Gridinsoft Logo
File Icon

RobloxPlayerInstaller (2).exe Trojan Wacatac Analysis

Technical Analysis

File Name RobloxPlayerInstaller (2).exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.179.174
Database Version 2024-06-22 23:00:29 UTC

Trojan.Win32.Wacatac.dd!n

Malware family: Wacatac

Wacatac malware demonstrates multiple malicious capabilities including data theft, system compromise, and secondary payload deployment. It can download additional malware components including ransomware to extend attack impact.
N/A
Detection Rate
5,720,984
File Size (bytes)
2024-06-22
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
cc2642d7f60c3ffe2a0b6823d559efc3
SHA1
d34443c1c0fb4adf924f2c20b1e5dd7be1368f04
SHA256
06f1730effee44d4a801c1971be1c6a4cb232cfe83f83d6d33addd20ca7e9ff5
SHA512
c6090784e3c0a52a0c1ef81a9fcd224b60535f38b82ecce5dbca1ca1d5b6a4e037a228470b6a07b341d7facd32a52c027e1061c9f28b4b0ff78024f083708655
ImpHash
bc703aa25a661c5cbf56690623c291dd

PE Analysis

Basic Information

Icon
Hash: b423ca67aaea047fe3295fc7c4dc1efd
Fuzzy: e77261c35382a2126a491c6a691a1197
dHash: 3cf0a4cccedac0c0
Image Base 0x00400000
Entry Point 0x006f2820
Compilation Time 2062-05-15 23:38:35
Checksum 0x00582f60 (Actual: 0x00582f5f)
OS Version 6.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
PDB Path C:\buildAgent\work\ci_deploy_ninja_boot-x86_git\build.ninja\common\vs2019\x86\release\Installer\Windows\RobloxPlayerInstaller.pdb
Digital Signature The expected hash does not match the digest in SpcInfo
Imports 16 libraries
Exports 0 functions
Resources 60 Resources
Sections 5 Sections

Version Information

CompanyName Roblox Corporation
FileDescription Roblox
FileVersion 1, 6, 0, 6300556
LegalCopyright Copyright © 2020 Roblox Corporation. All rights reserved.
OriginalFilename Roblox.exe
ProductName Roblox Bootstrapper
ProductVersion 1, 6, 0, 6300556
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 3,432,566 bytes 3,432,960 bytes 6.72 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ E9134CC84C165D3F3C171A198BA2F307
.rdata 0x00348000 947,026 bytes 947,200 bytes 6.16 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5BC3A93B9E988487ADCECF9633F16C35
.data 0x00430000 13,773,808 bytes 797,184 bytes 0.77 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE E900FF98F889078CAB72B3EC6D1AB86B
.rsrc 0x01153000 376,992 bytes 377,344 bytes 7.05 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ B390D56006DEA5B34074236445A29404
.reloc 0x011b0000 154,428 bytes 154,624 bytes 6.65 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ D0B04CFB15C4D6EFBE3CDA9259BF4470
Entropy Analysis Alert

3 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 60 (374,434 bytes)
Resource Type Count Total Size Percentage
PNG 8 33,956 bytes
9.1%
RT_ICON 10 81,737 bytes
21.8%
RT_DIALOG 1 254 bytes
0.1%
RT_STRING 36 23,064 bytes
6.2%
RT_ACCELERATOR 1 8 bytes
0%
RT_RCDATA 1 233,235 bytes
62.3%
RT_GROUP_ICON 1 146 bytes
0%
RT_VERSION 1 776 bytes
0.2%
RT_MANIFEST 1 1,258 bytes
0.3%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The expected hash does not match the digest in SpcInfo

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Win32.Wacatac.dd!n Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win32.Wacatac.dd!n without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware