File name:

Denetim kurulu raporu hk (İşlevsel VERGİ DÜZENSİZLİKLERİ).msg

Full analysis: https://app.any.run/tasks/20f40096-8984-4db3-8b15-4b06e48eae01
Verdict: Malicious activity
Analysis date: May 14, 2025, 10:38:42
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
susp-attachments
attachments
attc-unc
Indicators:
MIME: application/vnd.ms-outlook
File info: CDFV2 Microsoft Outlook Message
MD5:

8A5D96C0637D53D4E273D50C344DB1DD

SHA1:

8F15E4294F98E823413C0568FA503E1D5A18B5BC

SHA256:

251E44221282891586C925C3F810B679A4CE11B5416D22BE5C1CC0790E34CC3A

SSDEEP:

24576:j8pE8YKYH8wn289wvXvn7N9I/CT7NJz2VBht8Fgp/pm9Wfw:j8pE8Y18wn2898Xvn7N9IKT7Xz2VBhtG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Email with suspicious attachment

      • OUTLOOK.EXE (PID: 660)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 8188)
    • Executes application which crashes

      • kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe (PID: 3020)
      • kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe (PID: 6540)
  • INFO

    • Reads the computer name

      • kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe (PID: 6540)
      • kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe (PID: 3020)
      • kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe (PID: 7820)
    • Reads the machine GUID from the registry

      • kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe (PID: 3020)
      • kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe (PID: 6540)
      • kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe (PID: 7820)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 8188)
    • Email with attachments

      • OUTLOOK.EXE (PID: 660)
    • Checks supported languages

      • kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe (PID: 3020)
      • kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe (PID: 6540)
      • kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe (PID: 7820)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 7444)
      • WerFault.exe (PID: 7632)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msg | Outlook Message (58.9)
.oft | Outlook Form Template (34.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
10
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start outlook.exe sppextcomobj.exe no specs slui.exe no specs ai.exe no specs winrar.exe kdv _ isdep 2 programı denetim kurulunun denetimi hakkında_ustyazi.exe kdv _ isdep 2 programı denetim kurulunun denetimi hakkında_ustyazi.exe werfault.exe no specs werfault.exe no specs kdv _ isdep 2 programı denetim kurulunun denetimi hakkında_ustyazi.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
660"C:\Program Files\Microsoft Office\Root\Office16\OUTLOOK.EXE" /f "C:\Users\admin\AppData\Local\Temp\Denetim kurulu raporu hk (İşlevsel VERGİ DÜZENSİZLİKLERİ).msg"C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Outlook
Version:
16.0.16026.20146
Modules
Images
c:\program files\microsoft office\root\office16\outlook.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\microsoft office\root\office16\vcruntime140_1.dll
c:\program files\microsoft office\root\office16\outlookservicing.dll
c:\windows\system32\advapi32.dll
c:\program files\microsoft office\root\office16\vcruntime140.dll
3020"C:\Users\admin\AppData\Local\Temp\Rar$EXa8188.46370\kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa8188.46370\kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe
WinRAR.exe
User:
admin
Company:
VelocityForge Technologies
Integrity Level:
MEDIUM
Description:
⚡ System Hyperion Titanium ⚡
Exit code:
3762504530
Version:
0.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa8188.46370\kdv _ isdep 2 programı denetim kurulunun denetimi hakkında_ustyazi.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
6540"C:\Users\admin\AppData\Local\Temp\Rar$EXa8188.47652\kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa8188.47652\kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe
WinRAR.exe
User:
admin
Company:
VelocityForge Technologies
Integrity Level:
MEDIUM
Description:
⚡ System Hyperion Titanium ⚡
Exit code:
3762504530
Version:
0.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa8188.47652\kdv _ isdep 2 programı denetim kurulunun denetimi hakkında_ustyazi.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
7444C:\WINDOWS\SysWOW64\WerFault.exe -u -p 3020 -s 1348C:\Windows\SysWOW64\WerFault.exekdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
7600C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7632C:\WINDOWS\SysWOW64\WerFault.exe -u -p 6540 -s 1328C:\Windows\SysWOW64\WerFault.exekdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
7656"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7740"C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exe" "F6484478-4A53-4EE2-AB2F-2953F34CE267" "83CCAAF0-C904-4071-9EE6-4B041385B3BB" "660"C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exeOUTLOOK.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Artificial Intelligence (AI) Host for the Microsoft® Windows® Operating System and Platform x64.
Version:
0.12.2.0
Modules
Images
c:\program files\microsoft office\root\vfs\programfilescommonx64\microsoft shared\office16\ai.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\common files\microsoft shared\clicktorun\appvisvsubsystems64.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\program files\common files\microsoft shared\clicktorun\c2r64.dll
c:\windows\system32\rpcrt4.dll
7820"C:\Users\admin\AppData\Local\Temp\Rar$EXa8188.49484\kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa8188.49484\kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exeWinRAR.exe
User:
admin
Company:
VelocityForge Technologies
Integrity Level:
MEDIUM
Description:
⚡ System Hyperion Titanium ⚡
Version:
0.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa8188.49484\kdv _ isdep 2 programı denetim kurulunun denetimi hakkında_ustyazi.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
8188"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\L3B9UIVB\kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.r09"C:\Program Files\WinRAR\WinRAR.exe
OUTLOOK.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
17 874
Read events
16 735
Write events
1 019
Delete events
120

Modification events

(PID) Process:(660) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\ClientTelemetry\Sampling
Operation:writeName:6
Value:
01941A000000001000B24E9A3E06000000000000000600000000000000
(PID) Process:(660) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\CrashPersistence\OUTLOOK\660
Operation:writeName:0
Value:
0B0E10C20161C2EBA8604D8063F22787EAE20F2300468CD9A7A4C697F1ED016A04102400449A7D64B29D01008500A907556E6B6E6F776EC906022222CA0DC2190000C91003783634C5119405D2120B6F00750074006C006F006F006B002E00650078006500C51620C517808004C91808323231322D44656300
(PID) Process:(660) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics
Operation:delete valueName:BootCommand
Value:
(PID) Process:(660) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics
Operation:delete valueName:BootFailureCount
Value:
(PID) Process:(660) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics\BootDiagnosticsDataPreviousSession
Operation:delete keyName:(default)
Value:
(PID) Process:(660) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics\BootDiagnosticsDataPreviousSession
Operation:writeName:CantBootResolution
Value:
BootSuccess
(PID) Process:(660) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics\BootDiagnosticsDataPreviousSession
Operation:writeName:ProfileBeingOpened
Value:
Outlook
(PID) Process:(660) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics\BootDiagnosticsDataPreviousSession
Operation:writeName:SessionId
Value:
C3D8E96E-C1AF-4750-8D52-F4E28119C131
(PID) Process:(660) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics\BootDiagnosticsDataPreviousSession
Operation:writeName:BootDiagnosticsLogFile
Value:
C:\Users\admin\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16026_20146-20240718T1116060318-1644.etl
(PID) Process:(660) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics
Operation:delete valueName:ProfileBeingOpened
Value:
Executable files
3
Suspicious files
15
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
660OUTLOOK.EXEC:\Users\admin\Documents\Outlook Files\Outlook1.pst
MD5:
SHA256:
660OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\FontCache\4\PreviewFont\flat_officeFontsPreview_4_41.ttfbinary
MD5:A807151D5747F6460143DC1FD2C3195F
SHA256:C0C3B354480E34CCC0C25D371B30D0272DB86C786AF6438C217998B0A30E5EB0
660OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\L3B9UIVB\kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi (002).r09:Zone.Identifiertext
MD5:FBCCF14D504B7B2DBCB5A5BDA75BD93B
SHA256:EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913
660OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\9986B998.datimage
MD5:81C2C1741DBD9893837CBB680337B1A7
SHA256:A76D238D17DD22CD80AF5F9F9458B61D7042E6B893544C1698A975F200A9682D
660OUTLOOK.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotmbinary
MD5:70726F63A04E08575C3EAA02123A9C6C
SHA256:38FBFCB1D5470F58352EF4262E7B5B51AF66517E8EE8FA11384D37A390BF080D
7444WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_AKGMR1R0HGKALBVF_fbe35aad6ff34f88fb2f10ec7e4cbd34faffac99_247028b0_9238be09-7a02-4a3e-abc7-6d51b40672da\Report.wer
MD5:
SHA256:
7444WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe.3020.dmp
MD5:
SHA256:
660OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\089d66ba04a8cec4bdc5267f42f39cf84278bb67.tbresbinary
MD5:7AD5A8123A2E311EDB19DABBD82C14BC
SHA256:9E3C58571CD74860F36BE859E49827693B787781E98AB3405AF42B63407C6E33
660OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\56a61aeb75d8f5be186c26607f4bb213abe7c5ec.tbresbinary
MD5:5F61E2B9634EF7194FB00B8F0DEC39A0
SHA256:61F92AF369E7D0EE27601F92D82BCD8E6B4C37C4301E241C3EA08AB042B99E30
660OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Office\16.0\AddInClassifierCache\OfficeSharedEntities.bintext
MD5:CC90D669144261B198DEAD45AA266572
SHA256:89C701EEFF939A44F28921FD85365ECD87041935DCD0FE0BAF04957DA12C9899
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
29
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
660
OUTLOOK.EXE
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
GET
200
23.32.238.112:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
660
OUTLOOK.EXE
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
1164
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1164
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.32.238.112:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
660
OUTLOOK.EXE
52.109.32.97:443
officeclient.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
GB
whitelisted
660
OUTLOOK.EXE
52.123.131.14:443
ecs.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
660
OUTLOOK.EXE
23.197.142.186:443
fs.microsoft.com
Akamai International B.V.
US
whitelisted
660
OUTLOOK.EXE
52.109.68.129:443
roaming.officeapps.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.32.238.112
  • 23.32.238.107
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 95.101.149.131
whitelisted
google.com
  • 172.217.16.142
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
officeclient.microsoft.com
  • 52.109.32.97
whitelisted
ecs.office.com
  • 52.123.131.14
  • 52.123.130.14
whitelisted
fs.microsoft.com
  • 23.197.142.186
whitelisted
roaming.officeapps.live.com
  • 52.109.68.129
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted

Threats

No threats detected
No debug info