File name:

AnyDVD HD 8.1.4.0 FINAL + Crack [www.Tech-Tools.ME].rar

Full analysis: https://app.any.run/tasks/2eed8e4e-2aeb-43a2-92db-b096b65f0099
Verdict: Malicious activity
Analysis date: March 14, 2025, 16:37:48
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-doc
delphi
autorun-reg
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

D602DA34ABCD5AE6269E4E0CCCEC1308

SHA1:

39BF2553A702B7BBFA9C16053C8316B301921B0A

SHA256:

23C9B470E49863EC86F3B81F91EED5F30405AE98BE3FD62FD56ADFF25EBF6142

SSDEEP:

98304:Mf8oFNoU8lYyUENrIIQcKAXDamfuTeUp3QPYnvoln+G2rCwJeHEDpy0tTm+gnuzQ:aKApxXSKpYXVXPfn64JR3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 7704)
    • Changes the autorun value in the registry

      • nstDFE3.tmp (PID: 6044)
      • AnyDVDtray.exe (PID: 7916)
    • Executing a file with an untrusted certificate

      • ADvdDiscHlp64.exe (PID: 8092)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • SetupAnyDVD8140.exe (PID: 7272)
      • nstDFE3.tmp (PID: 6044)
      • patch.exe (PID: 7968)
    • Starts application with an unusual extension

      • SetupAnyDVD8140.exe (PID: 7272)
    • Starts itself from another location

      • SetupAnyDVD8140.exe (PID: 7272)
    • There is functionality for taking screenshot (YARA)

      • SetupAnyDVD8140.exe (PID: 7272)
      • nstDFE3.tmp (PID: 6044)
      • AnyDVDtray.exe (PID: 7916)
    • Creates files in the driver directory

      • nstDFE3.tmp (PID: 6044)
    • Drops a system driver (possible attempt to evade defenses)

      • nstDFE3.tmp (PID: 6044)
    • Creates or modifies Windows services

      • nstDFE3.tmp (PID: 6044)
    • Detected use of alternative data streams (AltDS)

      • AnyDVDtray.exe (PID: 7916)
    • Creates a software uninstall entry

      • nstDFE3.tmp (PID: 6044)
    • Reads security settings of Internet Explorer

      • AnyDVDtray.exe (PID: 7916)
  • INFO

    • Manual execution by a user

      • SetupAnyDVD8140.exe (PID: 7272)
      • SetupAnyDVD8140.exe (PID: 4892)
      • patch.exe (PID: 7992)
      • patch.exe (PID: 7968)
      • AnyDVD.exe (PID: 208)
    • Create files in a temporary directory

      • SetupAnyDVD8140.exe (PID: 7272)
      • nstDFE3.tmp (PID: 6044)
      • AnyDVDtray.exe (PID: 7916)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7704)
    • Checks supported languages

      • SetupAnyDVD8140.exe (PID: 7272)
      • nstDFE3.tmp (PID: 6044)
      • setacl.exe (PID: 7388)
      • DevCon.exe (PID: 6744)
      • SetRegACL.exe (PID: 1184)
      • setacl.exe (PID: 5720)
      • DevCon.exe (PID: 7000)
      • AnyDVDtray.exe (PID: 7364)
      • AnyDVDtray.exe (PID: 7916)
      • AnyDVD.exe (PID: 208)
      • patch.exe (PID: 7968)
      • ADvdDiscHlp64.exe (PID: 8092)
      • AnyDVDtray.exe (PID: 4220)
      • AnyDVD.exe (PID: 7440)
    • The sample compiled with german language support

      • nstDFE3.tmp (PID: 6044)
    • Reads the computer name

      • nstDFE3.tmp (PID: 6044)
      • AnyDVDtray.exe (PID: 7364)
      • patch.exe (PID: 7968)
      • AnyDVDtray.exe (PID: 7916)
      • AnyDVDtray.exe (PID: 4220)
      • ADvdDiscHlp64.exe (PID: 8092)
    • The sample compiled with english language support

      • nstDFE3.tmp (PID: 6044)
    • Creates files in the program directory

      • AnyDVDtray.exe (PID: 7364)
      • nstDFE3.tmp (PID: 6044)
      • patch.exe (PID: 7968)
    • Autorun file from Registry key

      • AnyDVDtray.exe (PID: 7916)
      • nstDFE3.tmp (PID: 6044)
    • Reads the machine GUID from the registry

      • AnyDVDtray.exe (PID: 7916)
    • Compiled with Borland Delphi (YARA)

      • AnyDVDtray.exe (PID: 7916)
    • Checks proxy server information

      • slui.exe (PID: 6592)
      • AnyDVDtray.exe (PID: 7916)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

FileVersion: RAR v4
CompressedSize: 362585
UncompressedSize: 369152
OperatingSystem: Win32
ModifyDate: 2016:09:08 07:30:12
PackingMethod: Normal
ArchivedFileName: AnyDVD HD 8.1.4.0 FINAL + Crack [www.Tech-Tools.ME]\Crack\patch.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
164
Monitored processes
25
Malicious processes
3
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs setupanydvd8140.exe no specs setupanydvd8140.exe nstdfe3.tmp anydvdtray.exe no specs setacl.exe no specs conhost.exe no specs setregacl.exe no specs conhost.exe no specs setacl.exe no specs conhost.exe no specs devcon.exe no specs conhost.exe no specs devcon.exe no specs conhost.exe no specs anydvd.exe no specs anydvdtray.exe no specs patch.exe no specs patch.exe slui.exe anydvd.exe no specs anydvdtray.exe advddischlp64.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
208"C:\Program Files (x86)\RedFox\AnyDVD\AnyDVD.exe" C:\Program Files (x86)\RedFox\AnyDVD\AnyDVD.exeexplorer.exe
User:
admin
Company:
RedFox
Integrity Level:
MEDIUM
Description:
AnyDVD Application
Exit code:
0
Version:
8.1.4.0
Modules
Images
c:\program files (x86)\redfox\anydvd\anydvd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1184"C:\Program Files (x86)\RedFox\AnyDVD\SetRegACL.exe" Software\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons 64C:\Program Files (x86)\RedFox\AnyDVD\SetRegACL.exenstDFE3.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files (x86)\redfox\anydvd\setregacl.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4120\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeDevCon.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4220"C:\Program Files (x86)\RedFox\AnyDVD\AnyDVDtray.exe" -cC:\Program Files (x86)\RedFox\AnyDVD\AnyDVDtray.exeAnyDVD.exe
User:
admin
Company:
RedFox
Integrity Level:
HIGH
Description:
AnyDVD Application
Exit code:
10
Version:
8.1.4.0
Modules
Images
c:\program files (x86)\redfox\anydvd\anydvdtray.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\psapi.dll
4892"C:\Users\admin\Desktop\AnyDVD HD 8.1.4.0 FINAL + Crack [www.Tech-Tools.ME]\SetupAnyDVD8140.exe" C:\Users\admin\Desktop\AnyDVD HD 8.1.4.0 FINAL + Crack [www.Tech-Tools.ME]\SetupAnyDVD8140.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\anydvd hd 8.1.4.0 final + crack [www.tech-tools.me]\setupanydvd8140.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4976\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSetRegACL.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5392\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesetacl.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5720"C:\Users\admin\AppData\Local\Temp\nstE159.tmp\SetACL.exe" "MACHINE\SOFTWARE\SlySoft\AnyDVD\Status" /registry /grant S-1-5-32-545 /full /sid /silentC:\Users\admin\AppData\Local\Temp\nstE159.tmp\setacl.exenstDFE3.tmp
User:
admin
Company:
Helge Klein
Integrity Level:
HIGH
Description:
SetACL
Exit code:
0
Version:
0, 9, 0, 4
Modules
Images
c:\users\admin\appdata\local\temp\nste159.tmp\setacl.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6044nstDFE3.tmp /DOITC:\Users\admin\AppData\Local\Temp\nstDFD3.tmp\nstDFE3.tmp
SetupAnyDVD8140.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nstdfd3.tmp\nstdfe3.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_a863d714867441db\comctl32.dll
6592C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
3 633
Read events
3 405
Write events
225
Delete events
3

Modification events

(PID) Process:(7704) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7704) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7704) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7704) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\AnyDVD HD 8.1.4.0 FINAL + Crack [www.Tech-Tools.ME].rar
(PID) Process:(7704) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7704) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7704) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7704) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7704) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(7704) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:psize
Value:
80
Executable files
34
Suspicious files
88
Text files
26
Unknown types
2

Dropped files

PID
Process
Filename
Type
7704WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7704.9343\AnyDVD HD 8.1.4.0 FINAL + Crack [www.Tech-Tools.ME]\www.Tech-Tools.ME - www.ThumperDC.COM.txttext
MD5:1C5B921F612DCAAAC7173B34E8046CC0
SHA256:A927BC268E5F8F5E8DE43A715518B456B60C579FADDE3122EA49EADEF3626A4B
7704WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7704.9343\AnyDVD HD 8.1.4.0 FINAL + Crack [www.Tech-Tools.ME]\SetupAnyDVD8140.exeexecutable
MD5:6E8D35CD4E2E0EB185971915B56D24A1
SHA256:A7269D8A20956352A211ED02264F29BDDD57485ED44312756C12C0DF9F1EDC48
6044nstDFE3.tmpC:\Users\admin\AppData\Local\Temp\nstE159.tmp\setacl.exeexecutable
MD5:ACDE12FA9A971A254C76C34C0BBE8608
SHA256:243DEE6B04AA006BAEE70922DBE9AA80FD0682CBEF5E12AD1540CFD8D1188705
6044nstDFE3.tmpC:\Users\admin\AppData\Local\Temp\nstE159.tmp\ExecuteWithUAC.exeexecutable
MD5:549E70189FA7B3034A8E58A48CB353C0
SHA256:BB23AC0440D9DE37D035E68895C53C559DF4F31C8D0905033AB40AD0A2910E77
7272SetupAnyDVD8140.exeC:\Users\admin\AppData\Local\Temp\nstDFD3.tmp\nstDFE3.tmpexecutable
MD5:6E8D35CD4E2E0EB185971915B56D24A1
SHA256:A7269D8A20956352A211ED02264F29BDDD57485ED44312756C12C0DF9F1EDC48
7704WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7704.9343\AnyDVD HD 8.1.4.0 FINAL + Crack [www.Tech-Tools.ME]\Crack\patch.exeexecutable
MD5:02A70D4DF5444FB3B1B18F61100A06E9
SHA256:B4A5BAF9A5CB5E7D8A0A71B6D76219AB0C0530A7E9AAA8F4D6996EDEF78E23D5
6044nstDFE3.tmpC:\Users\admin\AppData\Local\Temp\nstE159.tmp\InstallHelp.dllexecutable
MD5:83B07F94937A933CC1CD4AA07210BAB0
SHA256:BC68FEF64641E6C17430A956664464ECD0E58439789B685051F41E7FE4D31098
7704WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7704.9343\AnyDVD HD 8.1.4.0 FINAL + Crack [www.Tech-Tools.ME]\Crack\_ReadMe.txttext
MD5:70863D97877E28248ACC9B0C0CF1DCEF
SHA256:9556FF727A962022A1A0BDB67EDB5AE8C1288733C24C97F6E851E10E3C1E31A0
7704WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa7704.9343\AnyDVD HD 8.1.4.0 FINAL + Crack [www.Tech-Tools.ME]\_ReadMe.txttext
MD5:70863D97877E28248ACC9B0C0CF1DCEF
SHA256:9556FF727A962022A1A0BDB67EDB5AE8C1288733C24C97F6E851E10E3C1E31A0
6044nstDFE3.tmpC:\Users\admin\AppData\Local\Temp\nstE159.tmp\Language\AnyDVDda.lngbinary
MD5:1910EE1A3EF65E2BE9DF799D7CAA3992
SHA256:1CFB702804D972528E7D68125DC465097C00DBF7EB99177FBC779AE5833111CA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
22
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7900
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5552
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5552
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
20.198.162.78:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
SG
whitelisted
6544
svchost.exe
20.190.160.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
7900
backgroundTaskHost.exe
20.103.156.88:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7900
backgroundTaskHost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
5552
SIHClient.exe
172.202.163.200:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
GB
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.142
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
client.wns.windows.com
  • 20.198.162.78
  • 20.198.162.76
whitelisted
login.live.com
  • 20.190.160.130
  • 40.126.32.74
  • 20.190.160.65
  • 40.126.32.136
  • 20.190.160.17
  • 20.190.160.4
  • 20.190.160.3
  • 20.190.160.67
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
arc.msn.com
  • 20.103.156.88
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
www.microsoft.com
  • 23.219.150.101
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted

Threats

No threats detected
No debug info