fa70bfb784ea7e6d4047759d8eecc822e4b76ac9666997a41901c8269a8185f29e5472bcfaa87e4b97483bd544f3fc8f656b60dca71d63b44d291
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_mr.dllFilesize
28KB
MD5468a420700d239a0cd90b95896b0d6da
SHA1ce57e3abf57c7ae13e99546b2a5e19dec03cb9b7
SHA25624b304bd40f8e63848f8d2a1ca6ac8bc032b7a700161efad61ad445787650c87
SHA512604c4cc8132c520da70c4870514610364648ec6446afa47128ac3aa8a9157932705da93e8ed4e33d56f5191d611b26b76aeba1514e9dff1a13dd32693cfddb8b
-
C:\Program Files (x86)\Microsoft\Temp\EUF627.tmp\msedgeupdateres_ms.dllFilesize
28KB
MD551230a1b9ab0dad791e583b7ee57afe4
SHA1957ba3e5d9b2df16ea3e099aab5b7e74d2055e46
SHA256a47fc6a9a75875e75f3415f068c357dd499e533849381b875272d5994c163670
SHA5125a3d754cefa1ab28748cb38021b5cbebd93fe513da0f4a7cbae98c0938acb10cdda939171d0842b09e97cb4c73f19272be665f767642ba1c5b25c709b5417edb
-
C:\Program Files (x86)\Roblox\Versions\version-034c0d4a0a9b44cc\WebView2RuntimeInstaller\MicrosoftEdgeWebview2Setup.exeFilesize
1.5MB
MD5610b1b60dc8729bad759c92f82ee2804
SHA19992b7ae7a9c4e17a0a6d58ffd91b14cbb576552
SHA256921d51979f3416ca19dca13a057f6fd3b09d8741f3576cad444eb95af87ebe08
SHA5120614c4e421ccd5f4475a690ba46aac5bbb7d15caea66e2961895724e07e1ec7ee09589ca9394f6b2bcfb2160b17ac53798d3cf40fb207b6e4c6381c8f81ab6b4
-
C:\Program Files\MsEdgeCrashpad\settings.datFilesize
280B
MD557050222eee7d085ea16952f11aaa005
SHA15f0d4e8f597c355511219fda546deefd77135272
SHA2561ebe597702bbc7a0787faca49184fab56a3ab2f62cd5151055b963182c563408
SHA512480d6b1b90ed644ff0bf0ac7d786c83917397cb534455eec923ed68b4a2364bf83ef342fd16cc01bdf940bf1640b74a7218ce4b67ab38c78137b2fe25855762f
-
C:\Program Files\chrome_Unpacker_BeginUnzipping4472_1587940558\manifest.fingerprintFilesize
66B
MD55bbd09242392aacbb5fac763f9e3bd4e
SHA114bb7b23b459ce30193742ed1901a17b4dcf9645
SHA25622b55f5d9b1bafb80e00c1304cf5e0d6057a304a2e8757b4f021b416f4397297
SHA512541e4c7998e91a5113f627c2c44e32b54878fe225b3b9476572f025f51f2b4ec4a44b102498adcc22b8fe388970645bacfafb6e7fc8a216df4d7bbfc8b0ff670
-
C:\Program Files\chrome_Unpacker_BeginUnzipping4472_1587940558\manifest.jsonFilesize
76B
MD5ba25fcf816a017558d3434583e9746b8
SHA1be05c87f7adf6b21273a4e94b3592618b6a4a624
SHA2560d664bc422a696452111b9a48e7da9043c03786c8d5401282cff9d77bcc34b11
SHA5123763bd77675221e323faa5502023dc677c08911a673db038e4108a2d4d71b1a6c0727a65128898bb5dfab275e399f4b7ed19ca2194a8a286e8f9171b3536546f
-
C:\Program Files\chrome_Unpacker_BeginUnzipping4472_1863425693\manifest.jsonFilesize
79B
MD54d0f6dc55a3b6d944e3b292680f46a30
SHA1142e7abc9791a899d4b477933f245ba1215bc87e
SHA256a33c60a634c4477e5643e1f9f7c60336d277888b7ec09491ad725f73af19872a
SHA5128b569e3d35e9477cdece700231154043fb632a491e8d14763434c7c58593d9bb8765066b94e6497222cd2d30b29ecb36ba8de18cbea54431c03a1dea8b900e8f
-
C:\Program Files\chrome_Unpacker_BeginUnzipping4472_2092888453\manifest.jsonFilesize
113B
MD5b6911958067e8d96526537faed1bb9ef
SHA1a47b5be4fe5bc13948f891d8f92917e3a11ebb6e
SHA256341b28d49c6b736574539180dd6de17c20831995fe29e7bc986449fbc5caa648
SHA51262802f6f6481acb8b99a21631365c50a58eaf8ffdf7d9287d492a7b815c837d6a6377342e24350805fb8a01b7e67816c333ec98dcd16854894aeb7271ea39062
-
C:\Program Files\chrome_Unpacker_BeginUnzipping4472_263942637\manifest.jsonFilesize
132B
MD5e2e0e30a5061d2e813d389d776cd8ffd
SHA190913c06260b62534b42c0e28bac3082cdacd19c
SHA2567f8c92b4e9da2afa5a089e37797036d18e61e4f02a4885b7887c0b98d464259f
SHA512000727f5052c846e39c62ae90032db500708e5fec5af24b8cc1f3a9d4102bc7b9be025176f01722a7c72b5e8bf85b0084cab0ebeb00fde03928c4e22869c98cd
-
C:\Program Files\chrome_Unpacker_BeginUnzipping4472_312523267\manifest.jsonFilesize
134B
MD558d3ca1189df439d0538a75912496bcf
SHA199af5b6a006a6929cc08744d1b54e3623fec2f36
SHA256a946db31a6a985bdb64ea9f403294b479571ca3c22215742bdc26ea1cf123437
SHA512afd7f140e89472d4827156ec1c48da488b0d06daaa737351c7bec6bc12edfc4443460c4ac169287350934ca66fb2f883347ed8084c62caf9f883a736243194a2
-
C:\Program Files\chrome_Unpacker_BeginUnzipping4472_648236653\manifest.jsonFilesize
102B
MD58062e1b9705b274fd46fcd2dd53efc81
SHA161912082d21780e22403555a43408c9a6cafc59a
SHA2562f0e67d8b541936adc77ac9766c15a98e9b5de67477905b38624765e447fcd35
SHA51298609cf9b126c7c2ad29a6ec92f617659d35251d5f6e226fff78fd9f660f7984e4c188e890495ab05ae6cf3fbe9bf712c81d814fbd94d9f62cf4ff13bbd9521a
-
C:\ProgramData\Microsoft\EdgeUpdate\Log\MicrosoftEdgeUpdate.logFilesize
14KB
MD591070e080e7acd64773684e8e0e92030
SHA147c44ea4d9c801b96d770f046ff12cd50e585d9a
SHA2565f04eac2751fef5c9288b78296c56585c32b821e6608d10f015380efe912c432
SHA512b16bb1a0095c1042ccba82aef00c68af95477cddb97780ddcfe94f2c9f2616ea89564ce8f183ee90d1417956508ce7a7c1d21e8255acda17377e2b3b8cf4f29d
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\doomed\10784Filesize
11KB
MD598ffc7c83b8d97713a4cbca7f0a2bb7a
SHA166a5a013267e9c62f3e7d231263259914cbe9967
SHA2566f62be77e2212a5ffde55e2455bd06a2cbfd30764545d835c7fe06a374143e7e
SHA5124cf01254ea7b4d9a8f64d2b3cebd192e96650fd9ccb06fc17e4d418b598b4e7e76bd9c8e8fca9442d9fef37340ccb392d3f9371df366ad82f3d98c3f5deb4771
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\doomed\11099Filesize
10KB
MD509e89bfe4281ea1e0b639014900711b8
SHA1ea583260fc5d166588400906b270a3e5a36310b3
SHA256a93761a1df66856e6319288e5386d4bb326bbde7041fd068cbe16bc3dfb34f14
SHA51288d94df54c87d25584ed1df281fe85234451357779ef01fe20cbcb8a83600a24c81a3e38df03d4cb79b9b78ebefa42c4d9f8a988b715afdd2bcdaabcde073356
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\doomed\1260Filesize
20KB
MD53b3538ff0f535df608b36419bd37f78c
SHA1c3a385f47cf2a956f2cd57354a5e029048123fb6
SHA256be75bf719ed5db94df45937c1591c2a4b823c5641794bcd515b4d0797e7603a9
SHA5126d1efcbabb530e6741321683cd7f89815c900eb282073aa2e3d4ad85acd13c29c2d6e34c6208205954bc6c5197be0be04a4262ad52feabeb627244ea07b7996a
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\doomed\13938Filesize
10KB
MD5c7d4fca945dd67575cf8e08eb8bd4031
SHA1d17bca706d4d7d5d527490701c05ba866e8fc64f
SHA2560463379504b4b041db4a38a64db392ea2c38e21cbba2c864ad04c8a08d587a12
SHA5128346453b2785d7a27d67d74ddacb9d88fbb65ab1a307d16a5c36356b70e9ef66832d035593483454dd77234209766cf586c94f3b3fb8cdae4f50f5962d525938
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\doomed\14304Filesize
10KB
MD54ae5902faca13c93f48d1833930bba85
SHA1fdc55f844df2581d488e2972913864ea360854dc
SHA256da3a8ab592ca56565e4c9dc7e415ab8e31ba74bfc225b573f439e2c34a69ecf6
SHA51284ccc1bfa984d4033d811a5a7dd78cf319010fa7da2e80f8bc9b9c65027397641cb056dec8d44d73324436a1b7e2b57494c50b9a88eda2d48f94499ab7a5beaf
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\doomed\16802Filesize
11KB
MD5641133b3568810f3b1aa44067e0f01e2
SHA13c1aa09e8e1edc2b74b833a6aba188e790df3376
SHA256fd3d2cdbdd8e4bdce50699f3c1616369ac7f0ee4c0420319c58c3d5d25075572
SHA51267e557071d6aa51f7c5df0a943828959263a6a83cd150078f32e250b2efda681b4fb32069d364887ef8f797d0cca3f926b458a94482010bfd9d29ab31781300c
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\doomed\20068Filesize
11KB
MD533f4bbf5b5f5fbe74a7d5fe9c1471bd0
SHA1abfc486a665181abf9aeb534e817e98643b2345a
SHA2562d702db0f6b2680577783157690a57af9347a5c616730956ab5fe67290c19ddd
SHA512c131aff19804e7099e3633bb72901d86acc7f01c377421617daa5a759a0d69e415aa6ff952d46f5baca43591892ff0395617d21b4344591c029ac7effe67a02a
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\doomed\22429Filesize
11KB
MD578367636a209bb2f9e6dd530e7134642
SHA1ccdefefff9e862565dd3bc001051ef8b59ab7a2f
SHA2564063c27cae00ddffebf5211ecdea52ea7f178cca7bd5de1cb41c3448ff53cafc
SHA512fcdeb626e1135c4b2906de5213bd5f23b9b95856ec3d42cce586a74551718724126d3e39cfeecd643b95fda6688ab26cae1e0e05505b608f416b047961ef7c11
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\doomed\26599Filesize
10KB
MD50a9d884030fdf44746c8880b04a4a380
SHA1983c901390dd711d073477a8552ca54da23d068c
SHA256f4689cb9cab9ae04a9aefcc52d9e40194cdbc063d4354f66c7e17eb6a49f1088
SHA51238d9cf6208d235560cc3dc83fbc2c37c68de477a021c0c35bfee3adfa4e68c1f9ea202f06c966cec293422b87b74c263b41b1877a3e9fe545667969226326b0a
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\doomed\27908Filesize
11KB
MD5f3524cdbaea76d1507fa10f0363b52f3
SHA1ac9cf9157bda92271ba5e33da557b8290f5830a4
SHA256686515422f649aaf9a6be4204834df03df5296e8cab6f38fbf9690558c4417d4
SHA512ab7cc3db1a459066ec7f2c13b1452208b7b47131d6cf4d4d6e0d9f3979d7df61f33d02fe6123fd10b1de02ec08c788b1a76c1b661f1b69e1070f86d10385531f
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\doomed\28092Filesize
11KB
MD582722791e4c6c1e464a4618f841c0cde
SHA1c1f9d7593cbe0ab069a96d0778268fefecd44d0e
SHA2568df7eee50434cac991567e0fb7a07d0b7046b44c96e6b47b53cd2e818af1191a
SHA5124dee930f509fb8ba4c53c782e95ee94f0b93960edcc5071f776d3c41ad474279e29a0a41ed2feccdc36b414d063b464d1875716e50bb57ef00722652498f1fcb
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\doomed\29398Filesize
9KB
MD56a87013be0f46436e54c4e789bdae86c
SHA18c25d90f7754cfb8b958d5df58b806ae8b73feac
SHA256c7d3c4b8837564ecaba1828d4a0fcd86755c25cf079d604816e59b1376d1d3a4
SHA512e098e5e87a125f8d07901c31eeeb551b1a92e8e5cae929e8b0ea625adc62f1d779dd29973f9da2b7ac321462bc0de42df385264ae91bea5c48e9c3f2b4b43122
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\doomed\29503Filesize
11KB
MD5f88b7d665540ec88caa7cf0b5caf0b2d
SHA185fa74965d7e73a9c78edfa5bb15a642d703925b
SHA256a7861226c3a536642634085a3ef1af453e2b068e7d7059f88ca7fe9b02f2780e
SHA5121039c372060a518850ae7dc7c7deb6e22f034379bd70512ff3fa0fbf3d68d9bd80dd86693093c8c2e9b8f286f93cd3464da33849cdd2c34495ebdc9f18bc2e4d
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\doomed\29699Filesize
9KB
MD533d64098a5011c91ed60b6a6f7b710d5
SHA16dbb7e0ed2e2915472366a7ce821848b85ffd6c1
SHA25623b8b4a6b61aa576fa6f5e50f24d1b8b601b9e2a19b0a75f7a29829f2047cd83
SHA512ca53885619f580f20a461efead31bd36bff724983ed5ccf3a197f061395158bda6b962d7b993f5a2233ae540b6927e7c8110af2ad61b6a8c50ceeff4f1a91b21
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\doomed\5836Filesize
10KB
MD58b46398fd11cf30e07e7959dd1c84a70
SHA1507f3bfa10304c2d19c2bd0ca24a264ec7955401
SHA256e392b11f67198379c9c714b0e83189e62c6e8b8003f5b9d39766893cfcca2741
SHA512882d1d8f3d4d24afc0347cae14a36012b59420f26f98a47612168105e235cf3a64653886799a11c9d3cc1723db10e10d4b5a913029a7475591d8f3fd5ce4b371
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\doomed\72Filesize
11KB
MD5a702b7518c7f13e2669de850e4c5ac57
SHA1cd02ef0d5bac32c072143620cbc390a389b9bc41
SHA2564a285ca68da0a98f5657a483054695920aea18b4eab7b181856c81ad60f22bf9
SHA51253ee3c84a0629fafe92aa5ad1d0e3cdc8b618b5efe17538a594eb573615a6f2fa3ddabfeade7f96de9e982ce1a477890934ac8902746675563c4dbc5b08e4e05
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\doomed\8458Filesize
12KB
MD52e4c4d2c64d7b18e45d7d0a052471400
SHA1022cfecf49a1b4f8a5d8f581fb9fc78b3858a981
SHA256cd5a3c4542639cd598089cbb842911f4903a8008f996057ec9f0ee266470c5dc
SHA512a1cfb074f802386aff1a39dd3eaf4caebf2056fe35b8e37099e0bdca6546911b193d2d0077c1200164a82883c6641ad70a43634c70d275f7aa90c19b0ded62df
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\050DB43D78BBC79DCD9ADCBAE96500FE04597F1BFilesize
84KB
MD5cb334960d2062cf8cf0bdb2052677d2f
SHA197e827e05de3ccf58d4340c5e776853b5a8b37b7
SHA25655e4ed872ae78854b0c11f524bcf3831a69633011e697c974dd2d64a1af68ebc
SHA51214dbbab053c551729e6e2c73aa022c562a46d483b9b109bb3b7dc6763ec5ccad07701ca723d48d95f438f65dbb88f8336fd567c6c04e6769ce7cc2f284721b85
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\05EB7F6F7BD0BA633716511CCCAD442933622565Filesize
13KB
MD5143d27398f4a9f6dc612b7c57d81d947
SHA15dabe90570fcb89f78a3ae178ab1162fc4d84b86
SHA2567b5c33323cde2d7a96e483a2f7e154ab959e3c20a267f8db17b2d337524b2060
SHA5129cb68866a1e8eaf2993e6dd76e1792c43ed81f021b09063d88d4d7e3fb8993690f90f60af65f13ef6e185585f39209687029aa852b842cab4409da26c23677d7
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\11993EA3BF3D355927605B079BF182BDF694A9FCFilesize
13KB
MD5c5fbef35f76d3e1eca25c6013d441336
SHA110646c0db118c598d1b2b7348e8424a90f7b58f1
SHA25680cc947b8037f970ae26d138b04b74fe9498fc98a99fab1097716d5d9825cd77
SHA51269480ff727eb9f7d94430dcd0d1189e6d55b07220b6618107823a893a9f73df635d86987a23b1b7fe9d0bce13f313cba343c8a8e6a4ef441d0a6d464d9c29da6
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\21FAEFC67E926906698F51E305415CCBAB302E92Filesize
76KB
MD5fdcabc3043929da927783a21fad16417
SHA1d94e020deeceba9d62f64fedb8d601dc5efe7567
SHA256fa6677140223e302ce3a385d1d415a710be5788402b9d09082a51726d0af1ac6
SHA512cf13d53e0f837791cad9e073d01ce2cc706fe0b61ed925513c132c92acd6d91480b84c47efaac6e8c88781c6a078b9eb9040fd0c069fe0e287845ccb79bd6206
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\2241F205D64ECA1B98C5FF7640EE620A715AC9D3Filesize
14KB
MD502b7c1991a4c1dbe51cb93124fd489e9
SHA11968abad2161633a9e69f1e6dcad97486e371513
SHA25604f1b24a0a706ae86cccab8126d79812eae5b64f2590d78cfa4a601cd179e788
SHA51250d8b9f037bd35429e1b6e09d6ea16e38d0b9039d8209c3799120ee66428cd732b2f948722037af67b3a7eef37612e4b67d23b453e1265ccb9eb9a7fdf5142c2
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\34FCD85BB24EA779B612F41F27865438665A3A8CFilesize
51KB
MD52685a8ba5cc02d03766b1e111fbe66ba
SHA1beea8c0c4446259f010eaebab33cf4de6df2436a
SHA256742ed7d4dbc7d394082269a4426991ffa1d5ab406540695c1ea37525e186674e
SHA512acec35ebadada828f17e66d4b5411edfbcdc0589e5232745810c04b9550a98d774fe943fa1f6594ead0c0f24d1e9699075a4affe756a96e88629ff20b89b2d0b
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\36BCFA23A4D04A528CE70EF12214E3995E132134Filesize
33KB
MD544515af5cc7bb8b3ff2782ba995ef8f3
SHA12d48de219e3aa56fbe58921b98f534cc5a8bcab3
SHA25683858c0aae19f7e94d25f16c7fbd4790da4c2dd2aed694114d9056f5f2f9416c
SHA512f062d2f28f56f92f9fe1491c6626e483acc5d0aa9d9f76576bab689691e8087d2e1ee523e292ac06683dd7179780c38396a9d758a8e8bfefda721c7b4f1e7899
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\3CC64668187C540A26A18501F41B51C0CD662225Filesize
21KB
MD5732c169b84f6c1d8a7e27534ea09fc48
SHA100e2b86c835948668b32d6d125f942da04e8ed62
SHA2566c3de461614e01768ef28d9cabf3c93a5e46c991f4c11cdee4804dd074ec3015
SHA512da02a9a699c90c37e6621754dbaea482d6c923707b8f799662aaaffd1eab084ea306285cc445288676d1023b040ce1d7eec0d17c03bf9f7b97f7443ee7ad233a
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\3CD97724EBF47B50AE59221DC942CCA5EE96ED82Filesize
29KB
MD5607d49ff5714023cf2824d5230b29709
SHA1e9d2524a6d4630eaac17f7a1dc7f4eb9d738d883
SHA2562393f1e3cdd90fe5942740d628082c26528be9f894f0a29a9de7fb6d635b1fac
SHA512e70772fdd7dc88d863d77c82218e23046cfbbf29c17ad53be17f70927f8dc27239143803850ab50a45fff227643231e2c6cfbd617440f945e2f77de8f35bd78f
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\45072AEAD29EA3E13217CBB7CDEF22FEFC3A04ACFilesize
95KB
MD5759c8a29a62eccb3c3ec2e4c5d20dba2
SHA17c47a74a703fdf03e4d0c22d533eb18b81ec9ad2
SHA2560ad9513c0a8ed82260bcf9b11e78cc1f46e0c3455e2b7687bb8e08ebdf5237d7
SHA512e3a6f45cd7ae451fe553276eeba18940c2c349af8ce35cd84cc78429f543a63474df13c3f9ab1bba31f6077b64f7dc33d786ded4173dcc39b2bacb62128e2c81
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\4C11E373FD9A73A5E61FCB5291518B290C3C15DFFilesize
38KB
MD501c1473e6c6bab09f696ef80795df0f1
SHA1667f083b8e38e6d164fc6039180fde331f5bd36e
SHA256b181df26318b62aef315e8b6fb55f4cbef337c6e811da31cf38f59c6d2a5e613
SHA512a425c8fb534874f90decaaa3556807bf18a8e302bde46d186090885b9900559fa198f5c4ec831cf8bdfa5717a6a864100aa7fb4b133d2155dfd6fc57b494e268
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\4E3562C55341939E493011A1EC297C2A4CAF51DBFilesize
13KB
MD5ff710fe9672c9834f59a9f9d95c95dd7
SHA12edefb14dfa3536b927bbac5f32c7b3f90be5685
SHA2562c31cd2d7149e96eaed7822b262fe41212235860955495a10117d1c7addd7ea8
SHA5120e0d51c0ea804bd8d697ef66c285233f3fe9e286602d1c5f5f74f72e170926e88585351f583cec4352356da253c692323a461a5f153844be9b4243b2a30e6d95
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\55E5E6FB4DA0D621CA2B27FEAF7A867987DF935EFilesize
13KB
MD5e0a23997038823f0c6e98f011ecf465c
SHA1de638ffeef50720ab4d81667f1e003ef58858f1a
SHA256bf76b925348f4ff5e84e330fe3a686d06d87f3bcf1fda9d8d9a6b41c5c3415dc
SHA512171cc75d84daa2368fb2b0131009b6768bf53a41d3bdc6186a55dc847fb254e6133fb56fa55988db977504ebdbde5111d0b681cb7a5906d31e38724e9af4f798
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\5759696408CC362AAD43661B4E32560E15A7872CFilesize
18KB
MD5df191f06660317c343f4be3aac3e4c44
SHA1e6a12bf83d0e9e9bfd451fd52bd503e6721a1599
SHA25603ace4e41ded86f5859d0ffc84abb7c8ca7a095285559f402f41bc78b32b76e4
SHA512580fcfd734dec6353e5744b2dfb66ed50833bfc3ad70eecc533e92999c79aee3183a72a17cd21142ff27aa26368647d746b87f9bb639ebe287069e92f8dab7ab
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\62224DC9FF9DA23B14CBE62599DA9E88CC31D1DEFilesize
21KB
MD5e14b876ec57591a868e802a5599a6585
SHA16d9bedbc3f719e039d6bedb922e928dc503e0d4d
SHA25696c8e4b2f1e8d1f7fa8d8ec5356a8be61a2e43d1d1ecc6b57cb1b7ff06b37f67
SHA5121bc3e9fcca93ab38a7f53efee0c20433232ce54e82f34d00d36dec1f1bceb84c7fb7c0846032884ac0319bc7c8c07ec9304d49a8d4b25825447585621d8dba9f
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\6B995C7CA46FC5BA0EFF9F15DA86A8CAE4C276DFFilesize
13KB
MD56c9d983fd330f62d9d062962c1438cdd
SHA1838a9cc5244b6a15f59934ceca1bdd4af41c7d0f
SHA256ecab60d5781ee733b18e76c0c70b8f0f8e9cb0f5a69d7ad8a15793f18a14a2ef
SHA5127d23b91b71e55c62c3d31cb5d7f97c6d9dc8d4c9e1c3aea9a29fccc7600a76497a835c6a7a2758ea3b3ec2435a0eb6a5e06415c9234f40b68634c75c445ab87a
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\6C3E98A33DC9184060AAD2B595620A00C6B0F8DAFilesize
39KB
MD53acc3f613ac06447e5924885c63a05c7
SHA1ed0c64527fe5865f19886f7f784adce2e1e67739
SHA25660a91099171bc91ae103b109fa7c880ebbe16c09003716fcf5cba00367268124
SHA51258db27bbd57f0881145dcc4d63a36a13c2e7b06376f3fd4affca454eea353b48eb603689d7cd1bc7ac6fbd47960f1899ac229a4ea4dee2bb73aef988969206b2
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\739025F062E977A263D0043D9E01EE529DEBBEB9Filesize
39KB
MD52a9ca37ef7bde5da84d0d08ab26581dc
SHA1ab639455e931606d6f245673341f7978e8dbd98e
SHA256ace47c5ba0f2627fdeca0e9e169aa6d4c2bfa7af671155c2ce68c7e4d459d6d4
SHA512435a433bcc927ebd6bb82e3ad97cc177e5adde15f7b03a7e552004ad4622539d00315cf8da55b133895bb1fd25c0d25a8292831f35d1f040f42d79b325bf8725
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\7505C2B294EFEF808B30D034AFB6A215F17E6F38Filesize
25KB
MD5322f4ae21f2eb702be93715f9760c06f
SHA1de3cf5916b19c979812d3193deb7333a666d870a
SHA2561ead9c5e1b8855da563024f6ac425d8401e64c59e31aeed5854752624b6457ee
SHA5128cb008a15feea088735b59b03806d13308fcd790497f9a45d948228e517434be7003c4a80f287e3fc47e1d7dadd6f390bddbad2940cf382a7e217d4c5059030f
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\770E0283785D02965FE88959E3694DB0DF013438Filesize
50KB
MD51c994d014cee0aae7c964cd8b20aa883
SHA1b28ec355d2b9105e7c55a233310f6597905c2081
SHA256689a99197a74c098959f2d7e852e939591818649239c455f852e20187b2212d0
SHA5128d8a00659a618c2ea949b9b518635314e103bf88465afed44fb995362fef03280359fff4043af13f71b4c1ad7dc0f24d36a08da8379788636ae85aecd925a381
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\890B260FBDACABD0EC51EC8B7FB870C893DBE884Filesize
51KB
MD5dbac64976f06bd011ea5e09e96bedccf
SHA1b1779ae06eb59bc272afbf85072dc81140083979
SHA256f38d9cdd8182568be57555b67c0aac7696ee18857a7a0fb8dc86ad3bc7742d19
SHA512881cc06c4c7d2b4218e722b5c068e754752cdb1eacc7dc6197c2616c1eccbf6352c642afe38fd9513bbfc2063a14668a127502757ac6a93c0ec0858da3c97251
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\8BF307C8C2D564CDB14E394B9AE3785A272FD7E3Filesize
65KB
MD51b0bb7eaf9405d04c0d1ca9797e74a1a
SHA1f8d47f657fff36f999d125f27a110565603b5c78
SHA256db510ad2ef7f3935c463f9cf296699f4ed130a9fd3b102d6241f2c5fd21ec483
SHA512200388aa006a07c3584119409f2e09da79953de327bb05cf1a337679d2df536d1f8b48ae5e6f42282f210005e0adde7137de5886674dbf6f1b656fc7b0791a23
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\96A0D2F1C4ECD10450EA183542E05ADB3BBB4257Filesize
16KB
MD5e51c75d408498d302b23f41a4986d50b
SHA12a4af87766d3bb96d3f76fad2f9e85a35f6e5759
SHA256677d9780fe6aeecbfe5ec95527b5e1d4f5810a8314b4e2866f2cf1cf7fae22e0
SHA5126559a936e078e8cd87eb4827641a843c29234620f5a964f075fdaa063822023231b5d51d5a1541f201544289b85f9a6897453c1fb48325711872131a49fd60b4
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\9B652E5D4286B393D5A4026D505B06DED703EF99Filesize
13KB
MD50d9903ec1684e6b214380b5eb3cd7cc2
SHA1bd0c895e099de9a05ebcfc47d014211e523a3129
SHA25691d9f371b0f8aca6ccefb552e487d5f60aacc04b64ee9339c118df641a537488
SHA5124ea87066aa68f56153c18a8a295630d7385a864bc76dbc8b563c54e6cb13bfffdbafe03463b2cfa90a3483545385ef337a6f1621ffe4b1dee925b1b44855febf
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\9C29916B899C579DE3BA8409A772D155B031D381Filesize
99KB
MD5c7e26e50c4007fd9c96dbcc93652313d
SHA13a3db0d1d6934320572ad34932f8a1ab7eeed28e
SHA2568624ff554e5432df06dd44c7e4ca5b4709f4a672b11b8efc4db6fb131da7cd93
SHA512a18e16c3c22258e08db9ebf171355be7097d00f412d808d737e3a33745dfaa19a35316f3b19f83deb9fae03d67933d46bcaf1199854023b13019bef0c0123afc
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\AC5B4849CAB26A6FF5E0D69715FFD2D5203EA01FFilesize
68KB
MD5698f8a1dc7a0b2148de19aa07e416d4b
SHA1a1e8a52b96a40761898d234925241cf3e53090a7
SHA256c01937411091e5031e715b56d32e9f1019e10bc9aa5f88720456b5841a937a1e
SHA512aae423ffbfae883a91f6c9103c0beb5ab79f4452c18e88f3371dfb88d3555a80bc9eaa9d7a55d3e4f3a604a1861f17211a8c9deb6b570b05362f18121a92a4ed
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\B06FDD3E01490D5AF0ADF9D7F1A2372013062A7DFilesize
49KB
MD5424d6a3ebb06133478f900d18a2597ab
SHA19002971b6482492e1aeadbb658a40db7bc0ca3d9
SHA256ad92a98d2eb405fb5cdd35b461ae3e483b8cc54b38a53b50e92a4abd15ccecc0
SHA512a7219435cd3b1fa92037e1ae22cd60a4fdda040e5e377e4d909f0da555108b0c3681a16c574870bc8bf9a47e374b9f7a04cc24614b6184d4e5f1e6633b365e12
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\B3348424017CBDB45DC17E1577E7AF671BEBE82DFilesize
67KB
MD5903f15caac78586bf07b74949623afc9
SHA16a0ab1ad1084e434515eb5e07b508c87be13d4ed
SHA256807cb3f19e24dd607e977af0657a37015695a3b8128880f1d665a17b51b082f4
SHA51289e9a7117a81c3c9acb44b48ffcca03e9a2c44e5bb2d4d80089540e723f7725c1a2097fa186f9c674c2a7dbf261b26377bee8b9c449f31eff3d7c884e2fdff7f
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\B5141334764A8AEF9D288548CE29C471E602A16AFilesize
14KB
MD53b30f92f3f2d4bc6188bc996f29e25c6
SHA187db3e9a723c7cc04996762ba8c2515bb1ef91aa
SHA25699e8e630ec383deaac5e423db9045b95d7d369dc1b63c9635d643a9c68e72a05
SHA512ad509006e99fb485a1408d1edcb1be9d326818619ec2b25d6660b38737a725dd4335613fcff9803d9f667c5b7c4c95511c1f840144cd659a16303761ccaf772a
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\B5D9B00549A67C5E8FDA11F8BBFCECEDD00925E6Filesize
13KB
MD5164a3481d7ad974651d0a615e4f867ab
SHA1bddce2660ce9bbb1a5fbc95912cf3c6a7a17acdf
SHA256b541df6874d6dee13301adbe02c1a32304629d0f899435130a5753aa27ea5396
SHA51223973632e4d0390a4783fcd63338487f3385a0f25c0edb1db4248a0d8335c0b5cd795ab7be7bc5eda244827f0ac400da64e948c05477c1336d47e415b95e3d88
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\C20E036239CAF315DF30D2CDAAC4F746820BB89DFilesize
97KB
MD5e1e7a970c9565198f732eb5efd5d8501
SHA1a45abadbf335752a9b3e7cdb64160ce7c6ab188f
SHA256490b11d4a850322a9231ff5e1362bb8e20652f406a7e5080e402fe348bef5321
SHA51232522f33c3c2234972be5a25528038d735662b3f59d9eb1870b1e95dc13499bc11a446638fcc9101e304458ca0443556468f403f242189f971515978a8a1b3af
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\C51293C4725468F5CEA71BE4411050C2DA89A9FEFilesize
60KB
MD51aa60a66c4ae2a6c16903f37e80edcfa
SHA15b4bb38a0aee9367803979745b748161c94decc9
SHA2560abbc978c99af108715ce83c7650d4f6a6a56f53fe16b6cce65f9300ea1387ed
SHA51225182a498b32f0196c570cc714909b37de1a0eff2f4258d6fa3d7262a0503c73321c2cfe66ec99a6e5b126df3cf51f795278a823a303758f541ef2718c13e69d
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\C8346BE2A3CB54E99C43B824ABAC5F037264A4D4Filesize
19KB
MD5dad3fc7e0e6a5aea87cd1b60e8bcdfd3
SHA1c753c8ba27debc0457d8dc97a6b7799391e820fa
SHA256ae063629baa6c99cf2ab3226f882f3675060cf5eb13772546aa12081b0b3b28f
SHA512c34e01519f1bbf4d0a3679f7be9ae4271f731caf1e14fa9bfc894998846c7b0e8734bd5d4996273993d1b15bb705e2f488805efd2e5383b4188c65db9947fbe7
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\CF01F0CE16B6CA73735E46B0C4F8B8877FD6677BFilesize
48KB
MD55a0e700f40587681d1dfa0250e883201
SHA14fa7a0ae8606b385e0304aad25bfd1bab32c3321
SHA256fe0b41198ba1652d88f0b43f52a76bb4d93939ea1218dc83e50241a503850762
SHA5128816bd929e27bae5d1e296b70d6db615b14b8d227f90316b80496fcce6eafb883796462bccb269ec4d327c7aab7dff1abd6c48fe1a3fb0857009cce7e9976657
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\CF5FBA70D7243048D4F0F4EAE7DB9D1742EB1D64Filesize
13KB
MD5063b183864a9064786cebacaa2f4812f
SHA171514c2ca9ddceef3a4c2b39e2f6e77c5d5c00a6
SHA25655617bb9a94ed8e5b2a6077bb06a84bed056c6150521021a739767f7a67574ea
SHA5127cee75f107cd9a5ed6acca2498cd5b04a1d654b106372696804d0e912aef9421498236195c2d01474b0375cd5c80d780b8b30345ec6ad1f1b24a22222bb25b45
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\DA784CCDD74E697C1B9356166222C06487BCEA54Filesize
15KB
MD56827366bee56d265afba29abda03f8a2
SHA170190ffaea0c6079d13c5b058e2dffd8777c415d
SHA25617b9e528a7badf54622355df75751e16c835e9575d2fa8cd7d22182d2d6a070d
SHA512adee7ca182e6d0c0d5693a22a20c236cd48920cc4e2e46df18f23945cbca1d46dd432b12bc2db078bf818357a1e72353551e42ed476849d0c3aa91fe769ccb26
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\E049536DEABDF445A5A39B7D6289FDA9A6F2C5AFFilesize
37KB
MD54a8d876716e885ef040b918926d2501b
SHA1b29f563d7726950165e5b6053d8feca5148b2f10
SHA256d8a1d73c1551d0fb0c69a171ecdc63aff1dd368e6422f2a09aa2f0c123b3264c
SHA51230f299d71d1106b6af964af2782cd2ed6bd13ecb6355269ca4d181a8913c5e9471d632cd8f6941487929c0c9a560d89022fc67fbc384354dd88aa731e1c18c85
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\E1E5F90C5D42E8AAF6267CF5C1D4F4D7211B2A50Filesize
16KB
MD5587a7ace4bab70239c354eabc53d4e4f
SHA186643f789bcd3a9c08ff4a84c636c23f4db445b6
SHA2563d2c47f4fda0493f3096185d57ef73fa004b6484f636ddd4848fdd374975319c
SHA5127813cfe69edf88854b976ac998621329db06703159699370c51a8e199e1c23a921cbea2428742c221d855fea42def196b79a0d03a36c1e9917ac309ff1295195
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\F27E0CDCD1C7E6F6CED7F2BE71ED722173C6CCABFilesize
53KB
MD5390a10aacd87b570e8d62fad7a0b8e05
SHA152008c430dc470cf446d40fd840ba909c19d0790
SHA256b12f53b855ea6ef60c3e5350ac100c192786f223bbcc8f9dfd1553d629833295
SHA5123802d0e9fa2555e69dd7b45c2427dd1471a4a78bb8eae0f3d3a2af4ce020c39db1d7610bd795504c3ed828dc60ae04bda0b1d3b6f5758c9d3b398171c0be2b24
-
C:\Users\Admin\AppData\Local\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\cache2\entries\FE6FED1DB29A04E14B95986CC4B62D0A9086C405Filesize
30KB
MD5a3c1afff9c0803dad7867f90e44f9811
SHA1f652e224759f9cc4f371d95fdfc22d08671c9edd
SHA256d46f59f31f11e9f5ac0492d5fd557cde131717b472370efc61c11d9ab48d7c93
SHA512dc113875eab5722b679eefcc14931364499474fa7a3b92302055e87ce59a52cb356c36565db5c18325fed3b0ca22f11f42d524f391ee7a1d60fc2c7c827cf3df
-
C:\Users\Admin\AppData\Local\Roblox\2659602565\InstalledPlugins\0\settings.jsonFilesize
2KB
MD54705e802fe699fb8ae96360305531f09
SHA108af92ab95ca541d1e798fe60331c26c69391aa2
SHA256fd96fc96a0ef279be4bcb8d30a732e550e3878ce4e4d89b985d86959ff639db0
SHA51242e40d0e235c17b80ea7f2ca1f67decb4f32bd0b6792622c1d05f2aca619141362b30669668c604b36d6bb788c38e981851dcc06c92a4462ea2073f59aab9257
-
C:\Users\Admin\AppData\Local\Roblox\2659602565\InstalledPlugins\0\settings.jsonFilesize
3KB
MD5d826a0ef2956a801591102f50923b3b5
SHA1d2100edf99aa9be4d92bb560a5029d31a7f145e6
SHA256cc91510153d0fb66b49445f20ee33a24710e68628933c537a545c87ff63aac27
SHA512bec122727df6f7ec0eefabce11d04a4c0e517434f0536022a876cb497e44ba3fabdf5e1106ba32b83da389af4afff1dc1bb905eaff4ec9a9462c60a3e4b43aa6
-
C:\Users\Admin\AppData\Local\Roblox\Downloads\roblox-studio\4fa63f4ccb9b1fca93ab82e51c6d4750Filesize
5.4MB
MD54fa63f4ccb9b1fca93ab82e51c6d4750
SHA11f26018c15ed5e14140ed44c28cf52a7b892fc86
SHA256685f8b14eb645f892a666cf61cf691d086fe0d3e344a245323f1fe75034869fb
SHA512a25031fb2afe1baebe9b46266192574c6c73b7fcd8e3e2897873d97b3f6232c5228fa4f633b1df98b9410808d5afe1dd470cd8f3f6dbc0c52526311b769554ab
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\CertificateRevocation\6498.2023.8.1\crl-setFilesize
21KB
MD5d246e8dc614619ad838c649e09969503
SHA170b7cf937136e17d8cf325b7212f58cba5975b53
SHA2569dd9fba7c78050b841643e8d12e58ba9cca9084c98039f1ebff13245655652e1
SHA512736933316ee05520e7839db46da466ef94e5624ba61b414452b818b47d18dcd80d3404b750269da04912dde8f23118f6dfc9752c7bdf1afc5e07016d9c055fdb
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Crashpad\settings.datFilesize
280B
MD5026dd51fd46d97312a5bb596d060b176
SHA1d158ac2d143a8286a01efc920c5e9ee8b6e1bf58
SHA256b900c7dfb7dd834b1df109c2efbb874af28e9bfa23339a68f894259bfe865a6b
SHA512dfedd4c3416c18485d22b002f5799b897a3366a4c77fb459f2999161283ed3b0979d1c203cdb1188a315a960de3affaa85ac4d9f0ad0020bd8921190654fbace
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Crashpad\settings.datFilesize
280B
MD5f6bd7ae739b5b20d7cd4a64e99a6adbd
SHA126bf9e140924cdfbcbc09b6721e5cf7857467e30
SHA25692f06fc6d5648f04836d46f9f417e4f75d84db110f3bc4bcc4fd3bbb79100683
SHA5123f4cd9034ba3865eba4f599cee5c6bd30a91f0ceb19adb29c45dfbe17f5b319bcd4a804e53a6707a6aa1fed945f46994646e101effe28ce6d21b34a73ab2eca7
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Default\Code Cache\js\index-dir\the-real-indexFilesize
2KB
MD56311d3d3370df63df8c538cddb38db5b
SHA1c8fb8a6a0c085aca6286a52e84c8d2f7b4a4a2f9
SHA25628c4ce0e38ba801e3b62a1198bd8d3dd4d3e2783305d6ebf85cc1c6c12d6aa71
SHA51237e5e653b6726735d56efdf894ebc8710f7b73e0b4730125646876dc9f12f8cdc67a7b85edd6192d8be1320c76f6f9352db85ffc9916054b945bb8f2e9eead8a
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Default\Code Cache\js\index-dir\the-real-index~RFe599f63.TMPFilesize
48B
MD5e31eb0c045419b4be5ec086288fabb84
SHA1bdeedce88809860369ccf62dbcacc9feb11bac79
SHA2567e5953afbcb719b482278f7e0b81003c9ec9fe5774c7c8c385e868f864dd5cb2
SHA512425c63acf03709c9eae9a3dab72f705e95d5fb064f156d95aca900f41f672c1ca5f7e2c96baf3564ef563abfd6c44c01a2e807965667b97a8e1cf691de55e8dc
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Default\Extension Rules\CURRENTFilesize
16B
MD546295cac801e5d4857d09837238a6394
SHA144e0fa1b517dbf802b18faf0785eeea6ac51594b
SHA2560f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
SHA5128969402593f927350e2ceb4b5bc2a277f3754697c1961e3d6237da322257fbab42909e1a742e22223447f3a4805f8d8ef525432a7c3515a549e984d3eff72b23
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Default\Extension Rules\MANIFEST-000001Filesize
41B
MD55af87dfd673ba2115e2fcf5cfdb727ab
SHA1d5b5bbf396dc291274584ef71f444f420b6056f1
SHA256f9d31b278e215eb0d0e9cd709edfa037e828f36214ab7906f612160fead4b2b4
SHA512de34583a7dbafe4dd0dc0601e8f6906b9bc6a00c56c9323561204f77abbc0dc9007c480ffe4092ff2f194d54616caf50aecbd4a1e9583cae0c76ad6dd7c2375b
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Default\IndexedDB\https_www.roblox.com_0.indexeddb.leveldb\MANIFEST-000001Filesize
23B
MD53fd11ff447c1ee23538dc4d9724427a3
SHA11335e6f71cc4e3cf7025233523b4760f8893e9c9
SHA256720a78803b84cbcc8eb204d5cf8ea6ee2f693be0ab2124ddf2b81455de02a3ed
SHA51210a3bd3813014eb6f8c2993182e1fa382d745372f8921519e1d25f70d76f08640e84cb8d0b554ccd329a6b4e6de6872328650fefa91f98c3c0cfc204899ee824
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Default\Network\Network Persistent StateFilesize
3KB
MD5f991f3a9fda79175acc7bbbdd027f693
SHA13a4479f0b2b7ed16bb4a4d23e75b12078e5cb738
SHA2563451acc0f202d88f0fc0145660588c7345fe9dcc3206f41ca48be4d8bd058cfa
SHA512c100b3e3b5a6473e7e9516f8b1c4aa2486c7eef00df61ffa6f9d3ff4b6d4c79935fb760f6a61ca2da7444f91f1a01d5edc2329221891fe9835a4f2fb8d937db3
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Default\Network\Network Persistent StateFilesize
2KB
MD5254febfa24991389d66b4121bf68f2cc
SHA14f2b4b9e05010c3da854b0e3d779a0b23965a9b3
SHA25649833e00c164bc9ab7299d6d1a30bb0d7e3b99e456ba4daecc07b78233e79e93
SHA512bfd13e04b3024bf6cb6c1228614094cf99b75f9fa4a7b743b48ed33a3aa516833bd1663612cddd5ec6e54a77e40eb97ef62531e1975550dff04776d2e936d923
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Default\Network\Network Persistent StateFilesize
3KB
MD50ad9256bc0d7c1cfc64894c331e1c879
SHA110526c6d0ebd5ebd703d4fb9d570a7f6ecfe7ca9
SHA256af2f068435bb526c4f6c8327dfadf6a571743f1fffa496e8b33fc3714432b3b4
SHA512b7e3c579b9769bac9690470757d76fe4a283cfe9de8b87f93a63769611ce475a3ecc48677291fd00f695bbd86101bc47cdbe631f1b3900d0a35486df09daa47b
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Default\Network\Network Persistent State~RFe5a5d35.TMPFilesize
59B
MD52800881c775077e1c4b6e06bf4676de4
SHA12873631068c8b3b9495638c865915be822442c8b
SHA256226eec4486509917aa336afebd6ff65777b75b65f1fb06891d2a857a9421a974
SHA512e342407ab65cc68f1b3fd706cd0a37680a0864ffd30a6539730180ede2cdcd732cc97ae0b9ef7db12da5c0f83e429df0840dbf7596aca859a0301665e517377b
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Default\Network\SCT Auditing Pending ReportsFilesize
2B
MD5d751713988987e9331980363e24189ce
SHA197d170e1550eee4afc0af065b78cda302a97674c
SHA2564f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945
SHA512b25b294cb4deb69ea00a4c3cf3113904801b6015e5956bd019a8570b1fe1d6040e944ef3cdee16d0a46503ca6e659a25f21cf9ceddc13f352a3c98138c15d6af
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Default\Network\TransportSecurityFilesize
1KB
MD5036194ee4c8572257ff9e6e2ffe1edc6
SHA14faee918c844ee7d53f80e21e551fae1941e4df3
SHA25696736d09ba976ddeae3b3eb4b7a1a8da9c0019a3db61b4ac4c864c2928a303ab
SHA512bce65713c49f19713e9d43e571e9ae219ab20c36cc21ce5167db5b850fe18d20b279deca15c435a06735844e9006f8a2725e73f28ac556e297134356c7e839d6
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Default\Network\TransportSecurityFilesize
1KB
MD549c798af63f44c62ba5cd51fb47d3ea3
SHA1e6c5f777f3f622fae7cf304c580c5beb9f1112eb
SHA256030004aed3079522f8d4f8456d23fcabb83dd28086d760dea518ccc6bac01aa0
SHA51227237c66ad99ad6df3942993be70e43337579b31bfe43e60a0302f39d973eec6488d48f267deb0196b44e700d59839c92aa6ab45711b6a8bee269fddf67974c3
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Default\Network\TransportSecurityFilesize
1KB
MD514c50946e9d1b868f15221a02269c81c
SHA1bc4960fc27aed69f129bb9a5bef2cda61b9dd6ac
SHA256122fbb624b1bcf45330029fcc2f115a26048366ebfa90a75b314c78619e1deba
SHA512e5ede759a19936d52303888ed8745b2b92bd9519b8b87cfb5052deb5b25b9a323a1116f0fee4ec2b9bbdbff0d09457f1c234308903e3f86939f50819f05a4e84
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Default\Network\TransportSecurityFilesize
1KB
MD5c4698cbf3b09bbe0bb0e6cc738e4f55a
SHA13370f1e2c6115ba464d0247bc0b5ea91bcdb945d
SHA25654b74933e5ba9b1f0d928335f7a694888792ac8cf94e58570592d32792ce2f8a
SHA512e78e947a938d23efabe5697c4466c8e6215d5e600b91681fccfece12b7d94940a04a172901e07b41f8d3e1ec70afda266b5059386deaf24422a65a9868273025
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Default\Network\TransportSecurityFilesize
1KB
MD588c55bd1053a628be1edf11c04db29b7
SHA1c4874317f638fc6090adfa92100335e4dce294fc
SHA256bf9b0e179b3bccd9ee56e0eacd37c55a4cccb7ee8dbb3b75ce8828eae11f81da
SHA5124e23c091944543e9ba629f56e6e8c135084fd211cae6869a52ecd57f928c89124388ee811d29955795208cd37f05cbf542b583f4becebc2dab24086cb0635e59
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Default\Network\TransportSecurity~RFe599d5f.TMPFilesize
1KB
MD556dfb318769c1e26954cccd93332041a
SHA1fc23eb0bcb71374f0fb592cc05d3be59ea2c5342
SHA256a6aef619477ed17e6df402bf0ec06bf23d96355a195b65cc8428f5a1f95d339e
SHA512e47aa7f8964ac599996f5d126c7befffcbc59b0083ffb1863a7221ebeeeaf50eda7f6a99b54776c149a64342345a386dd4a21907b2ca793af99587612fb302c4
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Default\PreferencesFilesize
6KB
MD54b18b3fc77d1acbdea1b1e67987bd4cf
SHA1cfdde8167b83a31dcf99e0e4446c20382329a278
SHA256e6b8a241d4601cba991d9d0c36249fba087809dcbab3db96eb0934086b03d92e
SHA512b470eea00d677ea0c0f4357214717380ca8bdf9dbfcb6ddf88eba21f8e92ee07d94f74931d82331b231036db25fbfbdd1f75ca0751eee2c01586605cf5a0d1e5
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Default\PreferencesFilesize
7KB
MD526a2726de70eaea2a92e329611582f70
SHA1ca81215444729e09a60a1f5ec61e67a10db4807c
SHA256644467339d8ff00ac52b01d84dfeb80606c96e7e9847aceb7f633ba29ecae0d6
SHA51270a7bcc7a76d808f48f993677f00a578eba7a71527c98e8960c2c9d0f2bb4aff5290b018e9dbe0f12844a42845eceb6e97d66f62f2fdb408a015c6b624179bd8
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Default\PreferencesFilesize
6KB
MD517a2fefe92b91ad9f42dc7d38b05cc78
SHA19d7d1db7361708af23e1709bb3ad21c036c00b3e
SHA256fc38e19fdd2bd7cfeaef239e6f8d6667a38f4936d9657843ac9cd068d5e8ee8b
SHA512811c006fb75c313edfd988b11888186ff400a1453078eb7f8ecbb519e6a9b3e7ad3c8c7ae9b3cb5af75752591ffba883e02598dddbec33c5dec0186f9bc223e2
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Default\Preferences~RFe59e69d.TMPFilesize
6KB
MD5975ce0f7e89d1503d406049d4c0a7e6c
SHA1767d4a6a78cf440586a32ff79660d355674ac0b2
SHA2563a76c3c367ae8b02a009e6805c0fff930982b9a979e059c4e5045bdbebdeba2c
SHA512fb97efdff491941dea5b1c00d8e51474e3b14a2fe29e99455ae169779e3b59acaf3f93cc944a8ad8d762637b5e18a4cd59818778321abe85882aca6cc15e1ce0
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\GrShaderCache\data_0Filesize
8KB
MD5cf89d16bb9107c631daabf0c0ee58efb
SHA13ae5d3a7cf1f94a56e42f9a58d90a0b9616ae74b
SHA256d6a5fe39cd672781b256e0e3102f7022635f1d4bb7cfcc90a80fffe4d0f3877e
SHA5128cb5b059c8105eb91e74a7d5952437aaa1ada89763c5843e7b0f1b93d9ebe15ed40f287c652229291fac02d712cf7ff5ececef276ba0d7ddc35558a3ec3f77b0
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\GrShaderCache\data_1Filesize
264KB
MD5d0d388f3865d0523e451d6ba0be34cc4
SHA18571c6a52aacc2747c048e3419e5657b74612995
SHA256902f30c1fb0597d0734bc34b979ec5d131f8f39a4b71b338083821216ec8d61b
SHA512376011d00de659eb6082a74e862cfac97a9bb508e0b740761505142e2d24ec1c30aa61efbc1c0dd08ff0f34734444de7f77dd90a6ca42b48a4c7fad5f0bddd17
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\GrShaderCache\data_2Filesize
8KB
MD50962291d6d367570bee5454721c17e11
SHA159d10a893ef321a706a9255176761366115bedcb
SHA256ec1702806f4cc7c42a82fc2b38e89835fde7c64bb32060e0823c9077ca92efb7
SHA512f555e961b69e09628eaf9c61f465871e6984cd4d31014f954bb747351dad9cea6d17c1db4bca2c1eb7f187cb5f3c0518748c339c8b43bbd1dbd94aeaa16f58ed
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\GrShaderCache\data_3Filesize
8KB
MD541876349cb12d6db992f1309f22df3f0
SHA15cf26b3420fc0302cd0a71e8d029739b8765be27
SHA256e09f42c398d688dce168570291f1f92d079987deda3099a34adb9e8c0522b30c
SHA512e9a4fc1f7cb6ae2901f8e02354a92c4aaa7a53c640dcf692db42a27a5acc2a3bfb25a0de0eb08ab53983132016e7d43132ea4292e439bb636aafd53fb6ef907e
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Local StateFilesize
1KB
MD578701195aa20ea542ee55c05025330f4
SHA1ff4160eaebe72992d450f173fc6d99c60b02f889
SHA256a48dade650f9231bd8b61c1411783ac8b928528559491676fd442ed72769c8da
SHA512b21edbb1b8b912edbf7f95efcdf716110baa4142dc808c16c583f74876bbeda0f65612d67c00bcc1b9107173d83617862f10b3a4fc33a9738d543e453ed8f728
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Local StateFilesize
3KB
MD55d189df34760a07a8374107f4f6635c1
SHA11c217eb54feb5379d0d2c6ce8c8d2b91a095e9d6
SHA256e568d3eeba978363fafb558e6015b3ee80d210cfa645932fc7757aa88053aa1d
SHA512fbcf9165da6baa09a2213092dc2ee568d822a08842c7a8f34a40aa95b4b2097567fd0cc9d5ce78e565e676610d6ddb09a53e4c83dc138272ac4952b055369061
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Local StateFilesize
4KB
MD574e31e7d5dd6146be47f4ede5a06e761
SHA1a9f92df56b012110e190a9eaefac818e5a7d3024
SHA25611f8137b8ba8041f5556b80741806ac3e79f53cedc8b1f3955866ed2f22ec320
SHA5126a67d5064c18ed66818edb66ddfafe59cce7d75487ae3e0eb534431627b387d3879d3b2c1f3a3e7c3aee4ba02eeaeaadc6152e80d09f136913ead65dd87d7a20
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Local StateFilesize
16KB
MD533e35bff584d64bb1d0ad011597eca13
SHA12343b6f6234adb5a8317929aaa7e2566f7ba8bb4
SHA2560de58a9180c084de357ffdf928237d44581a51f140060efea5bfc8c2d4ed959b
SHA51265003743823785c3f53ad9391f01fea68a22ba898ee89a48636b9b51887f7cdc03bab2782b494c442ed394636ca99703c39ba573c02e22ecb0085294306221b6
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Local StateFilesize
20KB
MD5d4af78e4cfb471059f390999a47f1b24
SHA1914a9e18af7b874653d8396681c4b67f54c9835d
SHA25629a653066d53627610c118d834210a0c2bab3070580b7c466ad949041a0b8b44
SHA512011492d2b91c55f38945d8538435ac865b0321a415c5b4963b2999544e4f228c38f6ce4304e11d7066026aea5750b6215b0291cd543a2a6895fe41d17572fc67
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Local StateFilesize
18KB
MD5173c0803cc3974dc97b2e00f9533d26e
SHA1be885cd237436c1b12a13f1e589a92b310afb713
SHA256655fc3890f900c78535a3b77c649f1c0b6ba9fb8013b3326af861204ac393be6
SHA512c8c410f8ae22dbed46c44f23dd7572afd359ced3cdb845a3366558c549c7e41ce4e12326b8cb3f9568dfba27ebf8aca05aac6be89706db7b3c8048e7cc445006
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Local State~RFe5949c1.TMPFilesize
1KB
MD568ee26d366fc057b61b538fb1b0d3ff3
SHA13e118ec45531f35ab06a3f770c0190be6eb28ed2
SHA256a37ed7b222c818eea7d23c3b304829408552e144ad8e0585a76fa84b137df643
SHA512c88d81c57f6b19ead68abe883738067214d3f8951af16b7b7b9570560d4294b4be8964942f1053799e47f873f1b277176b7e7b0052c0a84471529996d9f2164e
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Trust Protection Lists\1.0.0.26\Mu\AdvertisingFilesize
24KB
MD5131857baba78228374284295fcab3d66
SHA1180e53e0f9f08745f28207d1f7b394455cf41543
SHA256b1666e1b3d0b31e147dc047e0e1c528939a53b419c6be4c8278ee30a0a2dbd49
SHA512c84c3794af8a3a80bb8415f18d003db502e8cb1d04b555f1a7eef8977c9f24e188ae28fc4d3223b52eab4046342b2f8fd0d7461130f3636609214a7b57f49cb4
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Trust Protection Lists\1.0.0.26\Mu\AnalyticsFilesize
4KB
MD5da298eacf42b8fd3bf54b5030976159b
SHA1a976f4f5e2d81f80dc0e8a10595190f35e9d324b
SHA2563abd2e1010e8824f200878942e0850d6e2620a2f0f15b87d32e2451fdda962ec
SHA5125bf24c2df7cc12c91d1fb47802dbac283244c1010baa68bfae9eb5eb8ee25758156bb1e21f6cc3f55e7d71e5c330888ffd41469b2630eb86237c9970d7ede75e
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Trust Protection Lists\1.0.0.26\Mu\CompatExceptionsFilesize
689B
MD5108de320dc5348d3b6af1f06a4374407
SHA190aa226d3c9d50cf4435ecdd2b8b0086d8edeb8b
SHA2565b462316a51c918d0bae95959bf827cb9c72bbd84ffb0e43b750aa91fbf3ba53
SHA51270f30c45e20b7cddd0cba6476af9338975cec8e40b8b19603af5fa859a34c6eb2138957daaa263633fe65213e2186402d05d9d29ad53e8f311335555116314c2
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Trust Protection Lists\1.0.0.26\Mu\ContentFilesize
6KB
MD597ea4c3bfaadcb4b176e18f536d8b925
SHA161f2eae05bf91d437da7a46a85cbaa13d5a7c7af
SHA25672ec1479e9cc7f90cf969178451717966c844889b715dff05d745915904b9554
SHA5125a82729fd2dce487d5f6ac0c34c077228bee5db55bf871d300fcbbd2333b1ee988d5f20ef4d8915d601bd9774e6fa782c8580edca24a100363c0cdce06e5503f
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Trust Protection Lists\1.0.0.26\Mu\CryptominingFilesize
1KB
MD516779f9f388a6dbefdcaa33c25db08f6
SHA1d0bfd4788f04251f4f2ac42be198fb717e0046ae
SHA25675ad2a4d85c1314632e3ac0679169ba92ef0a0f612f73a80fdd0bc186095b639
SHA512abd55eff87b4445694b3119176007f71cf71c277f20ea6c4dcadfb027fdce78f7afbcf7a397bd61bd2fa4bc452e03087a9e0e8b9cc5092ec2a631c1ebb00ee25
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Trust Protection Lists\1.0.0.26\Mu\EntitiesFilesize
68KB
MD5571c13809cc4efaff6e0b650858b9744
SHA183e82a841f1565ad3c395cbc83cb5b0a1e83e132
SHA256ab204851f39da725b5a73b040519c2e6aaf52cb7a537c75802cb25248d02ec1b
SHA51293ff4625866abf7cd96324528df2f56ecb358235ff7e63438ac37460aeb406a5fb97084e104610bb1d7c2e8693cabedc6239b95449e9abb90252a353038cb2a2
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Trust Protection Lists\1.0.0.26\Mu\FingerprintingFilesize
1KB
MD5b46196ad79c9ef6ddacc36b790350ca9
SHA13df9069231c232fe8571a4772eb832fbbe376c23
SHA256a918dd0015bcd511782ea6f00eed35f77456944981de7fd268471f1d62c7eaa3
SHA51261d6da8ee2ca07edc5d230bdcbc5302a2c6e3a9823e95ccfd3896d2e09a0027fece76f2c1ea54e8a8c4fa0e3cf885b35f3ff2e6208bf1d2a2757f2cbcdf01039
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Trust Protection Lists\1.0.0.26\Mu\LICENSEFilesize
34KB
MD5d32239bcb673463ab874e80d47fae504
SHA18624bcdae55baeef00cd11d5dfcfa60f68710a02
SHA2568ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903
SHA5127633623b66b5e686bb94dd96a7cdb5a7e5ee00e87004fab416a5610d59c62badaf512a2e26e34e2455b7ed6b76690d2cd47464836d7d85d78b51d50f7e933d5c
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Trust Protection Lists\1.0.0.26\Mu\OtherFilesize
34B
MD5cd0395742b85e2b669eaec1d5f15b65b
SHA143c81d1c62fc7ff94f9364639c9a46a0747d122e
SHA2562b4a47b82cbe70e34407c7df126a24007aff8b45d5716db384d27cc1f3b30707
SHA5124df2ce734e2f7bc5f02bb7845ea801b57dcf649565dd94b1b71f578b453ba0a17c61ccee73e7cff8f23cdd6aa37e55be5cb15f4767ff88a9a06de3623604fbf0
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Trust Protection Lists\1.0.0.26\Mu\SocialFilesize
355B
MD54c817c4cb035841975c6738aa05742d9
SHA11d89da38b339cd9a1aadfc824ed8667018817d4e
SHA2564358939a5a0b4d51335bf8f4adb43de2114b54f3596f9e9aacbdb3e52bef67e6
SHA512fa8e1e8aa00bf83f16643bf6a22c63649402efe70f13cd289f51a6c1172f504fedd7b63fc595fb867ecb9d235b8a0ea032b03d861ebb145f0f6a7d5629df8486
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Trust Protection Lists\1.0.0.26\Mu\TransparentAdvertisersFilesize
105B
MD557d5a3548911886de2f3bd3172e808ed
SHA1ca932af3b25f245ce931fbc6cf10299e5fbe35a7
SHA256d2cd0bef5f45daf490c53e705d6f67dfe12390c72a00efa6f5117432bd8edb8c
SHA512933194509d305b2a60b38c149ba1d74e142ef15647242b287844d263006d33ffa38b6ea263c89cb821a9277d41f0cfda95a0eda830f3a5ef8df5ba80d3bbc818
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Trust Protection Lists\1.0.0.26\Sigma\AdvertisingFilesize
2KB
MD5326ddffc1f869b14073a979c0a34d34d
SHA1df08e9d94ad0fad7cc7d2d815ee7d8b82ec26e63
SHA256d4201efd37aec4552e7aa560a943b4a8d10d08af19895e6a70991577609146fb
SHA5123822e64ca9cf23e50484afcc2222594b4b2c7cd8c4e411f557abea851ae7cbd57f10424c0c9d8b0b6a5435d6f28f3b124c5bc457a239f0a2f0caf433b01da83f
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Trust Protection Lists\1.0.0.26\Sigma\AnalyticsFilesize
432B
MD501f1f3c305218510ccd9aaa42aee9850
SHA1fbf3e681409d9fb4d36cba1f865b5995de79118c
SHA25662d7286cd7f74bdfda830ee5a48bce735ee3661bda8ceac9903b5627cbd0b620
SHA512e5b665e981f702a4a211d0569bb0bc42e3c29b76b3f75aaf8dc173f16f18f7c443f5cf0ccf1550df3aa2b151e607969c2c90ab1a6e7a910dfeb83854cea4e690
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Trust Protection Lists\1.0.0.26\Sigma\ContentFilesize
48B
MD57b0b4a9aafc18cf64f4d4daf365d2d8d
SHA1e9ed1ecbec6cccfefe00f9718c93db3d66851494
SHA2560b55eb3f97535752d3c1ef6cebe614b9b67dddfcfd3c709b84c6ecad6d105d43
SHA512a579069b026ed2aaef0bd18c3573c77bfb5e0e989c37c64243b12ee4e59635aaa9d9c9746f82dcc16ca85f091ec4372c63e294c25e48dfffbed299567149c4e2
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Trust Protection Lists\1.0.0.26\Sigma\CryptominingFilesize
32B
MD54ec1eda0e8a06238ff5bf88569964d59
SHA1a2e78944fcac34d89385487ccbbfa4d8f078d612
SHA256696e930706b5d391eb8778f73b0627ffc2be7f6c9a3e7659170d9d37fc4a97b5
SHA512c9b1ed7b61f26d94d7f5eded2d42d40f3e4300eee2319fe28e04b25cdb6dd92daf67828bff453bf5fc8d7b6ceb58cab319fc0daac9b0050e27a89efe74d2734e
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Trust Protection Lists\1.0.0.26\Sigma\EntitiesFilesize
42KB
MD5f446eb7054a356d9e803420c8ec41256
SHA198a1606a2ba882106177307ae11ec76cfb1a07ee
SHA2564dc67d4b882621a93ffdb21a198a48a0bc491148c91208cf440af5f0de3ef640
SHA5123cc3a521b297e4f48ed4ba29866a5ade380c9f0c06d85bea4140e24b05c6762d645df3d03d0a7058383b559baa3ae34ad3ed2b06017e91a061632862911a823b
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Trust Protection Lists\1.0.0.26\Sigma\FingerprintingFilesize
172B
MD53852430540e0356d1ba68f31be011533
SHA1d3f622450bcf0ced36d9d9c0aad630ebccfcb7ff
SHA256f1f413704c32a28a31a646f60cad36cc2da793e143f70eee72ae56f736df8054
SHA5127a4faa493c141ea88d6cd933dfc0b50ef6d25983323db2b931c7512e039859d60c4935e56b771264ca72b45c035b1962ad8680d616eaaf04fbc5a6e0b674e435
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Trust Protection Lists\1.0.0.26\Sigma\LICENSEFilesize
66B
MD55b7baf861a48c045d997992424b5877b
SHA12b2bd9a13afe49748abf39faf9eb29ed658f066e
SHA25644071e0fcffb9a9a32e8fa7010bb18dbc41afd0b176f81bf700b15b638a88a51
SHA5124820b41aa5ff4d934a583e1f0b93b1512631102bb2dfdb74792a2f0dcf9907da7680c02a5ddd2492a1e6d58cdada3453d9e38bb8deab6ce831ff36a7f8de016c
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Trust Protection Lists\1.0.0.26\Sigma\OtherFilesize
91B
MD509cedaa60eab8c7d7644d81cf792fe76
SHA1e68e199c88ea96fcb94b720f300f7098b65d1858
SHA256c8505ea2fe1b8f81a1225e4214ad07d8d310705be26b3000d7df8234e0d1f975
SHA512564f8e5c85208adabb4b10763084b800022bb6d6d74874102e2f49cc8f17899ce18570af1f462aa592a911e49086a2d1c2d750b601eedd2f61d1731689a0a403
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Trust Protection Lists\1.0.0.26\Sigma\SocialFilesize
3KB
MD5318801ce3611c0d25c65b809dd9b5b3c
SHA1b9d07f2aa9da1d83180dc24459093e20fe9cf1d8
SHA2562458da5d79b393459520e1319937cfc39caadbc2294f175659fae5df804e1d03
SHA5127daff0253da90f35bf00141b53d39c7cadacf451a7ecf1667c4ca6e8aed59a0c4a6b44ddc2afffa690e12c2134eddb9f46f72e4317ce99c307d9e524a5fd1103
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Trust Protection Lists\1.0.0.26\Sigma\StagingFilesize
16KB
MD539bdf35ac4557a2d2a4efdeeb038723e
SHA19703ca8af3432b851cb5054036de32f8ba7b083f
SHA25604441a10b0b1deee7996e298949ac3b029bd7c24257faf910fe14f9996ba12ae
SHA512732337f7b955e6acaf1e3aaa3395bc44c80197d204bd3cbb3e201b6177af6153cc9d7b22ad0e90b36796f92b0022806c32ac763eaec733b234503890900bf284
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\Trust Protection Lists\1.0.0.26\manifest.fingerprintFilesize
66B
MD5fc8af1e27127535b4eea55c8c2285865
SHA1dc9fb2a8fe358f84f4f2749460ef15507e7ecb07
SHA256c76f988dee6149c0c21f7f657688a7fcaa20b0dc83881efe14d58d9be3f5236b
SHA512ec847bd27383c37cd67d9204e5dc55256ca0303c0d7696558de650b569ef8f9eb747603180ae6561f884bbe6eb519a23c18fa4a646c43d58799f01744c2b9de3
-
C:\Users\Admin\AppData\Local\Roblox\RobloxStudio\WebView2\EBWebView\TrustTokenKeyCommitments\2024.6.30.1\keys.jsonFilesize
6KB
MD5f28538640e8188694f6d4b34572af2ac
SHA122927034985be25e0b6699ab79599640d7dc80ac
SHA2566168c389c4cd4afb71407f5a86f71260a6613dc375ce3a74e393b3d9fc245ec2
SHA512c70ab902188ce0d4003e93122f0bd9ab0904d51ffda1fd5e3202ae10de7b8c6bcff5134b0c55544e8c983ca51fe4b859e602c3fb7da09134beb8fc99fd3de1cb
-
C:\Users\Admin\AppData\Local\Temp\Roblox\http\0309a8e909b55e1fcd86d2628693475dFilesize
91B
MD5fba343fecf778db9de079a05b4dec457
SHA1f8fc4d9d461cf3ca73305103475efe64bcc8aebf
SHA256d3f4742def343d4c4d31c02a1a34b5cc8c719da5f218e6b45e2924f732b7e55a
SHA512b166a51384204d83984262b3df76b288d209ab622b13c760775462ae4c3b92cb801c3c688db696f8d705df402ea65504bce65ebff1032673a2f174097e017216
-
C:\Users\Admin\AppData\Local\Temp\Roblox\http\419322953fc6ba7c5676a6f5ab5b99d6Filesize
91B
MD5b448a0c9298a7339d40d2ee1fed98112
SHA1290b5315b5e12a2ec523622d32c784e361f68268
SHA25659738f47989304072d287cca71f56f0392072f8db43a0994b684123c6c55d5b5
SHA5127d261b7648ec9854384eeaec5d87cf10835b54c2f840a9147e7d1faa5cbb194074184d002ea7235976f80af5f842f871420644bee5b7ba4d07ff77a6247ec4e2
-
C:\Users\Admin\AppData\Local\Temp\Roblox\http\419ff0bbafa99fb5f1a9d5ec4d51d313Filesize
91B
MD57342a963fbe8b3a5bce98391f7c91497
SHA1d937946afb025eb344dac220aa2d8d3494c759af
SHA2563306f048a000d6a897405f05abfd4c6ea181af54c1b77f6db995e8e00a7a17cd
SHA512fbf1bc5dd2e4dd9a4bda60309ad0a9d891b60f5666d003af712028b28e740f060d6d745f1d33fbd8db95f0d6d8b4f1ba18a8c9622bf52fba1d14f2299ddc4053
-
C:\Users\Admin\AppData\Local\Temp\Roblox\http\446d73ec784045aa649a878657a00cfdFilesize
91B
MD56330cb088f7a8ab40a30e02e0b2bd22e
SHA1a7ed5126af301f850795df16bda850a00079f65d
SHA2560a3bbf5563d3dfb2e5ee0dd7f0ea83b76f733230cfe4f2d73dfa603de9f4fa7f
SHA512b8e7f1489deba2a045ed0649f322ede4f5176a6932f07b0129f66a61a05b273f02957080479b91a62edf00c69b41d5e6b9ac19510465c3257b00499cab36558c
-
C:\Users\Admin\AppData\Local\Temp\Roblox\http\4ab438a4615d5020ba51646cf85628dfFilesize
112KB
MD593fa712ba67720d99c91460898f46323
SHA186048af7b243f9d28d6a2132fa5c0e1da154a25f
SHA256376e98f769b85800338fe29488c0b1e47fb2e1acb30e7f4b45e58bca0a6e107c
SHA512362dce01fe1a38c0a0604623fdbe2a08c736696c43fdc79bcdffec80152f47641153a287cb8afb841038933a451084ef7df7e57a1f2b0141faae4c4908f0a530
-
C:\Users\Admin\AppData\Local\Temp\Roblox\http\4daa106f1d02a1b8a036ffdabe94e524Filesize
68KB
MD5fc72fb667b5e311750b62c66f56d8977
SHA1982de2650fb6460d5488624347550ebd6bcf72b9
SHA256248e893dc8ef2b52c9f6f4ef56b4d853b154c8cfedff570da9e6dcf5ef732163
SHA512957fb8f0522f1ac7ef5b56249f27b5b7b1f86fcac148900ea5fbee9ee6cb9e13cd37c68b148b5eaf5e773b491a3d3735f64af3aa85a9fa78ba94e47f1674ce13
-
C:\Users\Admin\AppData\Local\Temp\Roblox\http\70f0241ac1a77d790d54af92d9e6a016Filesize
12KB
MD5d32707386cb24872edcefb73567126d2
SHA10f9781d22e8bb9afa6c82d477b99fe5cdb61be5d
SHA25664d06ca2887a3d98d74d4e51e2071ef682ffc3a24b5e7c4e5b68b4e02f4b85d4
SHA51258f65774cae35bac01d2ff9657b4b46c8aadfe8f36ea04575fae7dc9e93b7afea48e1eb15ddecfe9a189d090b59b3ee7cedd0b38a0a54fd4a49e272c7807eb0c
-
C:\Users\Admin\AppData\Local\Temp\Roblox\http\775734913391c16891c6a2406f0183ceFilesize
11KB
MD59622d9fc11e70bc1b9afc41f00514137
SHA14b7420aa96109359b6bed08d5df84fcfa7bda8af
SHA256b60a33787d4610e4acf342b6c5728045cf0eb43c6c640c1e198132548904db5f
SHA512eb8f5f896c9c335cffa139f7905229810a43ea901188f7d86b18834853912251cc1ec717a01fd480c330f01cb0beb7ee1b2c5ccba3669b61e50cb2b1d20b22f1
-
C:\Users\Admin\AppData\Local\Temp\Roblox\http\9e28d9b3e7042ef35827ef526070e180Filesize
13KB
MD5e63df0bc9aa04910ccdfa33307d6521b
SHA1b084d4109d7d0d86724733e4742ded23ccc513aa
SHA256cd8884064828e411798c40be70926d2530c0b6a447680922655fbfa9ebf67268
SHA5128094da9f987405e5ea9ee1b9676a66667280e55cbdbbbe7fce0d977cb32ff2c0c192feca86ee781942efcd09a3b9290a41884a05855a621302e85bd3534dc6a8
-
C:\Users\Admin\AppData\Local\Temp\Roblox\http\a25332ca5f5eae67d9e02fbcc631215dFilesize
11KB
MD5850cbf2648a100afc52813158feb5578
SHA1d0c2495d91b07424f62e87e3055c636dbcb82a32
SHA256abdddcd10491b5d75e435d19e09c7ca55aa2acf747c8784678a635b411106f1c
SHA512c5fcb5f32e1d3934a6d698c54dfe69495a64136ead6b65afa3f0c1c94fe36b64eb92e4bf11456f271d18b47c1c3655e8108371f6c9c10be48824c2388b165dec
-
C:\Users\Admin\AppData\Local\Temp\Roblox\http\a423ab66878a77eddee923ed2dab8abeFilesize
14KB
MD506432e7b3aecc630f6f4561d9e50907e
SHA13181344f1f2c029ace4b63ba004d504322f378ea
SHA256fb6bd24dcd25a18f6a2ef6f8d210d976b7f0c9cc796cb1fbed64268edfd1cea0
SHA512b9c8614c486581a3e9db765a2f8060060d6fecd40c6d22d0900da3981da3adea3e269e978d5793cdbbedf1f336d3c5dad0d03e2605ca9c48a2d0357962630a51
-
C:\Users\Admin\AppData\Local\Temp\Roblox\http\b564a5b0978176943772a32bff21e970Filesize
269KB
MD58491358a98140b56e4995586d772c45b
SHA177aadc068773e81c84426268c2eb60bf2bd92f7a
SHA256d6c694078cd2b23cda7b5fa42b8601fde9303914adff83256906639c1455eb1f
SHA512c3b8d4e46992c3f64ade76ba29adc11889afa51ff818f593c957e0e77ddfc35104f5320c48c230dd75cd5df886f8b06341308a461ab34ad843b70a38ed50fe69
-
C:\Users\Admin\AppData\Local\Temp\Roblox\http\bee42de6660ec8977b9cc896aa151419Filesize
40KB
MD5f2c30fc925c4f08743642a64b32b1330
SHA1127537bcdb262f5b461c20e1058453071852036f
SHA256aa4c2da3772fa59a4f5141c3e8b2e1963676989bd340ddef9c5785edc41f2391
SHA5129844e2ad33c69c27c1797d343b3288dbcf40caedc7478f1f4b96d9653eb1faba50c758e112c66dd95425c8de05e09a9d5603b59c5c8714875e925274bbd6f113
-
C:\Users\Admin\AppData\Local\Temp\tmpaddonFilesize
442KB
MD585430baed3398695717b0263807cf97c
SHA1fffbee923cea216f50fce5d54219a188a5100f41
SHA256a9f4281f82b3579581c389e8583dc9f477c7fd0e20c9dfc91a2e611e21e3407e
SHA51206511f1f6c6d44d076b3c593528c26a602348d9c41689dbf5ff716b671c3ca5756b12cb2e5869f836dedce27b1a5cfe79b93c707fd01f8e84b620923bb61b5f1
-
C:\Users\Admin\AppData\Local\Temp\tmpaddon-1Filesize
8.0MB
MD5a01c5ecd6108350ae23d2cddf0e77c17
SHA1c6ac28a2cd979f1f9a75d56271821d5ff665e2b6
SHA256345d44e3aa3e1967d186a43d732c8051235c43458169a5d7d371780a6475ee42
SHA512b046dd1b26ec0b810ee441b7ad4dc135e3f1521a817b9f3db60a32976352e8f7e53920e1a77fc5b4130aac260d79deef7e823267b4414e9cc774d8bffca56a72
-
C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6824f4a902c78fbd.customDestinations-msFilesize
8KB
MD52517cca7c291700a177724418238fb0a
SHA1f62d6f79ec61bf3e808d1bc14057862171deabc5
SHA256b17dd723cf09d840819e0bf67d6060a6eef80fa514d183b8d1b05cad7c732242
SHA5124fba6f0173782081d11142f01307645eb07652400815dad52353514eaeb711ddd0dc4b42f8c28e16dc1475fe14d993e521d2ffd4d1dc1046edf154e3d8d6a008
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\AlternateServices.txtFilesize
7KB
MD5a1f2e9ff8f53ccaeb36dbe634747c1ad
SHA14876a0794f984477b328ac67c7f9bcfc416d59f2
SHA25686a8c804558b5dccb4c3a0f241b53d4381a1ef42fbcb52dec281d34b48b10fa3
SHA512d0f4399492a5a715d2dc12ee5635e54a4ae33f63425ae692d9b8df94f93a013edeb8bc7d77f57b7a7670b8c8ce3ec8ea5bf1ab9df09217934b511759118e5f5a
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\SiteSecurityServiceState.txtFilesize
2KB
MD50128be8e8e43d757a0cb3043766656bc
SHA18ecaac5e26517e44bc032d1f536e180d130d02ee
SHA25626ece6eccf296e6a187e10568833620d5e57e73b2e3305aa91f82d883dd205b6
SHA5128c9b095d21535d6229919c8fa828021d585f57dca82decb72667734937c66886396a7e84132e438c1d17b9cfd702ca98b4b013ff553909b395e08117f43d558e
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\bookmarkbackups\bookmarks-2024-07-02_11_JYHA1IDH37kjW2ud4k03lA==.jsonlz4Filesize
948B
MD57c618c5385632ed123b3929e89a9104a
SHA1877eef304b5bca587c7f990c0b187b1fbe666e04
SHA2560c052f029079668e4dc8f63800c6b2fd173fd97de4739e5a66d017df726f519c
SHA51278e0c287f8367a1fb67e816d2ca7a675cf880d1a245ebc1f4633c52a54bd7fb8ba4564d7c07ceddd9f56c9efbaadb2da1ccc928f679645b3d91dcdac7c87d64e
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\broadcast-listeners.jsonFilesize
204B
MD572c95709e1a3b27919e13d28bbe8e8a2
SHA100892decbee63d627057730bfc0c6a4f13099ee4
SHA2569cf589357fceea2f37cd1a925e5d33fd517a44d22a16c357f7fb5d4d187034aa
SHA512613ca9dd2d12afe31fb2c4a8d9337eeecfb58dabaeaaba11404b9a736a4073dfd9b473ba27c1183d3cc91d5a9233a83dce5a135a81f755d978cea9e198209182
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\datareporting\glean\db\data.safe.binFilesize
2KB
MD5a7996c5bf8b850c571f3328fafe90b7e
SHA170f49d898337e2cce7d973c0a3abe702962dde6f
SHA256f8f9039cec42ceb656b973520bbb9282c414cee0ba631193a0a932c6861c2d24
SHA51250008e391046d5e3eeee94ed1c393acc9858d8983933854c07ddaee4a24316891ccf9258e80f50bd977d82159f6ea37d0dfdc28e7497c5600eae462ad10bba3f
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\datareporting\glean\pending_pings\43fa4c8a-c7a5-471f-a8de-ac8b892a9b26Filesize
746B
MD5399f13376a4d46ca900654e8f4aa1463
SHA155d92fe3eb526acb87640ef75b38d224950d564b
SHA256b3ccb215a9ef1266aa93c9192bac422d7b9f7b97e033700b9fb05ba9e19cab3c
SHA512592258cd2259297a2b1dfdf621908a0612f67316de274185f8d73f819a4a7a5bba393b26559e77e864b1558c3a16e424c149301d5e481579ee2695d692b978b3
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\datareporting\glean\pending_pings\fe7052cd-cce0-444b-abec-672561a7a3e8Filesize
10KB
MD56b073892df696e9e1679ea685aebc9e7
SHA15f92a1bb73aa37344999f3f69c9af2ce4779d94d
SHA25660bb2a33252473575941c1f389f9deb6592cc9d50272968ba43656a0501639ef
SHA5128f59983b1b227d3707d482847456f5859d43d0b31dba22d0b0d6a01b3ddcb0ae3338bd4c97d0587de96f8b85b794cd86a299a5b52371f1179f486aaba8e91a69
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\extensions.jsonFilesize
36KB
MD5163c023280e94de1801dc728742a36b7
SHA13955c5ebd70334251652f410f0344eddf1f5e671
SHA256a330908573217bca13c3c1b40b947bbe9ebbba3518151e5794f412a6e5f37be6
SHA512b48f48158e66b62872f56c943648778b75af454d4d8299b393ac0b315a2e269816dd6195b58549566af1395952589cd0b1049b5948361ffdffb72348e33241f2
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\gmp-gmpopenh264\1.8.1.2\gmpopenh264.dllFilesize
997KB
MD5fe3355639648c417e8307c6d051e3e37
SHA1f54602d4b4778da21bc97c7238fc66aa68c8ee34
SHA2561ed7877024be63a049da98733fd282c16bd620530a4fb580dacec3a78ace914e
SHA5128f4030bb2464b98eccbea6f06eb186d7216932702d94f6b84c56419e9cf65a18309711ab342d1513bf85aed402bc3535a70db4395874828f0d35c278dd2eac9c
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\gmp-gmpopenh264\1.8.1.2\gmpopenh264.infoFilesize
116B
MD53d33cdc0b3d281e67dd52e14435dd04f
SHA14db88689282fd4f9e9e6ab95fcbb23df6e6485db
SHA256f526e9f98841d987606efeaff7f3e017ba9fd516c4be83890c7f9a093ea4c47b
SHA512a4a96743332cc8ef0f86bc2e6122618bfc75ed46781dadbac9e580cd73df89e74738638a2cccb4caa4cbbf393d771d7f2c73f825737cdb247362450a0d4a4bc1
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\gmp-widevinecdm\4.10.2557.0\LICENSE.txtFilesize
479B
MD549ddb419d96dceb9069018535fb2e2fc
SHA162aa6fea895a8b68d468a015f6e6ab400d7a7ca6
SHA2562af127b4e00f7303de8271996c0c681063e4dc7abdc7b2a8c3fe5932b9352539
SHA51248386217dabf7556e381ab3f5924b123a0a525969ff98f91efb03b65477c94e48a15d9abcec116b54616d36ad52b6f1d7b8b84c49c204e1b9b43f26f2af92da2
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\gmp-widevinecdm\4.10.2557.0\manifest.jsonFilesize
372B
MD58be33af717bb1b67fbd61c3f4b807e9e
SHA17cf17656d174d951957ff36810e874a134dd49e0
SHA256e92d3394635edfb987a7528e0ccd24360e07a299078df2a6967ca3aae22fa2dd
SHA5126125f60418e25fee896bf59f5672945cd8f36f03665c721837bb50adf5b4dfef2dddbfcfc817555027dcfa90e1ef2a1e80af1219e8063629ea70263d2fc936a7
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\gmp-widevinecdm\4.10.2557.0\widevinecdm.dllFilesize
11.8MB
MD533bf7b0439480effb9fb212efce87b13
SHA1cee50f2745edc6dc291887b6075ca64d716f495a
SHA2568ee42d9258e20bbc5bfdfae61605429beb5421ffeaaa0d02b86d4978f4b4ac4e
SHA512d329a1a1d98e302142f2776de8cc2cd45a465d77cb21c461bdf5ee58c68073a715519f449cb673977288fe18401a0abcce636c85abaec61a4a7a08a16c924275
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\gmp-widevinecdm\4.10.2557.0\widevinecdm.dll.libFilesize
1KB
MD5688bed3676d2104e7f17ae1cd2c59404
SHA1952b2cdf783ac72fcb98338723e9afd38d47ad8e
SHA25633899a3ebc22cb8ed8de7bd48c1c29486c0279b06d7ef98241c92aef4e3b9237
SHA5127a0e3791f75c229af79dd302f7d0594279f664886fea228cfe78e24ef185ae63aba809aa1036feb3130066deadc8e78909c277f0a7ed1e3485df3cf2cd329776
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\gmp-widevinecdm\4.10.2557.0\widevinecdm.dll.sigFilesize
1KB
MD5937326fead5fd401f6cca9118bd9ade9
SHA14526a57d4ae14ed29b37632c72aef3c408189d91
SHA25668a03f075db104f84afdd8fca45a7e4bff7b55dc1a2a24272b3abe16d8759c81
SHA512b232f6cf3f88adb346281167ac714c4c4c7aac15175087c336911946d12d63d3a3a458e06b298b41a7ec582ef09fe238da3a3166ff89c450117228f7485c22d2
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\handlers.jsonFilesize
439B
MD5eb4710f71d10ed586a4305aa2aa2ed5f
SHA1e030c03e8911496ba858daabb18714934e097a7f
SHA256d8819cb4472578db7f248442bfe7fd2b939c7f0b27cc427ab531eb9b5e02c94f
SHA51265a0d593a1e952e08f0f80ffd715a17021618251b52a9ffaf278fdc5acb0fe2c86cffcac4005434795bde45e27f8cd178601a23c2392f64f708969a3aff27263
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\prefs-1.jsFilesize
6KB
MD55d3efea1c4c77377db025d843601c447
SHA14dd6a1136e59de4e42813a447bce19a5239ba2dc
SHA25668bd4e227087157aa1b90e44aaa8c9a066dd2382e135f95947477f438d112469
SHA5123e3215381cfb461f379db05fd48e96b4fb3a0338a479087394434ec9caf691a6ce266a23c7bef4f71548fb59a35af1fd70872adc009363a5be4e26f537c9d1ba
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\prefs-1.jsFilesize
7KB
MD5357cacecc748ac63f406786a71613c81
SHA1c056055a9375f022bebcd7c3120bcfc957373169
SHA2566034b673043593ec268b0ba938b7b79a994b59fb6baae58badfc714f6d560c6c
SHA512a2f7c6d00308ca92d1d1bff61c085d0ceff669d44bd485487163beb739e5969b9f18952a10ba0c99da6ab7da6c7ee86a38b502c49402a86520ab9d97c9ff4147
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\prefs-1.jsFilesize
7KB
MD5152c78d71583c39e04b0a6636964e001
SHA15147a3481e868e523f123d04c4f3d67944958623
SHA2562cfce4bf5293f11f7c590b24b9d7e1102f0613383434f0ef6d617cc31bdc6558
SHA512daa8ceebc841bb31eeb291cf3c132357b477330817d6dfcfc1ee8f1fe2884d6eb5ea803204c28b62e3de104b2b5a2bdb5036fccd712c3c37dee2b1f4122b04af
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\prefs-1.jsFilesize
7KB
MD5e0c7516ef79096e45c333afa81e31270
SHA1d1fc2c6557a31d817a278579761f57663a7adcb1
SHA25641713c72f0b9a5739505d8d9f7787f743f95efe433fba39ab2387925f6b23346
SHA51231541ac2389389034ade4099f247c9a643ab99ec3b9d850a19e38b3fc3fae096c14824f643a2d00e1c397425abe3573062f87bd28a9cd22652cd61cffe92bdf7
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\prefs-1.jsFilesize
7KB
MD5fe284e606e7912615fb7dd964b52a915
SHA1eb98477c4d7959757d398478471c8e339a8d497e
SHA256d43553029cb266bce7725afd1d19c45f852107cf63ff5d8e827375bb62214ce4
SHA5123c3c23a0e3b8d42097b8a1efcfb3d11e8bb298f5ff40a45919a18c608fb547e8a0961263634efe53fc68e437ab5804e520d33da1dc947d90d44e88784e5617fb
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\prefs-1.jsFilesize
7KB
MD594c940043870144b1fdfac9866fadcf5
SHA1b5b4896e2fb8c7b4963b86f912893a89ac59a221
SHA256871148facb2b2d288e977ae4931401aa9453bead84373b7b2246eda5a2c56142
SHA5122c5288dbc6bd428917e029d571ef1869c77ef4a638d27b2e6c3f067fe530aa9b7e631f2d97a7cc3e05e4cfac917e5176d94dee1546611184327f3c3962999278
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\prefs-1.jsFilesize
7KB
MD55b323afaaefae1243735113d14d1f65e
SHA1eded52285164dadca793596a7d8d13db97c27108
SHA256ab5f6d6a2c7fddc3f094b95adc82e5f6740f85ddd2ac8f03bff75ccd982b0f2e
SHA5126ae8a62cf06c14096115ae465e11e10fc324e6c329583e29c2399370e50db86f69dbf890487d64f4ead302b9e4547c7c7b79fa1299dfd2c0b99ddd447c75dc7f
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\prefs.jsFilesize
7KB
MD55e0811c1af69397304fee3db14b2c180
SHA1147f80241c9f44562b9eb8e69071a0b348d284ce
SHA256b3ae43e4af4dc6dae3918666953474220a5ecd74bbdf2d1ba3bf0fdf01effc61
SHA5127d61fd2934a30e2c571f76ffdcba08c6ca55bc12ffb61558101f4d9549faead332e607201613bfe6071014dc7ca3210f3d48090131faa4f79a61e54bc8dfb587
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\prefs.jsFilesize
7KB
MD5734cf753effd8cb5afb3adb456a2458d
SHA143969871a5f210e8557b909d0ed69c9e8fee7e25
SHA256e59da29c994d46ed47b117c0ad4ddfd1f8d2330770a77b5ab5a703a6713ea24b
SHA512adf40c6bacb90f7603a0abdf317f93633afc446680494b926ff7273f7244538b02cc316106f3093412aa4de07613613f28e70eaf92c7f3a5e7ec45610658cf8a
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\sessionCheckpoints.jsonFilesize
90B
MD5c4ab2ee59ca41b6d6a6ea911f35bdc00
SHA15942cd6505fc8a9daba403b082067e1cdefdfbc4
SHA25600ad9799527c3fd21f3a85012565eae817490f3e0d417413bf9567bb5909f6a2
SHA51271ea16900479e6af161e0aad08c8d1e9ded5868a8d848e7647272f3002e2f2013e16382b677abe3c6f17792a26293b9e27ec78e16f00bd24ba3d21072bd1cae2
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\sessionstore-backups\recovery.jsonlz4Filesize
12KB
MD58226441a06ed1fa2327620f3130ce12a
SHA1cf7c68e97123315380e44c99cd5f5a54ac4c419a
SHA256044cd8515ffcc39e59e883d1493df21495d5d9b36d89f0703fbf7542dcd59592
SHA512d52ff3c1bff76ea7b043a3efdbec96f494160be74305b8198163db7bb5e4a431b4ad01b58b9d81290638ea8f2a039df3baf333fe2e83d41bbe8f3520e4b15999
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\sessionstore-backups\recovery.jsonlz4Filesize
9KB
MD52ed9ab0310674d7ef83cab20fa961e8b
SHA15ffa698402711ed5bb6a88866b89627d2fd90a82
SHA256c5ac9b228ad73c184d910af7c4950813ca330857bd0504e1ca941ce94176c99b
SHA51213205c8e94dc416e01f33dd21088c526f27c66fc4fc326865af305f2a90361b3793f3484e22eb381d7947d7f80d700f1621f095c4e8e6f246fc7e48be19b8955
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\sessionstore-backups\recovery.jsonlz4Filesize
1KB
MD59cd43d6548a7afc2aa993c0f7672fb19
SHA1d10f77d9c1f59c0d0d49de3a721c710a934bd082
SHA256c2a410d5a903c2a5c4a03f0d3a94bfca8826dc866a2dffaca764ee72b8ca076f
SHA5121c9cd4cad77aebf28aabba2470338a1109c60881f7f0240e0d98451412c3618719ec874e8ec44fd319a92ee961c2bf3cd3b4d1b92492d0a2413a4dd45490ea0a
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\sessionstore-backups\recovery.jsonlz4Filesize
12KB
MD579234fca27af9edee744ccd5953c0e22
SHA1c54bea3a74aae7ad2517d1ca9a757fe1a971f2e3
SHA2562973f33a6ede718d47c5bac076bdc0665555ff32b8dda3a93d7afce8c183e935
SHA5121b1af6fb6d3233168cdd3623382771cb8b3fbe154170907fc7962e4695b72e6a435a50e150db106e5ecd32044eb2922e0f8c0bf476f3bdd4d807b38cd55bbe06
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\sessionstore-backups\recovery.jsonlz4Filesize
8KB
MD59132398c3a38f566816e5b71fd473170
SHA1da1755b556e6ba201c73ce56ac4f73a47b322f85
SHA2563f20a9a3d22125ecd3b5c6c6c7a316bf97603e2f73703b9cfa00a725bbc7eb4d
SHA512ec03f2891bb75173b6a684850acded8dd175f51bb15db6da5179bd34191c0395dd76cfce5c561607c99912b1e88d1fa849059adbb921bdc141b7e92b177c3ce7
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\storage\default\https+++www.roblox.com\idb\3140325527hBbDa.sqliteFilesize
48KB
MD5ea0172f25cf07fc8fe0c668eb03bf662
SHA17306204dd0d416ecc9dd457a68c843498ff5ec4f
SHA25668da76aa14ee3e69a1a0e2a5d29e0e25c0d4e05ad2f62fa2f1a2e00864e9975c
SHA512f1c5285b1e97ce6c65a0238ebb9f2f4dfd314e5d5a0cf743189281dad4ddbe23b27ba0941e5398da59a064ebb9085df3c7198b61e2e7899d967c7fc365659bc0
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqliteFilesize
184KB
MD57f868e557b098795d645df9ea302427f
SHA1001f3306144559b4049a8ab139b4139f51e59c0e
SHA256b228e23ecfb7965e3badefcbb031de0b4bb887634bccb34a826ac8ac89124ac5
SHA51256fd8aa514cc25db5a2c9191d665eaffe90182cc5e4f15317e0cfbc9adf7336d9ad937d20384b0504f784e5939b76b4c4b0020cb06e4a472c650355cc6c4c89a
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqliteFilesize
208KB
MD525f69812bdc231c573f20cca9d7d2c74
SHA16f23523fb24e1b5924a1857a7b4f023b50465931
SHA256e0ea10f1f88eba976bc71c529424a1cb01c972be917ba58eaa43c84dab246ffb
SHA512e979de9ffeebd53827325524c93326952772d416f2340d350739b9af0c0e10697a7f0caa493f60ef6222c2b89135200d77ad41e01248045cd3faa5c5c10709a9
-
C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\wjyk7j4u.default-release\targeting.snapshot.jsonFilesize
3KB
MD52021f527852660d00d72aeb2cccba221
SHA19fdf585685b5c26c98e5a98074e5be70730739bb
SHA256077aa2211f729a63e6bb88aa918192c70cdb95418119096e82743c2b64bcc427
SHA5127729293c3e2cb09374e2537354a0fd1fa146d4ac8f266b2a1720ef26818273060deaf1ecae739c44dcd6ccb4336632c9b7f29d0868e0183def1098bf7295b9e7
-
C:\Users\Admin\Videos\Captures\desktop.iniFilesize
190B
MD5b0d27eaec71f1cd73b015f5ceeb15f9d
SHA162264f8b5c2f5034a1e4143df6e8c787165fbc2f
SHA25686d9f822aeb989755fac82929e8db369b3f5f04117ef96fd76e3d5f920a501d2
SHA5127b5c9783a0a14b600b156825639d24cbbc000f5066c48ce9fecc195255603fc55129aaaca336d7ce6ad4e941d5492b756562f2c7a1d151fcfc2dabac76f3946c
-
memory/1356-309-0x0000000072F50000-0x0000000073160000-memory.dmpFilesize
2.1MB
-
memory/1356-383-0x0000000072F50000-0x0000000073160000-memory.dmpFilesize
2.1MB
-
memory/1356-369-0x0000000072F50000-0x0000000073160000-memory.dmpFilesize
2.1MB
-
memory/1356-322-0x0000000072F50000-0x0000000073160000-memory.dmpFilesize
2.1MB
-
memory/1356-305-0x0000000072F50000-0x0000000073160000-memory.dmpFilesize
2.1MB
-
memory/1356-313-0x0000000072F50000-0x0000000073160000-memory.dmpFilesize
2.1MB
-
memory/2164-302-0x0000000000B60000-0x0000000000B95000-memory.dmpFilesize
212KB
-
memory/2164-318-0x0000000072F50000-0x0000000073160000-memory.dmpFilesize
2.1MB
-
memory/2164-303-0x0000000072F50000-0x0000000073160000-memory.dmpFilesize
2.1MB
-
memory/2164-379-0x0000000000B60000-0x0000000000B95000-memory.dmpFilesize
212KB
-
memory/3316-434-0x00007FFBF1610000-0x00007FFBF1611000-memory.dmpFilesize
4KB
-
memory/3440-535-0x00007FFBF1610000-0x00007FFBF1611000-memory.dmpFilesize
4KB
-
memory/4464-304-0x0000000072F50000-0x0000000073160000-memory.dmpFilesize
2.1MB
-
memory/4960-1629-0x0000029B4A650000-0x0000029B4A651000-memory.dmpFilesize
4KB
-
memory/4960-385-0x00007FFBD4C80000-0x00007FFBD51CC000-memory.dmpFilesize
5.3MB
-
memory/4960-384-0x00007FFBD65C0000-0x00007FFBD69C2000-memory.dmpFilesize
4.0MB
-
memory/4960-386-0x00007FF74B270000-0x00007FF74C270000-memory.dmpFilesize
16.0MB
-
memory/4960-1624-0x0000029B38EC0000-0x0000029B390C0000-memory.dmpFilesize
2.0MB
-
memory/4960-1621-0x0000029B4ACC0000-0x0000029B4B100000-memory.dmpFilesize
4.2MB
-
memory/4960-1626-0x0000029B4A650000-0x0000029B4A651000-memory.dmpFilesize
4KB
-
memory/4960-1628-0x0000029B4A660000-0x0000029B4A661000-memory.dmpFilesize
4KB
-
memory/4960-1625-0x0000029B4A650000-0x0000029B4A651000-memory.dmpFilesize
4KB
-
memory/5036-507-0x00007FFBF1870000-0x00007FFBF1871000-memory.dmpFilesize
4KB
-
memory/5036-506-0x00007FFBF09E0000-0x00007FFBF09E1000-memory.dmpFilesize
4KB