File name:

Office Installer and Office Installer+ v1.25.7z

Full analysis: https://app.any.run/tasks/5d18687c-d4f2-4690-b619-40cf77b01c2a
Verdict: Malicious activity
Analysis date: March 19, 2025, 15:47:59
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

349192E852F520412B616FFC391DFA6E

SHA1:

03F30A8D15E1A01AD13C054737479DB10F92E687

SHA256:

176B4A7ED15CAD31EF6644CD2859B788AF3BAE365D152B535D9F5DA42A558B86

SSDEEP:

98304:ZpI6D0YCSFwH/l9TWWWb5yNiyLLMJjic1OQDYxM7T0lRwVUsG6yc/RW8Hi4m8KCF:tTo+o3r5yp4aQyJsjl6/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Script downloads file (POWERSHELL)

      • powershell.exe (PID: 5064)
      • powershell.exe (PID: 2552)
      • powershell.exe (PID: 4756)
  • SUSPICIOUS

    • Uses REG/REGEDIT.EXE to modify registry

      • Office Installer.exe (PID: 5596)
    • Starts POWERSHELL.EXE for commands execution

      • Office Installer.exe (PID: 5596)
    • Probably download files using WebClient

      • Office Installer.exe (PID: 5596)
    • The process bypasses the loading of PowerShell profile settings

      • Office Installer.exe (PID: 5596)
    • Executes script without checking the security policy

      • powershell.exe (PID: 5064)
    • Starts CMD.EXE for commands execution

      • Office Installer.exe (PID: 5596)
    • Starts SC.EXE for service management

      • cmd.exe (PID: 7892)
    • Stops a currently running service

      • sc.exe (PID: 8024)
    • Start notepad (likely ransomware note)

      • Office Installer.exe (PID: 5596)
    • Uses TASKKILL.EXE to kill process

      • Office Installer.exe (PID: 5596)
    • Unpacks CAB file

      • expand.exe (PID: 4944)
      • expand.exe (PID: 5588)
    • Executable content was dropped or overwritten

      • expand.exe (PID: 4944)
      • OfficeClickToRun.exe (PID: 4400)
    • Process drops legitimate windows executable

      • expand.exe (PID: 4944)
      • OfficeClickToRun.exe (PID: 4400)
    • The process drops C-runtime libraries

      • expand.exe (PID: 4944)
  • INFO

    • Checks supported languages

      • Office Installer.exe (PID: 5596)
      • OfficeClickToRun.exe (PID: 4224)
      • OfficeClickToRun.exe (PID: 4400)
    • Manual execution by a user

      • Office Installer.exe (PID: 5596)
      • Office Installer.exe (PID: 1244)
      • Office Installer+.exe (PID: 5020)
      • Office Installer+.exe (PID: 6372)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7400)
    • Reads the computer name

      • Office Installer.exe (PID: 5596)
    • Create files in a temporary directory

      • Office Installer.exe (PID: 5596)
    • UPX packer has been detected

      • Office Installer.exe (PID: 5596)
    • Checks proxy server information

      • powershell.exe (PID: 2552)
      • powershell.exe (PID: 4756)
      • OfficeClickToRun.exe (PID: 4400)
      • OfficeClickToRun.exe (PID: 4224)
    • Disables trace logs

      • powershell.exe (PID: 2552)
      • powershell.exe (PID: 4756)
    • The sample compiled with english language support

      • expand.exe (PID: 4944)
    • The sample compiled with arabic language support

      • expand.exe (PID: 4944)
    • Creates files in the program directory

      • expand.exe (PID: 4944)
      • expand.exe (PID: 5588)
      • OfficeClickToRun.exe (PID: 4400)
    • The sample compiled with bulgarian language support

      • expand.exe (PID: 4944)
    • The sample compiled with spanish language support

      • expand.exe (PID: 4944)
    • The sample compiled with french language support

      • expand.exe (PID: 4944)
    • The sample compiled with czech language support

      • expand.exe (PID: 4944)
    • The sample compiled with Indonesian language support

      • expand.exe (PID: 4944)
    • The sample compiled with german language support

      • expand.exe (PID: 4944)
    • The sample compiled with korean language support

      • expand.exe (PID: 4944)
    • The sample compiled with japanese language support

      • expand.exe (PID: 4944)
    • The sample compiled with Italian language support

      • expand.exe (PID: 4944)
    • The sample compiled with portuguese language support

      • expand.exe (PID: 4944)
    • The sample compiled with polish language support

      • expand.exe (PID: 4944)
    • The sample compiled with slovak language support

      • expand.exe (PID: 4944)
    • The sample compiled with russian language support

      • expand.exe (PID: 4944)
    • The sample compiled with swedish language support

      • expand.exe (PID: 4944)
    • The sample compiled with turkish language support

      • expand.exe (PID: 4944)
    • The sample compiled with chinese language support

      • expand.exe (PID: 4944)
    • Reads Microsoft Office registry keys

      • OfficeClickToRun.exe (PID: 4224)
      • OfficeClickToRun.exe (PID: 4400)
    • Executes as Windows Service

      • OfficeClickToRun.exe (PID: 4400)
    • Reads the machine GUID from the registry

      • OfficeClickToRun.exe (PID: 4400)
    • Creates files or folders in the user directory

      • OfficeClickToRun.exe (PID: 4224)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
172
Monitored processes
32
Malicious processes
2
Suspicious processes
3

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs office installer.exe no specs office installer.exe reg.exe no specs conhost.exe no specs powershell.exe conhost.exe no specs slui.exe notepad.exe no specs cmd.exe no specs conhost.exe no specs sc.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs powershell.exe conhost.exe no specs expand.exe conhost.exe no specs powershell.exe conhost.exe no specs expand.exe no specs conhost.exe no specs officeclicktorun.exe officeclicktorun.exe Delivery Optimization User no specs office installer+.exe no specs office installer+.exe

Process information

PID
CMD
Path
Indicators
Parent process
1244"C:\Users\admin\Desktop\Office Installer and Office Installer+ v1.25\Office Installer.exe" C:\Users\admin\Desktop\Office Installer and Office Installer+ v1.25\Office Installer.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\office installer and office installer+ v1.25\office installer.exe
c:\windows\system32\ntdll.dll
1328"taskkill.exe" /t /f /IM OfficeC2RClient.exeC:\Windows\System32\taskkill.exeOffice Installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2064C:\WINDOWS\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
2136\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exereg.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2136\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2140"reg.exe" add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script Host\Settings" /v "Enabled" /t REG_DWORD /d 1 /fC:\Windows\System32\reg.exeOffice Installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2268\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2392\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeexpand.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2552"powershell" -command "& { (New-Object Net.WebClient).DownloadFile('http://officecdn.microsoft.com/pr/7983bac0-e531-40cf-be00-fd24fe66619c/Office/Data/16.0.17932.20286/i640.cab', 'C:\Users\admin\AppData\Local\Temp\i640.cab') }"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Office Installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\atl.dll
2984\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
26 823
Read events
26 627
Write events
75
Delete events
121

Modification events

(PID) Process:(7400) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(7400) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7400) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7400) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7400) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Office Installer and Office Installer+ v1.25.7z
(PID) Process:(7400) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7400) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7400) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7400) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7400) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:15
Value:
Executable files
222
Suspicious files
12
Text files
40
Unknown types
0

Dropped files

PID
Process
Filename
Type
2552powershell.exeC:\Users\admin\AppData\Local\Temp\i640.cab
MD5:
SHA256:
7400WinRAR.exeC:\Users\admin\Desktop\Office Installer and Office Installer+ v1.25\readme.txttext
MD5:200F8C8D0762053F1FC582DA872EBEEB
SHA256:E379B64C125830A593982058DAC69D129734B4CF5D98C6FABCFAFDDFE8657143
7400WinRAR.exeC:\Users\admin\Desktop\Office Installer and Office Installer+ v1.25\Office Installer x86.exeexecutable
MD5:741D25BAFBD80CDB3A7179E00A409689
SHA256:BE96A882503392D3BAA2217874BCF37FCAEC4EB971BEA868D8E2CA7E6187F2C8
7400WinRAR.exeC:\Users\admin\Desktop\Office Installer and Office Installer+ v1.25\readme+.txttext
MD5:509DB22BF8D2518B97D647FE3E85A622
SHA256:C9DE1237F6C6E1A6320460991C5222E8308716E5CE58B11E29EC9956281C6FA4
7400WinRAR.exeC:\Users\admin\Desktop\Office Installer and Office Installer+ v1.25\Office Installer+ x86.exeexecutable
MD5:CA2BDE1C44A604E937F06EDE3AD6CACE
SHA256:CAEC937F201DAD832F0EADDBE09C93525E5A4BBFF325CCAC7A2326B2BB0AE19F
7400WinRAR.exeC:\Users\admin\Desktop\Office Installer and Office Installer+ v1.25\Office Installer+.exeexecutable
MD5:74BD276FECB69602374D85FF2142D386
SHA256:3174FEA793F078DA0D05A1CBF2823AD27FFE32FB4795461830281B0447621F48
5064powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_k4ox3uwb.vzr.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
5064powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivebinary
MD5:3D9855B37C4C673F467A626218391F08
SHA256:B68070A3CBD4A39E198BC8FF0F4FE416F5E4B66C68C3FCB5AA64D37F491FA113
2552powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_oyu5mesu.jrg.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
4944expand.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-localization-l1-2-0.dllexecutable
MD5:6B4F2CA3EFCEB2C21E93F92CDC150A9D
SHA256:B39A515B9E48FC6589703D45E14DCEA2273A02D7FA6F2E1D17985C0228D32564
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
21
TCP/UDP connections
43
DNS requests
34
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.164:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
6544
svchost.exe
GET
200
23.54.109.203:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
5728
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
419 b
whitelisted
5728
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
408 b
whitelisted
7748
backgroundTaskHost.exe
GET
200
23.54.109.203:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
DE
binary
471 b
whitelisted
4756
powershell.exe
GET
200
199.232.210.172:80
http://officecdn.microsoft.com/pr/7983bac0-e531-40cf-be00-fd24fe66619c/Office/Data/16.0.17932.20286/i641036.cab
US
compressed
9.84 Kb
whitelisted
2552
powershell.exe
GET
200
199.232.210.172:80
http://officecdn.microsoft.com/pr/7983bac0-e531-40cf-be00-fd24fe66619c/Office/Data/16.0.17932.20286/i640.cab
US
compressed
32.0 Mb
whitelisted
7964
svchost.exe
GET
200
103.46.230.61:80
http://103.46.230.61/pr/7983BAC0-E531-40CF-BE00-FD24FE66619C/Office/Data/16.0.17932.20286/s640.cab.phf?cacheHostOrigin=officecdn.microsoft.com
AU
binary
293 b
unknown
7964
svchost.exe
GET
103.46.230.61:80
http://103.46.230.61/pr/7983bac0-e531-40cf-be00-fd24fe66619c/Office/Data/16.0.17932.20286/s640.cab?cacheHostOrigin=officecdn.microsoft.com
AU
unknown
7964
svchost.exe
GET
206
103.46.230.61:80
http://103.46.230.61/pr/7983bac0-e531-40cf-be00-fd24fe66619c/Office/Data/16.0.17932.20286/s640.cab?cacheHostOrigin=officecdn.microsoft.com
AU
text
2 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.164:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
6544
svchost.exe
20.190.160.3:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
23.54.109.203:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7748
backgroundTaskHost.exe
20.223.35.26:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7748
backgroundTaskHost.exe
23.54.109.203:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.110
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.48.23.164
  • 23.48.23.150
  • 23.48.23.138
  • 23.48.23.161
  • 23.48.23.194
  • 23.48.23.168
  • 23.48.23.137
  • 23.48.23.162
  • 23.48.23.145
  • 23.48.23.140
  • 23.48.23.179
  • 23.48.23.183
  • 23.48.23.177
  • 23.48.23.141
  • 23.48.23.134
  • 23.48.23.139
whitelisted
login.live.com
  • 20.190.160.3
  • 20.190.160.14
  • 40.126.32.138
  • 40.126.32.134
  • 40.126.32.140
  • 20.190.160.20
  • 40.126.32.74
  • 20.190.160.131
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
ocsp.digicert.com
  • 23.54.109.203
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
mrodevicemgr.officeapps.live.com
  • 52.109.89.117
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted

Threats

No threats detected
No debug info