File name:

Dota-2-Changer-ENG.rar

Full analysis: https://app.any.run/tasks/8afe2fed-5b0c-4c90-9f52-9b78b23177d9
Verdict: Malicious activity
Analysis date: June 21, 2025, 22:21:05
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-doc
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32, flags: FirstVolume
MD5:

6982B43009070ACDC4F26CB1B81305DB

SHA1:

D2A123DA7BB4505BE7ABC18A48F3EAA283E56D85

SHA256:

B408132BAE366BD751499C21B0556140E9FD0BCAC57DD5CD1A93EF42AC8BB35E

SSDEEP:

98304:b3hiyghf+tElA+hjmykzGJIZTbif8qRMUn+Y99nbn+YtRUIYWTYLiJ6qz11/tkl4:KI4HUab8MOylb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 2680)
    • Executes application which crashes

      • Dota 2 Changer [ENG].exe (PID: 856)
      • Dota 2 Changer [ENG].exe (PID: 1688)
      • Dota 2 Changer [ENG].exe (PID: 1204)
    • Reads Microsoft Outlook installation path

      • Dota 2 Changer [ENG].exe (PID: 1688)
      • Dota 2 Changer [ENG].exe (PID: 1204)
      • Dota 2 Changer [ENG].exe (PID: 856)
    • Reads security settings of Internet Explorer

      • UpdaterEng.exe (PID: 5008)
      • Dota 2 Changer [ENG].exe (PID: 1688)
      • Dota 2 Changer [ENG].exe (PID: 1204)
      • Dota 2 Changer [ENG].exe (PID: 856)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2680)
    • Checks supported languages

      • Dota 2 Changer [ENG].exe (PID: 856)
      • UpdaterEng.exe (PID: 5008)
      • Dota 2 Changer [ENG].exe (PID: 1688)
      • Dota 2 Changer [ENG].exe (PID: 1204)
    • Creates files or folders in the user directory

      • Dota 2 Changer [ENG].exe (PID: 856)
      • WerFault.exe (PID: 5896)
      • WerFault.exe (PID: 2188)
      • WerFault.exe (PID: 6680)
      • Dota 2 Changer [ENG].exe (PID: 1204)
    • Reads the software policy settings

      • Dota 2 Changer [ENG].exe (PID: 856)
      • WerFault.exe (PID: 5896)
      • UpdaterEng.exe (PID: 5008)
      • Dota 2 Changer [ENG].exe (PID: 1688)
      • WerFault.exe (PID: 2188)
      • Dota 2 Changer [ENG].exe (PID: 1204)
      • WerFault.exe (PID: 6680)
      • slui.exe (PID: 3960)
    • Checks proxy server information

      • WerFault.exe (PID: 5896)
      • Dota 2 Changer [ENG].exe (PID: 856)
      • UpdaterEng.exe (PID: 5008)
      • Dota 2 Changer [ENG].exe (PID: 1688)
      • WerFault.exe (PID: 2188)
      • Dota 2 Changer [ENG].exe (PID: 1204)
      • slui.exe (PID: 3960)
      • WerFault.exe (PID: 6680)
    • Reads the computer name

      • UpdaterEng.exe (PID: 5008)
      • Dota 2 Changer [ENG].exe (PID: 1688)
      • Dota 2 Changer [ENG].exe (PID: 1204)
      • Dota 2 Changer [ENG].exe (PID: 856)
    • Manual execution by a user

      • UpdaterEng.exe (PID: 5008)
      • Dota 2 Changer [ENG].exe (PID: 856)
      • WinRAR.exe (PID: 7076)
      • Dota 2 Changer [ENG].exe (PID: 1204)
    • Disables trace logs

      • UpdaterEng.exe (PID: 5008)
      • Dota 2 Changer [ENG].exe (PID: 1688)
      • Dota 2 Changer [ENG].exe (PID: 1204)
      • Dota 2 Changer [ENG].exe (PID: 856)
    • Create files in a temporary directory

      • UpdaterEng.exe (PID: 5008)
      • Dota 2 Changer [ENG].exe (PID: 856)
    • Process checks computer location settings

      • UpdaterEng.exe (PID: 5008)
    • Reads the machine GUID from the registry

      • Dota 2 Changer [ENG].exe (PID: 1688)
      • UpdaterEng.exe (PID: 5008)
      • Dota 2 Changer [ENG].exe (PID: 1204)
      • Dota 2 Changer [ENG].exe (PID: 856)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

FileVersion: RAR v4
CompressedSize: 180
UncompressedSize: 160
OperatingSystem: Win32
ModifyDate: 2015:01:11 07:20:56
PackingMethod: Normal
ArchivedFileName: Dota 2 Changer ENG\app\announce.txt
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
151
Monitored processes
11
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe slui.exe rundll32.exe no specs dota 2 changer [eng].exe werfault.exe updatereng.exe dota 2 changer [eng].exe werfault.exe winrar.exe no specs dota 2 changer [eng].exe werfault.exe

Process information

PID
CMD
Path
Indicators
Parent process
856"C:\Users\admin\Desktop\Dota 2 Changer ENG\Dota 2 Changer [ENG].exe" C:\Users\admin\Desktop\Dota 2 Changer ENG\Dota 2 Changer [ENG].exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Dota 2 Changer [ENG]
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\dota 2 changer eng\dota 2 changer [eng].exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
1204"C:\Users\admin\Desktop\Dota 2 Changer ENG\Dota 2 Changer [ENG].exe" C:\Users\admin\Desktop\Dota 2 Changer ENG\Dota 2 Changer [ENG].exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Dota 2 Changer [ENG]
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\dota 2 changer eng\dota 2 changer [eng].exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
1688"C:\Users\admin\Desktop\Dota 2 Changer ENG\Dota 2 Changer [ENG].exe" C:\Users\admin\Desktop\Dota 2 Changer ENG\Dota 2 Changer [ENG].exe
UpdaterEng.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Dota 2 Changer [ENG]
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\dota 2 changer eng\dota 2 changer [eng].exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
2188C:\WINDOWS\SysWOW64\WerFault.exe -u -p 1688 -s 2600C:\Windows\SysWOW64\WerFault.exe
Dota 2 Changer [ENG].exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
2680"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Dota-2-Changer-ENG.rarC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3960C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4576C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
5008"C:\Users\admin\Desktop\Dota 2 Changer ENG\UpdaterEng.exe" C:\Users\admin\Desktop\Dota 2 Changer ENG\UpdaterEng.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Updater
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\dota 2 changer eng\updatereng.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
5896C:\WINDOWS\SysWOW64\WerFault.exe -u -p 856 -s 2840C:\Windows\SysWOW64\WerFault.exe
Dota 2 Changer [ENG].exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
6680C:\WINDOWS\SysWOW64\WerFault.exe -u -p 1204 -s 2568C:\Windows\SysWOW64\WerFault.exe
Dota 2 Changer [ENG].exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
Total events
16 990
Read events
16 927
Write events
63
Delete events
0

Modification events

(PID) Process:(2680) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(2680) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(2680) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2680) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Dota-2-Changer-ENG.rar
(PID) Process:(2680) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2680) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2680) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2680) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2680) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(2680) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
Executable files
2
Suspicious files
71
Text files
29
Unknown types
0

Dropped files

PID
Process
Filename
Type
2680WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2680.33527\Dota 2 Changer ENG\app\announce.txttext
MD5:CB0DEB27FB1755F914CE441B2E06FEC0
SHA256:2500461BAC4D5B00CA1D4F33AE553E2EB0EFC93E4DAAC2A0B19D3067B41C2217
2680WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2680.33527\Dota 2 Changer ENG\app\app.zipcompressed
MD5:644DFCF73B47D43DCEB0045E091CB7F9
SHA256:D01A0DC82C3FFA05911B3F9AAE5F0CE78CDE5083EB4D3F8C6B675AC9307A7332
2680WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2680.33527\Dota 2 Changer ENG\app\cursors.txttext
MD5:D815D4269B89EEBA7B681B4E08D3BE61
SHA256:CE0A9D4E765D664197E625D1FBEC9DC19A065E3724534E43F3149B492F9B7A91
2680WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2680.33527\Dota 2 Changer ENG\app\boobsmod.txttext
MD5:193895308A2245E5BF2649FE5BB830F3
SHA256:11955950A62A44EFBD82BC366166ADFCB67C7CF20B9FD103BB4F0F2F459EEB56
2680WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2680.33527\Dota 2 Changer ENG\app\couriers.txttext
MD5:3E548B4ECC0D7E0D23FD610324272862
SHA256:BAB994E99A9B06D016FA5447E7D192F59C81295C0DE9B32F07F6815DDEB4F54C
2680WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2680.33527\Dota 2 Changer ENG\app\deletemodseng.txttext
MD5:17254C9CD531802FA84E86861B6910E6
SHA256:EF9868C20BA36A6087F5872EA0779835B3ECEFBF48D632A4018B05B6A52DA843
2680WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2680.33527\Dota 2 Changer ENG\app\deletemods.txttext
MD5:922543D71D39CF472D15F1488D76D10F
SHA256:3AF253A7C5912041D48BB495AD0DFF099E68D8F72D6CC0E1BD7907DC4FD895F9
2680WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2680.33527\Dota 2 Changer ENG\app\deletesounds.txttext
MD5:EF14FB083D90E605D574963EAC5CCB13
SHA256:9E8181771C84B5585AEDB51CB0D3C17CDF06CA9ED14AC66E45C3149CB74C1DBE
2680WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2680.33527\Dota 2 Changer ENG\app\effects.txttext
MD5:7DDFD20E4100319EA0ECBACC7B304AFD
SHA256:1275F8B3CF4D3375245BF9700CFB030815D6EFDDB723041F302C509DFBF89B5C
2680WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2680.33527\Dota 2 Changer ENG\app\pers.txttext
MD5:6114287A7A3284045A6B025078F87769
SHA256:09A516D983D95B35FE831B243BE2920DCBAA8D7DC86DC52A63B76EC41EB44E7E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
55
DNS requests
27
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6748
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
856
Dota 2 Changer [ENG].exe
GET
301
87.240.132.72:80
http://vk.com/dota_2_changer
unknown
whitelisted
856
Dota 2 Changer [ENG].exe
GET
301
87.236.16.2:80
http://dota2changer.ru/uploads/programm/update/MainPageENG.html
unknown
unknown
856
Dota 2 Changer [ENG].exe
GET
301
87.236.16.2:80
http://dota2changer.ru/uploads/programm/update/popupEng.html
unknown
unknown
856
Dota 2 Changer [ENG].exe
GET
200
151.101.66.133:80
http://ocsp2.globalsign.com/rootr5/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQiD0S5cIHyfrLTJ1fvAkJWflH%2B2QQUPeYpSJvqB8ohREom3m7e0oPQn1kCDQHuXyKVQkkF%2BQGRqNw%3D
unknown
whitelisted
856
Dota 2 Changer [ENG].exe
GET
301
87.236.16.2:80
http://dota2changer.ru/uploads/programm/update/StatEng.html
unknown
unknown
856
Dota 2 Changer [ENG].exe
GET
301
87.236.16.2:80
http://dota2changer.ru/app.zip
unknown
unknown
856
Dota 2 Changer [ENG].exe
GET
200
104.18.20.213:80
http://r11.c.lencr.org/124.crl
unknown
whitelisted
856
Dota 2 Changer [ENG].exe
GET
200
151.101.66.133:80
http://ocsp.globalsign.com/gseccovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBSTMjK03nNiYoQYvu4Izyfn9OJNdAQUWHuOdSr%2BYYCqkEABrtboB0ZuP0gCDCTd0ivVYZX4fOkPSA%3D%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3876
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
184.24.77.13:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3864
SIHClient.exe
172.202.163.200:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
GB
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
  • 51.104.136.2
whitelisted
google.com
  • 216.58.206.78
whitelisted
crl.microsoft.com
  • 184.24.77.13
  • 184.24.77.31
  • 184.24.77.4
  • 184.24.77.6
  • 184.24.77.34
  • 184.24.77.42
  • 184.24.77.14
  • 184.24.77.18
  • 184.24.77.33
  • 184.24.77.19
  • 184.24.77.38
  • 184.24.77.39
  • 184.24.77.24
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 95.101.149.131
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
login.live.com
  • 20.190.159.64
  • 20.190.159.130
  • 20.190.159.131
  • 40.126.31.3
  • 40.126.31.71
  • 20.190.159.23
  • 40.126.31.73
  • 20.190.159.68
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

PID
Process
Class
Message
856
Dota 2 Changer [ENG].exe
Potentially Bad Traffic
ET HUNTING Terse Request for Zip File (GET)
5008
UpdaterEng.exe
Potentially Bad Traffic
ET HUNTING Terse Request for Zip File (GET)
1688
Dota 2 Changer [ENG].exe
Potentially Bad Traffic
ET HUNTING Terse Request for Zip File (GET)
1204
Dota 2 Changer [ENG].exe
Potentially Bad Traffic
ET HUNTING Terse Request for Zip File (GET)
No debug info