File name:

Denetim kurulu raporu hk (İşlevsel VERGİ DÜZENSİZLİKLERİ).msg

Full analysis: https://app.any.run/tasks/20f40096-8984-4db3-8b15-4b06e48eae01
Verdict: Malicious activity
Analysis date: May 14, 2025, 10:38:42
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
susp-attachments
attachments
attc-unc
Indicators:
MIME: application/vnd.ms-outlook
File info: CDFV2 Microsoft Outlook Message
MD5:

8A5D96C0637D53D4E273D50C344DB1DD

SHA1:

8F15E4294F98E823413C0568FA503E1D5A18B5BC

SHA256:

251E44221282891586C925C3F810B679A4CE11B5416D22BE5C1CC0790E34CC3A

SSDEEP:

24576:j8pE8YKYH8wn289wvXvn7N9I/CT7NJz2VBht8Fgp/pm9Wfw:j8pE8Y18wn2898Xvn7N9IKT7Xz2VBhtG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Email with suspicious attachment

      • OUTLOOK.EXE (PID: 660)
    • Executes application which crashes

      • kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe (PID: 3020)
      • kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe (PID: 6540)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 8188)
  • INFO

    • Email with attachments

      • OUTLOOK.EXE (PID: 660)
    • Checks supported languages

      • kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe (PID: 3020)
      • kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe (PID: 6540)
      • kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe (PID: 7820)
    • Reads the computer name

      • kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe (PID: 3020)
      • kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe (PID: 6540)
      • kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe (PID: 7820)
    • Reads the machine GUID from the registry

      • kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe (PID: 3020)
      • kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe (PID: 6540)
      • kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe (PID: 7820)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 7444)
      • WerFault.exe (PID: 7632)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 8188)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.msg | Outlook Message (58.9)
.oft | Outlook Form Template (34.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
10
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start outlook.exe sppextcomobj.exe no specs slui.exe no specs ai.exe no specs winrar.exe kdv _ isdep 2 programı denetim kurulunun denetimi hakkında_ustyazi.exe kdv _ isdep 2 programı denetim kurulunun denetimi hakkında_ustyazi.exe werfault.exe no specs werfault.exe no specs kdv _ isdep 2 programı denetim kurulunun denetimi hakkında_ustyazi.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
660"C:\Program Files\Microsoft Office\Root\Office16\OUTLOOK.EXE" /f "C:\Users\admin\AppData\Local\Temp\Denetim kurulu raporu hk (İşlevsel VERGİ DÜZENSİZLİKLERİ).msg"C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Outlook
Version:
16.0.16026.20146
Modules
Images
c:\program files\microsoft office\root\office16\outlook.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\microsoft office\root\office16\vcruntime140_1.dll
c:\program files\microsoft office\root\office16\outlookservicing.dll
c:\windows\system32\advapi32.dll
c:\program files\microsoft office\root\office16\vcruntime140.dll
3020"C:\Users\admin\AppData\Local\Temp\Rar$EXa8188.46370\kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa8188.46370\kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe
WinRAR.exe
User:
admin
Company:
VelocityForge Technologies
Integrity Level:
MEDIUM
Description:
⚡ System Hyperion Titanium ⚡
Exit code:
3762504530
Version:
0.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa8188.46370\kdv _ isdep 2 programı denetim kurulunun denetimi hakkında_ustyazi.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
6540"C:\Users\admin\AppData\Local\Temp\Rar$EXa8188.47652\kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa8188.47652\kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe
WinRAR.exe
User:
admin
Company:
VelocityForge Technologies
Integrity Level:
MEDIUM
Description:
⚡ System Hyperion Titanium ⚡
Exit code:
3762504530
Version:
0.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa8188.47652\kdv _ isdep 2 programı denetim kurulunun denetimi hakkında_ustyazi.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
7444C:\WINDOWS\SysWOW64\WerFault.exe -u -p 3020 -s 1348C:\Windows\SysWOW64\WerFault.exekdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
7600C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7632C:\WINDOWS\SysWOW64\WerFault.exe -u -p 6540 -s 1328C:\Windows\SysWOW64\WerFault.exekdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
7656"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7740"C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exe" "F6484478-4A53-4EE2-AB2F-2953F34CE267" "83CCAAF0-C904-4071-9EE6-4B041385B3BB" "660"C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exeOUTLOOK.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Artificial Intelligence (AI) Host for the Microsoft® Windows® Operating System and Platform x64.
Version:
0.12.2.0
Modules
Images
c:\program files\microsoft office\root\vfs\programfilescommonx64\microsoft shared\office16\ai.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\common files\microsoft shared\clicktorun\appvisvsubsystems64.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\program files\common files\microsoft shared\clicktorun\c2r64.dll
c:\windows\system32\rpcrt4.dll
7820"C:\Users\admin\AppData\Local\Temp\Rar$EXa8188.49484\kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa8188.49484\kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exeWinRAR.exe
User:
admin
Company:
VelocityForge Technologies
Integrity Level:
MEDIUM
Description:
⚡ System Hyperion Titanium ⚡
Version:
0.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa8188.49484\kdv _ isdep 2 programı denetim kurulunun denetimi hakkında_ustyazi.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
8188"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\L3B9UIVB\kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.r09"C:\Program Files\WinRAR\WinRAR.exe
OUTLOOK.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
17 874
Read events
16 735
Write events
1 019
Delete events
120

Modification events

(PID) Process:(660) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\ClientTelemetry\Sampling
Operation:writeName:6
Value:
01941A000000001000B24E9A3E06000000000000000600000000000000
(PID) Process:(660) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\CrashPersistence\OUTLOOK\660
Operation:writeName:0
Value:
0B0E10C20161C2EBA8604D8063F22787EAE20F2300468CD9A7A4C697F1ED016A04102400449A7D64B29D01008500A907556E6B6E6F776EC906022222CA0DC2190000C91003783634C5119405D2120B6F00750074006C006F006F006B002E00650078006500C51620C517808004C91808323231322D44656300
(PID) Process:(660) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics
Operation:delete valueName:BootCommand
Value:
(PID) Process:(660) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics
Operation:delete valueName:BootFailureCount
Value:
(PID) Process:(660) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics\BootDiagnosticsDataPreviousSession
Operation:delete keyName:(default)
Value:
(PID) Process:(660) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics\BootDiagnosticsDataPreviousSession
Operation:writeName:CantBootResolution
Value:
BootSuccess
(PID) Process:(660) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics\BootDiagnosticsDataPreviousSession
Operation:writeName:ProfileBeingOpened
Value:
Outlook
(PID) Process:(660) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics\BootDiagnosticsDataPreviousSession
Operation:writeName:SessionId
Value:
C3D8E96E-C1AF-4750-8D52-F4E28119C131
(PID) Process:(660) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics\BootDiagnosticsDataPreviousSession
Operation:writeName:BootDiagnosticsLogFile
Value:
C:\Users\admin\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16026_20146-20240718T1116060318-1644.etl
(PID) Process:(660) OUTLOOK.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Diagnostics
Operation:delete valueName:ProfileBeingOpened
Value:
Executable files
3
Suspicious files
15
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
660OUTLOOK.EXEC:\Users\admin\Documents\Outlook Files\Outlook1.pst
MD5:
SHA256:
660OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\5EE78AB0-020F-4FA8-84C5-39FB92F5A86Axml
MD5:95CF8D6445AA867E209132A2D7F78611
SHA256:D983FA17E6AD1CF558A878270ED5C6634286773172E87147E56993607F234131
660OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\9986B998.datimage
MD5:81C2C1741DBD9893837CBB680337B1A7
SHA256:A76D238D17DD22CD80AF5F9F9458B61D7042E6B893544C1698A975F200A9682D
660OUTLOOK.EXEC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9binary
MD5:8268898AFA791EE6FEC1DC4958A91849
SHA256:86EEE3372BA1DFA88DCC70ACD26971EFBC8AC7DE87499466E778843C90A43E21
660OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\089d66ba04a8cec4bdc5267f42f39cf84278bb67.tbresbinary
MD5:7AD5A8123A2E311EDB19DABBD82C14BC
SHA256:9E3C58571CD74860F36BE859E49827693B787781E98AB3405AF42B63407C6E33
7444WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_AKGMR1R0HGKALBVF_fbe35aad6ff34f88fb2f10ec7e4cbd34faffac99_247028b0_9238be09-7a02-4a3e-abc7-6d51b40672da\Report.wer
MD5:
SHA256:
7444WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\kdv _ ISDEP 2 Programı Denetim Kurulunun Denetimi Hakkında_Ustyazi.exe.3020.dmp
MD5:
SHA256:
660OUTLOOK.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$rmalEmail.dotmbinary
MD5:70726F63A04E08575C3EAA02123A9C6C
SHA256:38FBFCB1D5470F58352EF4262E7B5B51AF66517E8EE8FA11384D37A390BF080D
660OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\FontCache\4\PreviewFont\flat_officeFontsPreview_4_41.ttfbinary
MD5:A807151D5747F6460143DC1FD2C3195F
SHA256:C0C3B354480E34CCC0C25D371B30D0272DB86C786AF6438C217998B0A30E5EB0
660OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Office\16.0\AddInClassifierCache\OfficeSharedEntities.bintext
MD5:CC90D669144261B198DEAD45AA266572
SHA256:89C701EEFF939A44F28921FD85365ECD87041935DCD0FE0BAF04957DA12C9899
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
29
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.32.238.112:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
660
OUTLOOK.EXE
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
660
OUTLOOK.EXE
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
1164
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1164
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.32.238.112:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
660
OUTLOOK.EXE
52.109.32.97:443
officeclient.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
GB
whitelisted
660
OUTLOOK.EXE
52.123.131.14:443
ecs.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
660
OUTLOOK.EXE
23.197.142.186:443
fs.microsoft.com
Akamai International B.V.
US
whitelisted
660
OUTLOOK.EXE
52.109.68.129:443
roaming.officeapps.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.32.238.112
  • 23.32.238.107
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 95.101.149.131
whitelisted
google.com
  • 172.217.16.142
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
officeclient.microsoft.com
  • 52.109.32.97
whitelisted
ecs.office.com
  • 52.123.131.14
  • 52.123.130.14
whitelisted
fs.microsoft.com
  • 23.197.142.186
whitelisted
roaming.officeapps.live.com
  • 52.109.68.129
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted

Threats

No threats detected
No debug info