File name:

wfc6setup.exe

Full analysis: https://app.any.run/tasks/fc9f77df-ab00-4e40-8b92-ecda73457b74
Verdict: Malicious activity
Analysis date: July 19, 2025, 23:12:38
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto-reg
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

0113764902E7DA08F297754EE2F70BC9

SHA1:

93C1AF570FD6B88A996489C47A19E21A54E8716F

SHA256:

0057E9D784E600D879E0DF70D64587A846AAB653274641393FDBC8E1092B7E06

SSDEEP:

98304:ufCnNG0sQSaczf4ijJVjJH+CkXBym9geQGDOVsOBkqcWnSwx8aVEvqevauwmAO0I:t+Kj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • wfc6setup.exe (PID: 1204)
  • SUSPICIOUS

    • Reads the date of Windows installation

      • wfc6setup.exe (PID: 1512)
    • Uses TASKKILL.EXE to kill process

      • wfc6setup.exe (PID: 1204)
    • Reads security settings of Internet Explorer

      • wfc6setup.exe (PID: 1204)
      • wfc6setup.exe (PID: 1512)
      • wfcs.exe (PID: 3760)
      • wfcUI.exe (PID: 1660)
    • Windows service management via SC.EXE

      • sc.exe (PID: 1592)
      • sc.exe (PID: 6540)
      • sc.exe (PID: 72)
      • sc.exe (PID: 1948)
    • Starts SC.EXE for service management

      • wfc6setup.exe (PID: 1204)
      • wfcs.exe (PID: 3760)
    • Application launched itself

      • wfc6setup.exe (PID: 1512)
    • Executable content was dropped or overwritten

      • wfc6setup.exe (PID: 1204)
    • Process drops legitimate windows executable

      • wfc6setup.exe (PID: 1204)
    • The process verifies whether the antivirus software is installed

      • wfc6setup.exe (PID: 1204)
      • wfcs.exe (PID: 3760)
      • wfcUI.exe (PID: 1660)
    • Sets the service to start on system boot

      • sc.exe (PID: 4648)
      • sc.exe (PID: 2492)
    • Creates a software uninstall entry

      • wfc6setup.exe (PID: 1204)
    • Creates a new Windows service

      • sc.exe (PID: 2728)
    • Restarts service on failure

      • sc.exe (PID: 4088)
    • Suspicious use of NETSH.EXE

      • wfc6setup.exe (PID: 1204)
    • Searches for installed software

      • wfc6setup.exe (PID: 1204)
    • Executes as Windows Service

      • wfcs.exe (PID: 3760)
    • Reads the BIOS version

      • wfcUI.exe (PID: 1660)
  • INFO

    • Reads the machine GUID from the registry

      • wfc6setup.exe (PID: 1512)
      • wfc6setup.exe (PID: 1204)
      • wfcs.exe (PID: 3760)
      • wfcUI.exe (PID: 1660)
    • Checks supported languages

      • wfc6setup.exe (PID: 1512)
      • wfc6setup.exe (PID: 1204)
      • wfcs.exe (PID: 3760)
      • wfcUI.exe (PID: 1660)
    • Reads the computer name

      • wfc6setup.exe (PID: 1512)
      • wfc6setup.exe (PID: 1204)
      • wfcs.exe (PID: 3760)
      • wfcUI.exe (PID: 1660)
    • The sample compiled with english language support

      • wfc6setup.exe (PID: 1204)
    • Creates files in the program directory

      • wfc6setup.exe (PID: 1204)
      • netsh.exe (PID: 1828)
      • wfcs.exe (PID: 3760)
      • wfcUI.exe (PID: 1660)
    • Launching a file from a Registry key

      • wfc6setup.exe (PID: 1204)
    • Process checks computer location settings

      • wfcs.exe (PID: 3760)
      • wfc6setup.exe (PID: 1512)
    • Reads product name

      • wfcUI.exe (PID: 1660)
    • Reads the software policy settings

      • wfcUI.exe (PID: 1660)
      • slui.exe (PID: 1156)
    • Checks proxy server information

      • wfcUI.exe (PID: 1660)
      • slui.exe (PID: 1156)
    • Disables trace logs

      • wfcUI.exe (PID: 1660)
    • Reads Environment values

      • wfcUI.exe (PID: 1660)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (49.4)
.scr | Windows screen saver (23.4)
.dll | Win32 Dynamic Link Library (generic) (11.7)
.exe | Win32 Executable (generic) (8)
.exe | Generic Win/DOS Executable (3.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2088:03:25 04:22:37+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 3487232
InitializedDataSize: 20480
UninitializedDataSize: -
EntryPoint: 0x355466
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 6.18.0.0
ProductVersionNumber: 6.18.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Best tool to manage Windows Firewall with Advanced Security
CompanyName: Malwarebytes
FileDescription: Malwarebytes Windows Firewall Control - Setup
FileVersion: 6.18.0.0
InternalName: wfc6setup.exe
LegalCopyright: © 2025 Malwarebytes. All rights reserved.
LegalTrademarks: -
OriginalFileName: wfc6setup.exe
ProductName: Malwarebytes Windows Firewall Control - Setup
ProductVersion: 6.18.0.0
AssemblyVersion: 6.18.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
166
Monitored processes
29
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wfc6setup.exe no specs wfc6setup.exe taskkill.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs auditpol.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs wfcs.exe no specs wfcui.exe sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs auditpol.exe no specs conhost.exe no specs slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
72"C:\WINDOWS\system32\sc.exe" description wfcs "Malwarebytes Windows Firewall Control extends the functionality of Windows Firewall and adds new features which help you to protect your computer."C:\Windows\System32\sc.exewfc6setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
1156C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1204"C:\Users\admin\Desktop\wfc6setup.exe" "C:\Program Files\Malwarebytes\Windows Firewall Control" -install C:\Users\admin\Desktop\wfc6setup.exe
wfc6setup.exe
User:
admin
Company:
Malwarebytes
Integrity Level:
HIGH
Description:
Malwarebytes Windows Firewall Control - Setup
Exit code:
0
Version:
6.18.0.0
Modules
Images
c:\users\admin\desktop\wfc6setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1512"C:\Users\admin\Desktop\wfc6setup.exe" C:\Users\admin\Desktop\wfc6setup.exeexplorer.exe
User:
admin
Company:
Malwarebytes
Integrity Level:
MEDIUM
Description:
Malwarebytes Windows Firewall Control - Setup
Exit code:
0
Version:
6.18.0.0
Modules
Images
c:\users\admin\desktop\wfc6setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1568"C:\WINDOWS\system32\auditpol.exe" /set /subcategory:{0CCE9226-69AE-11D9-BED3-505054503030} /failure:enable /success:enableC:\Windows\System32\auditpol.exewfc6setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Audit Policy Program
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\auditpol.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1592"C:\WINDOWS\system32\sc.exe" start MpsSvcC:\Windows\System32\sc.exewfc6setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
1056
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
1636\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1636\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1660"C:\Program Files\Malwarebytes\Windows Firewall Control\wfcUI.exe"C:\Program Files\Malwarebytes\Windows Firewall Control\wfcUI.exe
wfc6setup.exe
User:
admin
Company:
Malwarebytes
Integrity Level:
MEDIUM
Description:
Malwarebytes Windows Firewall Control
Version:
6.18.0.0
Modules
Images
c:\program files\malwarebytes\windows firewall control\wfcui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1828"C:\WINDOWS\system32\netsh.exe" advfirewall export "C:\Program Files\Malwarebytes\Windows Firewall Control\restore.wfw"C:\Windows\System32\netsh.exewfc6setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
Total events
24 741
Read events
24 155
Write events
561
Delete events
25

Modification events

(PID) Process:(1204) wfc6setup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\WFC
Operation:writeName:MaxSize
Value:
524288
(PID) Process:(1204) wfc6setup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\WFC
Operation:writeName:AutoBackupLogFiles
Value:
0
(PID) Process:(1204) wfc6setup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\WFC\WFC
Operation:writeName:EventMessageFile
Value:
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\EventLogMessages.dll
(PID) Process:(1204) wfc6setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Malwarebytes Windows Firewall Control
Value:
"C:\Program Files\Malwarebytes\Windows Firewall Control\wfcUI.exe"
(PID) Process:(1204) wfc6setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Firewall Control
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Malwarebytes\Windows Firewall Control\wfcUI.exe
(PID) Process:(1204) wfc6setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Firewall Control
Operation:writeName:DisplayName
Value:
Malwarebytes Windows Firewall Control
(PID) Process:(1204) wfc6setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Firewall Control
Operation:writeName:DisplayVersion
Value:
6.18.0.0
(PID) Process:(1204) wfc6setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Firewall Control
Operation:writeName:EstimatedSize
Value:
5637
(PID) Process:(1204) wfc6setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Firewall Control
Operation:writeName:HelpLink
Value:
support@binisoft.org
(PID) Process:(1204) wfc6setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Firewall Control
Operation:writeName:URLInfoAbout
Value:
https://binisoft.org
Executable files
11
Suspicious files
3
Text files
23
Unknown types
0

Dropped files

PID
Process
Filename
Type
1204wfc6setup.exeC:\Program Files\Malwarebytes\Windows Firewall Control\Grpc.Core.Api.dllexecutable
MD5:09E30BE18DE7EE5EBFC0C49E7F21E292
SHA256:07639BEAFCAF9BF73487F124C74ED42AE73AA074BB6D9112C616EE9D14CC585B
1204wfc6setup.exeC:\Program Files\Malwarebytes\Windows Firewall Control\Google.Protobuf.dllexecutable
MD5:320FDA89BDB9FB82732BA8E4847883A6
SHA256:FA54C6622421C8D021152245FDD643591F7420B41E364D87131C424F1BA5C37A
1204wfc6setup.exeC:\Program Files\Malwarebytes\Windows Firewall Control\System.Memory.dllexecutable
MD5:35E6237FF5533342516BF01A46E4B7CD
SHA256:B8FE216AFF0F6D162F8EEFE7BE1712162B7D8199E20CE2E70FFAC36C7CE20A4C
1204wfc6setup.exeC:\Program Files\Malwarebytes\Windows Firewall Control\wfcs.exeexecutable
MD5:E1805846E4D82E2A2118E3145960A89F
SHA256:27B9CFA04A6C6BA08BEC3F7ACDC4C657C210D07E2BC0DBC74C7A127C6A6B283C
1204wfc6setup.exeC:\Program Files\Malwarebytes\Windows Firewall Control\lang\wfcBR.lngtext
MD5:129F563E792DA1AE7B1AC5C148704A60
SHA256:57F68D1673453D8089CE4E9F20DCB2C0072F76974EF1CD58797DEC9EE2546F75
1204wfc6setup.exeC:\Program Files\Malwarebytes\Windows Firewall Control\mbcut.dllexecutable
MD5:5F9D7C48C991C87F16072B79F4C92538
SHA256:42F5D448D98AACC53B92A56806D1FEEE3CD8E2EAB5C717F7DFC8CBD3809B1502
1204wfc6setup.exeC:\Program Files\Malwarebytes\Windows Firewall Control\lang\wfcCZ.lngtext
MD5:6A201658F9C51A78B10F1D5A5913532D
SHA256:6FCD28E2DC30E91F8855D7905526F3249D62325AE896A41B528F7C52592B8C09
1204wfc6setup.exeC:\Program Files\Malwarebytes\Windows Firewall Control\Newtonsoft.Json.dllexecutable
MD5:195FFB7167DB3219B217C4FD439EEDD6
SHA256:E1E27AF7B07EEEDF5CE71A9255F0422816A6FC5849A483C6714E1B472044FA9D
1204wfc6setup.exeC:\Program Files\Malwarebytes\Windows Firewall Control\System.Numerics.Vectors.dllexecutable
MD5:7AB5DBDD2ACE2A313392CFF4F372E4B9
SHA256:22C84BE385FE8BA6D0E0138952748F28D781FCE36078B5A7AED91A6104BCD99B
1204wfc6setup.exeC:\Program Files\Malwarebytes\Windows Firewall Control\wfcUI.exeexecutable
MD5:D8A94870AC43CFF447213625D4BF821F
SHA256:693C15A745655DF9D9876FE3D863F2DB3BAB51CACFFAC2E676E6F962A99F93A5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
35
TCP/UDP connections
50
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1864
RUXIMICS.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
POST
400
20.190.160.130:443
https://login.live.com/ppsecure/deviceaddcredential.srf
unknown
text
203 b
whitelisted
POST
200
20.190.160.130:443
https://login.live.com/RST2.srf
unknown
xml
1.24 Kb
whitelisted
1268
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1864
RUXIMICS.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
POST
400
20.190.160.20:443
https://login.live.com/ppsecure/deviceaddcredential.srf
unknown
text
203 b
whitelisted
POST
400
20.190.160.5:443
https://login.live.com/ppsecure/deviceaddcredential.srf
unknown
text
203 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1864
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5944
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1864
RUXIMICS.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5944
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
  • 40.127.240.158
whitelisted
google.com
  • 142.250.186.78
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.36
  • 23.216.77.28
  • 23.216.77.20
  • 2.16.241.14
  • 2.16.241.12
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 95.101.149.131
whitelisted
login.live.com
  • 20.190.160.131
  • 40.126.32.72
  • 20.190.160.3
  • 20.190.160.5
  • 40.126.32.68
  • 20.190.160.130
  • 20.190.160.20
  • 20.190.160.2
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
self.events.data.microsoft.com
  • 52.182.143.215
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
  • 40.91.76.224
whitelisted

Threats

No threats detected
No debug info