File name:

USB Safely Remove 7.1.2.1327 Incl Keygen - KhanPC.zip

Full analysis: https://app.any.run/tasks/8c7f0b8c-ca09-4550-b0fd-5b2e6a3703d4
Verdict: Malicious activity
Analysis date: June 15, 2025, 17:43:15
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
delphi
inno
installer
Indicators:
MIME: application/zip
File info: Zip archive data, at least v1.0 to extract, compression method=store
MD5:

092D9A47D185731D30F7F312048BDE8E

SHA1:

C6BD996C70EDBFA42FEE80A1351367760F804559

SHA256:

2616C236AEA7FF67D20B77ABC40BEB70E5A7022665766652CA66BB99F142260C

SSDEEP:

98304:p9dwG0pEiMuF7gU1ws8/PxlaMh/PtPoYTXCZJCg5t+VtLJLR10We+B6HVNSwhFvL:uO3vrX+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 5644)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • SetUp.exe (PID: 1564)
      • SetUp.tmp (PID: 1332)
      • KeyGen.exe (PID: 1044)
      • dllhost.exe (PID: 4020)
    • Reads the Windows owner or organization settings

      • SetUp.tmp (PID: 1332)
    • Drops a system driver (possible attempt to evade defenses)

      • SetUp.tmp (PID: 1332)
    • Reads security settings of Internet Explorer

      • SetUp.tmp (PID: 1332)
    • Executes as Windows Service

      • USBSRService.exe (PID: 6756)
    • There is functionality for taking screenshot (YARA)

      • KeyGen.exe (PID: 1036)
      • KeyGen.exe (PID: 1044)
  • INFO

    • Manual execution by a user

      • SetUp.exe (PID: 1564)
      • WinRAR.exe (PID: 3396)
      • KeyGen.exe (PID: 1036)
      • KeyGen.exe (PID: 1044)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 5644)
      • WinRAR.exe (PID: 3396)
    • Checks supported languages

      • SetUp.exe (PID: 1564)
      • SetUp.tmp (PID: 1332)
      • USBSRService.exe (PID: 304)
      • USBSRService.exe (PID: 6756)
      • KeyGen.exe (PID: 1036)
    • Create files in a temporary directory

      • SetUp.exe (PID: 1564)
      • SetUp.tmp (PID: 1332)
    • Reads the computer name

      • SetUp.tmp (PID: 1332)
      • USBSRService.exe (PID: 304)
      • USBSRService.exe (PID: 6756)
      • KeyGen.exe (PID: 1036)
    • Detects InnoSetup installer (YARA)

      • SetUp.exe (PID: 1564)
      • SetUp.tmp (PID: 1332)
    • Compiled with Borland Delphi (YARA)

      • SetUp.exe (PID: 1564)
      • SetUp.tmp (PID: 1332)
    • Creates files in the program directory

      • SetUp.tmp (PID: 1332)
      • USBSRService.exe (PID: 304)
    • The sample compiled with english language support

      • SetUp.tmp (PID: 1332)
      • KeyGen.exe (PID: 1044)
    • Creates files or folders in the user directory

      • SetUp.tmp (PID: 1332)
    • Creates a software uninstall entry

      • SetUp.tmp (PID: 1332)
    • Process checks computer location settings

      • SetUp.tmp (PID: 1332)
    • Reads the software policy settings

      • slui.exe (PID: 3624)
    • Checks proxy server information

      • slui.exe (PID: 3624)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xpi | Mozilla Firefox browser extension (66.6)
.zip | ZIP compressed archive (33.3)

EXIF

ZIP

ZipRequiredVersion: 10
ZipBitFlag: 0x0800
ZipCompression: None
ZipModifyDate: 2025:06:15 17:42:20
ZipCRC: 0x16b43bd8
ZipCompressedSize: 109249
ZipUncompressedSize: 109249
ZipFileName: USB Safely Remove 7.1.2.1327 Incl Keygen - KhanPC/Keygen.zip
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
154
Monitored processes
11
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winrar.exe slui.exe rundll32.exe no specs winrar.exe setup.exe setup.tmp usbsrservice.exe no specs usbsrservice.exe no specs keygen.exe Copy/Move/Rename/Delete/Link Object keygen.exe

Process information

PID
CMD
Path
Indicators
Parent process
304"C:\Program Files (x86)\USB Safely Remove\USBSRService.exe" /install /silentC:\Program Files (x86)\USB Safely Remove\USBSRService.exeSetUp.tmp
User:
admin
Company:
Crystal Rich Ltd
Integrity Level:
HIGH
Description:
USB Safely Remove assistant service
Exit code:
0
Version:
7.1.1.1326
Modules
Images
c:\program files (x86)\usb safely remove\usbsrservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1036"C:\Users\admin\Desktop\USB Safely Remove 7.1.2.1327 Incl Keygen - KhanPC\Keygen\KeyGen.exe" C:\Users\admin\Desktop\USB Safely Remove 7.1.2.1327 Incl Keygen - KhanPC\Keygen\KeyGen.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\usb safely remove 7.1.2.1327 incl keygen - khanpc\keygen\keygen.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1044"C:\Program Files (x86)\USB Safely Remove\KeyGen.exe" C:\Program Files (x86)\USB Safely Remove\KeyGen.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files (x86)\usb safely remove\keygen.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1332"C:\Users\admin\AppData\Local\Temp\is-2B78J.tmp\SetUp.tmp" /SL5="$F02CE,3235808,145920,C:\Users\admin\Desktop\USB Safely Remove 7.1.2.1327 Incl Keygen - KhanPC\SetUp.exe" C:\Users\admin\AppData\Local\Temp\is-2B78J.tmp\SetUp.tmp
SetUp.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-2b78j.tmp\setup.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
1564"C:\Users\admin\Desktop\USB Safely Remove 7.1.2.1327 Incl Keygen - KhanPC\SetUp.exe" C:\Users\admin\Desktop\USB Safely Remove 7.1.2.1327 Incl Keygen - KhanPC\SetUp.exe
explorer.exe
User:
admin
Company:
Crystal Rich Ltd
Integrity Level:
HIGH
Description:
USB Safely Remove Setup
Version:
7.1.1.1326
Modules
Images
c:\users\admin\desktop\usb safely remove 7.1.2.1327 incl keygen - khanpc\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
2076C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
3396"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver -- "C:\Users\admin\Desktop\USB Safely Remove 7.1.2.1327 Incl Keygen - KhanPC\Keygen.zip" "C:\Users\admin\Desktop\USB Safely Remove 7.1.2.1327 Incl Keygen - KhanPC\"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3624C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4020C:\WINDOWS\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09}C:\Windows\System32\dllhost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
5644"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\USB Safely Remove 7.1.2.1327 Incl Keygen - KhanPC.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
7 488
Read events
7 353
Write events
114
Delete events
21

Modification events

(PID) Process:(5644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(5644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(5644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(5644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\USB Safely Remove 7.1.2.1327 Incl Keygen - KhanPC.zip
(PID) Process:(5644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(5644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(5644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(5644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(5644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:15
Value:
(PID) Process:(5644) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:14
Value:
Executable files
16
Suspicious files
16
Text files
485
Unknown types
0

Dropped files

PID
Process
Filename
Type
5644WinRAR.exeC:\Users\admin\Desktop\USB Safely Remove 7.1.2.1327 Incl Keygen - KhanPC\How to Install.txttext
MD5:360C93747C81146F22154F8BE82C0962
SHA256:5095C1EC8815C4C14A3D3308719E1276D33E3782B4A3D48F11CD300893EB524F
5644WinRAR.exeC:\Users\admin\Desktop\USB Safely Remove 7.1.2.1327 Incl Keygen - KhanPC\Like Us Facebook.URLbinary
MD5:72267D54CBB304DF0C624E78E8C090E2
SHA256:87EED86BE2C5A105A0F1CFF92FDCE72B3D7DD8D490874CC9B57B745D93E5F251
5644WinRAR.exeC:\Users\admin\Desktop\USB Safely Remove 7.1.2.1327 Incl Keygen - KhanPC\Keygen.zipcompressed
MD5:77EF6A0DD5B6803DFE1095EB62B35763
SHA256:54C026081B716C3C43E06BDC68875EDDCAC39FE63F2F5591E94A89A02EFCDA5C
1332SetUp.tmpC:\Program Files (x86)\USB Safely Remove\DeviceImages\is-CH9C5.tmpimage
MD5:F8F80923B68C6C2E4266364A3FB9CCBE
SHA256:50B2B00A74BC3B8D68DE0A4FAF329E83D10AE79FDB83682326122B4EA3C9D702
1332SetUp.tmpC:\Program Files (x86)\USB Safely Remove\DeviceImages\Bluetooth.icoimage
MD5:F8F80923B68C6C2E4266364A3FB9CCBE
SHA256:50B2B00A74BC3B8D68DE0A4FAF329E83D10AE79FDB83682326122B4EA3C9D702
1332SetUp.tmpC:\Program Files (x86)\USB Safely Remove\is-Q712H.tmpexecutable
MD5:864BBE38FEB8773D562C47FE958F4164
SHA256:9FE098458FCE97341D752EDD5C998231F49BB7D30E8993121A6436290296AF05
5644WinRAR.exeC:\Users\admin\Desktop\USB Safely Remove 7.1.2.1327 Incl Keygen - KhanPC\SetUp.exeexecutable
MD5:DF72C892132F5B1615314314B2302965
SHA256:17036A3C3B7B53FA30B1CC70235C8574B23900A1925A48E67315E4C1D15BF637
1564SetUp.exeC:\Users\admin\AppData\Local\Temp\is-2B78J.tmp\SetUp.tmpexecutable
MD5:AD51A2FA0D4E495C95FA4D9BE19418B0
SHA256:B22F23CD7FFB5E8D9D2430D837C7A00EA09D6FBD8604C9938C13FC535862CFB4
1332SetUp.tmpC:\Program Files (x86)\USB Safely Remove\DeviceImages\is-GUED3.tmpimage
MD5:C25501DE265B8A6851CFF9C98F14E516
SHA256:8F7D3B3774C73FDD67548074FD0BBA864300B97D64A359D482138FC705118D25
3396WinRAR.exeC:\Users\admin\Desktop\USB Safely Remove 7.1.2.1327 Incl Keygen - KhanPC\Keygen\KeyGen.exeexecutable
MD5:9C5FB44D68698F39A64C0D5CC3A33279
SHA256:F814596DBB325AF2095D6BE91027E9BEDDCABA572E9D7FB2013379C64EDA5A68
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
30
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4832
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1268
svchost.exe
GET
200
2.16.168.114:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6016
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6024
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6016
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2940
svchost.exe
GET
200
23.209.209.135:80
http://x1.c.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6960
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2336
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
4832
svchost.exe
40.126.32.136:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4832
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1268
svchost.exe
2.16.168.114:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
1268
svchost.exe
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
whitelisted
google.com
  • 142.250.185.238
whitelisted
client.wns.windows.com
  • 172.211.123.250
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.32.136
  • 40.126.32.138
  • 20.190.160.66
  • 20.190.160.17
  • 20.190.160.14
  • 20.190.160.131
  • 20.190.160.3
  • 40.126.32.133
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
crl.microsoft.com
  • 2.16.168.114
  • 2.16.168.124
whitelisted
www.microsoft.com
  • 23.219.150.101
  • 95.101.149.131
whitelisted
nexusrules.officeapps.live.com
  • 52.111.227.11
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted

Threats

No threats detected
No debug info