File name:

FiveM.exe

Full analysis: https://app.any.run/tasks/ddd05358-83c9-4676-bd7e-aad1621ebcd0
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: July 25, 2025, 01:07:53
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
loader
qrcode
arch-scr
arch-doc
arch-html
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 7 sections
MD5:

FC8A8FFAC2B41442D04E534F58AD39DF

SHA1:

355770ACF4FEDCFA009B2F3A986B9FF189B517D2

SHA256:

672EE97A665325BC227FCC7958002876BB6FFD967B7820193ECA6D5800FB27F4

SSDEEP:

98304:D+152z1PBaMJBFQf68VXK8A8te5BBf2shx99fBk25dETb9z2MYgzXeN4jqxa8NNg:zwe4Oa

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Opens an HTTP connection (SCRIPT)

      • wscript.exe (PID: 432)
    • Sends HTTP request (SCRIPT)

      • wscript.exe (PID: 432)
    • Creates internet connection object (SCRIPT)

      • wscript.exe (PID: 480)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • FiveM.exe (PID: 4724)
      • FiveM.exe (PID: 4168)
    • Starts itself from another location

      • FiveM.exe (PID: 4724)
      • FiveM.exe (PID: 4168)
    • Write to the desktop.ini file (may be used to cloak folders)

      • FiveM.exe (PID: 4168)
    • Reads security settings of Internet Explorer

      • FiveM.exe (PID: 4168)
      • GameBar.exe (PID: 5236)
    • Creates a software uninstall entry

      • FiveM.exe (PID: 4168)
    • Process drops legitimate windows executable

      • FiveM.exe (PID: 4168)
    • There is functionality for taking screenshot (YARA)

      • FiveM.exe (PID: 4168)
      • FiveM_DumpServer (PID: 2312)
    • The process drops C-runtime libraries

      • FiveM.exe (PID: 4168)
    • The process creates files with name similar to system file names

      • FiveM.exe (PID: 4168)
    • Starts application with an unusual extension

      • FiveM.exe (PID: 4168)
    • Creates a Stream, which may work with files, input/output devices, pipes, or TCP/IP sockets (SCRIPT)

      • wscript.exe (PID: 4836)
      • wscript.exe (PID: 480)
  • INFO

    • Reads the computer name

      • FiveM.exe (PID: 4724)
      • FiveM.exe (PID: 4168)
      • GameBar.exe (PID: 5236)
      • FiveM_DumpServer (PID: 2312)
    • Creates files or folders in the user directory

      • FiveM.exe (PID: 4724)
      • FiveM.exe (PID: 4168)
      • FiveM_DumpServer (PID: 2312)
    • The sample compiled with english language support

      • FiveM.exe (PID: 4724)
      • FiveM.exe (PID: 4168)
    • Checks supported languages

      • FiveM.exe (PID: 4724)
      • FiveM.exe (PID: 4168)
      • GameBar.exe (PID: 5236)
      • FiveM_DumpServer (PID: 2312)
    • Manual execution by a user

      • wscript.exe (PID: 4196)
      • wscript.exe (PID: 5960)
      • wscript.exe (PID: 5300)
      • wscript.exe (PID: 3980)
      • wscript.exe (PID: 3872)
      • wscript.exe (PID: 2148)
      • wscript.exe (PID: 3048)
      • wscript.exe (PID: 480)
      • wscript.exe (PID: 4836)
      • wscript.exe (PID: 432)
    • JScript runtime error (SCRIPT)

      • wscript.exe (PID: 5300)
      • wscript.exe (PID: 3980)
    • Checks proxy server information

      • slui.exe (PID: 2732)
    • Reads the software policy settings

      • slui.exe (PID: 2732)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:07:17 08:24:07+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.36
CodeSize: 3403264
InitializedDataSize: 1927168
UninitializedDataSize: -
EntryPoint: 0x28da20
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.16538
ProductVersionNumber: 2.0.0.16538
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Cfx.re
FileDescription: FiveM
InternalName: FiveM
FileVersion: 2.0.0.16538
LegalCopyright: (C) 2015-2022 Cfx.re
OriginalFileName: CitizenMP.exe
ProductName: FiveM
ProductVersion: 2.0.0.16538
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
154
Monitored processes
17
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start fivem.exe fivem.exe gamebarpresencewriter.exe no specs gamebar.exe no specs slui.exe fivem_dumpserver gamebarpresencewriter.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs wscript.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
432"C:\Windows\System32\WScript.exe" C:\Users\admin\Desktop\main.jsC:\Windows\System32\wscript.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
1
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
480"C:\Windows\System32\WScript.exe" C:\Users\admin\Desktop\src_cfx_apps_mpMenu_parts_LegalAccepter_PDFRenderer_tsx.chunk.jsC:\Windows\System32\wscript.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
1
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1040"C:\Windows\System32\GameBarPresenceWriter.exe" -ServerName:Windows.Gaming.GameBar.Internal.PresenceWriterServerC:\Windows\System32\GameBarPresenceWriter.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Gamebar Presence Writer
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\gamebarpresencewriter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
1660"C:\Windows\System32\GameBarPresenceWriter.exe" -ServerName:Windows.Gaming.GameBar.Internal.PresenceWriterServerC:\Windows\System32\GameBarPresenceWriter.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Gamebar Presence Writer
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\gamebarpresencewriter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
2148"C:\Windows\System32\WScript.exe" C:\Users\admin\Desktop\src_cfx_common_services_servers_source_WorkerSource_worker_ts.chunk.jsC:\Windows\System32\wscript.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
1
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2312"C:\Users\admin\AppData\Local\FiveM\FiveM.app\data\cache\subprocess\FiveM_DumpServer" -dumpserver:2124 -parentpid:4168C:\Users\admin\AppData\Local\FiveM\FiveM.app\data\cache\subprocess\FiveM_DumpServer
FiveM.exe
User:
admin
Company:
Cfx.re
Integrity Level:
MEDIUM
Description:
FiveM
Version:
2.0.0.16538
Modules
Images
c:\users\admin\appdata\local\fivem\fivem.app\data\cache\subprocess\fivem_dumpserver
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2732C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3048"C:\Windows\System32\WScript.exe" C:\Users\admin\Desktop\color-scheme.min.jsC:\Windows\System32\wscript.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
1
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3872"C:\Windows\System32\WScript.exe" C:\Users\admin\Desktop\src_cfx_apps_mpMenu_parts_ThemeManager_BackdropBlur_worker_ts.chunk.jsC:\Windows\System32\wscript.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
1
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3980"C:\Windows\System32\WScript.exe" C:\Users\admin\Desktop\jquery.jsC:\Windows\System32\wscript.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
33 466
Read events
33 345
Write events
117
Delete events
4

Modification events

(PID) Process:(4724) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\CitizenFX\FiveM
Operation:writeName:Last Run Location
Value:
C:\Users\admin\Desktop\
(PID) Process:(4168) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\CitizenFX\FiveM
Operation:writeName:Last Run Location
Value:
C:\Users\admin\AppData\Local\FiveM\FiveM.app\
(PID) Process:(4168) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:DisplayName
Value:
FiveM
(PID) Process:(4168) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\FiveM\FiveM.exe,0
(PID) Process:(4168) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:HelpLink
Value:
https://cfx.re/
(PID) Process:(4168) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\FiveM
(PID) Process:(4168) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:Publisher
Value:
Cfx.re
(PID) Process:(4168) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Local\FiveM\FiveM.exe" -uninstall app
(PID) Process:(4168) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:URLInfoAbout
Value:
https://cfx.re/
(PID) Process:(4168) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:NoModify
Value:
1
Executable files
418
Suspicious files
117
Text files
224
Unknown types
56

Dropped files

PID
Process
Filename
Type
4724FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.exeexecutable
MD5:FC8A8FFAC2B41442D04E534F58AD39DF
SHA256:672EE97A665325BC227FCC7958002876BB6FFD967B7820193ECA6D5800FB27F4
4168FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM - Cfx.re Development Kit (FxDK).lnklnk
MD5:6C668C42F02083EF9E17B90BD8216FE5
SHA256:B51CF9A78F39E754F796883126085EBF21C17A377C25DE31E8A47F8E0FF1892F
4168FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_game_1_aslr.bin.tmpexecutable
MD5:98EF5E2190853602E9D2E33F4AD5F83E
SHA256:0054B35B9DAA280CCD0ABF32E66C0562D9633690B99D1DE12E2232B38B53567D
4168FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_game_2189_aslr.bin.tmpexecutable
MD5:759F5AD36E5327BAF80E83286666466E
SHA256:F2F11B5B506CE6A848AA472F8B1905CD81E0840AE2A786A092588E76760F4D3F
4168FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitiLaunch_TLSDummy.dll.tmpexecutable
MD5:7892DF9CF0675D24AEF591E09F6E9040
SHA256:CA15E331CF6A9BD97CEBF4790DBE96E617409BBC375DD4032B82DE495301B8D4
4168FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitiLaunch_TLSDummy.dllexecutable
MD5:7892DF9CF0675D24AEF591E09F6E9040
SHA256:CA15E331CF6A9BD97CEBF4790DBE96E617409BBC375DD4032B82DE495301B8D4
4168FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_game_1604_aslr.binexecutable
MD5:BDA6965ECACE39125C1D1D0AB6972286
SHA256:398EB804BAC414A01B41EDBEF547F81CB7ADB58572BBBEE3030DB8B65461F268
4168FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_game_1_aslr.binexecutable
MD5:98EF5E2190853602E9D2E33F4AD5F83E
SHA256:0054B35B9DAA280CCD0ABF32E66C0562D9633690B99D1DE12E2232B38B53567D
4168FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_game_2060_aslr.bin.tmpexecutable
MD5:374914BBAFC751AE9CB8D8109C4F65C7
SHA256:CE59043E1B5F4C8194F16F0AC628AEA28249F5E4CEBC10D14AC89DAD680CD3B5
4168FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_game_1604_aslr.bin.tmpexecutable
MD5:BDA6965ECACE39125C1D1D0AB6972286
SHA256:398EB804BAC414A01B41EDBEF547F81CB7ADB58572BBBEE3030DB8B65461F268
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
429
TCP/UDP connections
31
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.53.40.178:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.53.40.178:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
104.18.9.193:443
https://content.cfx.re/updates/heads/fivereborn/production?time=1753405685
unknown
text
7 b
unknown
GET
200
104.18.8.193:443
https://content.cfx.re/updates/heads/fivereborn/production?time=1753405686
unknown
text
7 b
unknown
GET
200
104.18.9.193:443
https://content.cfx.re/updates/7a/b0/7ab0536e624cf62f0fcdb76d7461fdc8754ab43ee907c75fab8807940912b288
unknown
text
96.2 Kb
unknown
GET
200
104.18.8.193:443
https://content.cfx.re/updates/ca/15/ca15e331cf6a9bd97cebf4790dbe96e617409bbc375dd4032b82de495301b8d4.xz
unknown
binary
52.9 Kb
unknown
GET
200
104.18.8.193:443
https://content.cfx.re/updates/heads/fivereborn/production?time=1753405684
unknown
text
7 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
5944
MoUsoCoreWorker.exe
23.53.40.178:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.53.40.178:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.53.40.178:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5944
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
whitelisted
google.com
  • 172.217.18.14
whitelisted
crl.microsoft.com
  • 23.53.40.178
  • 23.53.40.176
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
content.cfx.re
  • 104.18.8.193
  • 104.18.9.193
unknown
self.events.data.microsoft.com
  • 51.116.253.168
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted
sentry.fivem.net
  • 104.18.27.86
  • 104.18.26.86
whitelisted

Threats

No threats detected
Process
Message
FiveM_DumpServer
DumpServer is active and waiting.