File name:

Velocity Bootstrapper.exe

Full analysis: https://app.any.run/tasks/e57aa6b9-13ad-4a43-9cb5-5232bac4a200
Verdict: Malicious activity
Analysis date: February 05, 2025, 22:38:32
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
fody
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

A6CDBD38A42600CEDC2993F68D6C8C21

SHA1:

42057545BFFA1F9686B99B8D926CF99DFEEA02F7

SHA256:

285951B716AF4A7A38956FCE73249FDEBFB7EE7D626A52A1D396966003BD53E9

SSDEEP:

98304:wZX2pflB2bz14ZIMjWXS9NOMFqdxRdzoxPg/7SzHKJFZ8YMahPYmAkmYqSBHhy14:

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • dotnet-sdk-8.0.404-win-x64.exe (PID: 4672)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Velocity Bootstrapper.exe (PID: 6284)
      • dotnet-runtime-8.0.404-win-x64.exe (PID: 624)
    • Reads the date of Windows installation

      • Velocity Bootstrapper.exe (PID: 6284)
    • Starts a Microsoft application from unusual location

      • dotnet-runtime-8.0.404-win-x64.exe (PID: 5004)
      • dotnet-runtime-8.0.404-win-x64.exe (PID: 624)
      • dotnet-sdk-8.0.404-win-x64.exe (PID: 4672)
    • Executable content was dropped or overwritten

      • dotnet-runtime-8.0.404-win-x64.exe (PID: 5004)
      • dotnet-runtime-8.0.404-win-x64.exe (PID: 624)
      • dotnet-sdk-8.0.404-win-x64.exe (PID: 4672)
    • Process drops legitimate windows executable

      • dotnet-runtime-8.0.404-win-x64.exe (PID: 5004)
      • dotnet-runtime-8.0.404-win-x64.exe (PID: 624)
      • dotnet-sdk-8.0.404-win-x64.exe (PID: 4672)
    • Searches for installed software

      • dotnet-runtime-8.0.404-win-x64.exe (PID: 624)
    • Starts itself from another location

      • dotnet-runtime-8.0.404-win-x64.exe (PID: 624)
    • Creates a software uninstall entry

      • dotnet-sdk-8.0.404-win-x64.exe (PID: 4672)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 5236)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 5236)
  • INFO

    • Checks supported languages

      • Velocity Bootstrapper.exe (PID: 6284)
      • dotnet-runtime-8.0.404-win-x64.exe (PID: 5004)
      • dotnet-runtime-8.0.404-win-x64.exe (PID: 624)
      • dotnet-sdk-8.0.404-win-x64.exe (PID: 4672)
      • msiexec.exe (PID: 5236)
      • msiexec.exe (PID: 5092)
    • Reads the computer name

      • Velocity Bootstrapper.exe (PID: 6284)
      • dotnet-runtime-8.0.404-win-x64.exe (PID: 5004)
      • dotnet-runtime-8.0.404-win-x64.exe (PID: 624)
      • dotnet-sdk-8.0.404-win-x64.exe (PID: 4672)
      • msiexec.exe (PID: 5236)
      • msiexec.exe (PID: 5092)
    • Reads the machine GUID from the registry

      • Velocity Bootstrapper.exe (PID: 6284)
      • dotnet-sdk-8.0.404-win-x64.exe (PID: 4672)
      • msiexec.exe (PID: 5236)
    • Checks proxy server information

      • Velocity Bootstrapper.exe (PID: 6284)
    • Reads Environment values

      • Velocity Bootstrapper.exe (PID: 6284)
    • Reads the software policy settings

      • Velocity Bootstrapper.exe (PID: 6284)
      • msiexec.exe (PID: 5236)
    • Detects Fody packer (YARA)

      • Velocity Bootstrapper.exe (PID: 6284)
    • Create files in a temporary directory

      • Velocity Bootstrapper.exe (PID: 6284)
      • dotnet-runtime-8.0.404-win-x64.exe (PID: 624)
      • dotnet-sdk-8.0.404-win-x64.exe (PID: 4672)
    • Process checks computer location settings

      • Velocity Bootstrapper.exe (PID: 6284)
      • dotnet-runtime-8.0.404-win-x64.exe (PID: 624)
    • Disables trace logs

      • Velocity Bootstrapper.exe (PID: 6284)
    • The sample compiled with english language support

      • dotnet-runtime-8.0.404-win-x64.exe (PID: 5004)
      • dotnet-runtime-8.0.404-win-x64.exe (PID: 624)
      • dotnet-sdk-8.0.404-win-x64.exe (PID: 4672)
    • Creates files in the program directory

      • dotnet-sdk-8.0.404-win-x64.exe (PID: 4672)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 5236)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 5236)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2104:05:11 21:08:36+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 1703424
InitializedDataSize: 115200
UninitializedDataSize: -
EntryPoint: 0x1a1d1e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: Velocity Bootstrapper
FileVersion: 1.0.0.0
InternalName: Velocity Bootstrapper.exe
LegalCopyright: Copyright © 2025
LegalTrademarks: -
OriginalFileName: Velocity Bootstrapper.exe
ProductName: Velocity Bootstrapper
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
7
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start velocity bootstrapper.exe dotnet-runtime-8.0.404-win-x64.exe dotnet-runtime-8.0.404-win-x64.exe dotnet-sdk-8.0.404-win-x64.exe msiexec.exe msiexec.exe no specs velocity bootstrapper.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
624"C:\WINDOWS\Temp\{642AC432-8B25-4AE5-BC4B-C2E89250129B}\.cr\dotnet-runtime-8.0.404-win-x64.exe" -burn.clean.room="C:\Users\admin\AppData\Local\Temp\dotnet-runtime-8.0.404-win-x64.exe" -burn.filehandle.attached=708 -burn.filehandle.self=712 /quiet /norestartC:\Windows\Temp\{642AC432-8B25-4AE5-BC4B-C2E89250129B}\.cr\dotnet-runtime-8.0.404-win-x64.exe
dotnet-runtime-8.0.404-win-x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET SDK 8.0.404 (x64)
Version:
8.4.424.52308
Modules
Images
c:\windows\temp\{642ac432-8b25-4ae5-bc4b-c2e89250129b}\.cr\dotnet-runtime-8.0.404-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3092"C:\Users\admin\AppData\Local\Temp\Velocity Bootstrapper.exe" C:\Users\admin\AppData\Local\Temp\Velocity Bootstrapper.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Velocity Bootstrapper
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\velocity bootstrapper.exe
c:\windows\system32\ntdll.dll
4672"C:\WINDOWS\Temp\{6CC0DADE-744B-452E-8A8A-C669B0307157}\.be\dotnet-sdk-8.0.404-win-x64.exe" -q -burn.elevated BurnPipe.{99CA6A37-3723-4941-A260-F6B1662DDC04} {49FB353C-E5F9-49A6-AFDB-2A668870F61B} 624C:\Windows\Temp\{6CC0DADE-744B-452E-8A8A-C669B0307157}\.be\dotnet-sdk-8.0.404-win-x64.exe
dotnet-runtime-8.0.404-win-x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET SDK 8.0.404 (x64)
Version:
8.4.424.52308
Modules
Images
c:\windows\temp\{6cc0dade-744b-452e-8a8a-c669b0307157}\.be\dotnet-sdk-8.0.404-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5004"C:\Users\admin\AppData\Local\Temp\dotnet-runtime-8.0.404-win-x64.exe" /quiet /norestartC:\Users\admin\AppData\Local\Temp\dotnet-runtime-8.0.404-win-x64.exe
Velocity Bootstrapper.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET SDK 8.0.404 (x64)
Version:
8.4.424.52308
Modules
Images
c:\users\admin\appdata\local\temp\dotnet-runtime-8.0.404-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5092C:\Windows\syswow64\MsiExec.exe -Embedding ABF4197473A07E6031FB0FEBD33D8200C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
5236C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6284"C:\Users\admin\AppData\Local\Temp\Velocity Bootstrapper.exe" C:\Users\admin\AppData\Local\Temp\Velocity Bootstrapper.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Velocity Bootstrapper
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\velocity bootstrapper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
6 726
Read events
6 681
Write events
43
Delete events
2

Modification events

(PID) Process:(6284) Velocity Bootstrapper.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Velocity Bootstrapper_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6284) Velocity Bootstrapper.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Velocity Bootstrapper_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6284) Velocity Bootstrapper.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Velocity Bootstrapper_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6284) Velocity Bootstrapper.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Velocity Bootstrapper_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(6284) Velocity Bootstrapper.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Velocity Bootstrapper_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(6284) Velocity Bootstrapper.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Velocity Bootstrapper_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(6284) Velocity Bootstrapper.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Velocity Bootstrapper_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(6284) Velocity Bootstrapper.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Velocity Bootstrapper_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6284) Velocity Bootstrapper.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Velocity Bootstrapper_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6284) Velocity Bootstrapper.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Velocity Bootstrapper_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
68
Suspicious files
5
Text files
21
Unknown types
0

Dropped files

PID
Process
Filename
Type
6284Velocity Bootstrapper.exeC:\Users\admin\AppData\Local\Temp\dotnet-runtime-8.0.404-win-x64.exe
MD5:
SHA256:
624dotnet-runtime-8.0.404-win-x64.exeC:\Windows\Temp\{6CC0DADE-744B-452E-8A8A-C669B0307157}\.ba\wixstdba.dllexecutable
MD5:F1919C6BD85D7A78A70C228A5B227FBE
SHA256:DCEA15F3710822FFC262E62EC04CC7BBBF0F33F5D1A853609FBFB65CB6A45640
624dotnet-runtime-8.0.404-win-x64.exeC:\Windows\Temp\{6CC0DADE-744B-452E-8A8A-C669B0307157}\.ba\1031\thm.wxlxml
MD5:D9F3E60B1262A4140991C47BC9D2E37F
SHA256:6B37D837535CA6AB6D46703EADF9CD87965DE6DA66F034F0053F52971150FC43
624dotnet-runtime-8.0.404-win-x64.exeC:\Windows\Temp\{6CC0DADE-744B-452E-8A8A-C669B0307157}\.ba\thm.xmlxml
MD5:BC4C1B302D6C87C4026508120E167C95
SHA256:C9E7E37D46601196E0DDA5D42FDF80C533DAB4CDF09D68E5A7C9A86C05795E00
624dotnet-runtime-8.0.404-win-x64.exeC:\Windows\Temp\{6CC0DADE-744B-452E-8A8A-C669B0307157}\.ba\1028\thm.wxlxml
MD5:9FE46D49770E77244310F4792D3D80E3
SHA256:E223393A3CD462D725D56D687DFB2EB3CC1C380D7CCFAD12329547F6816979ED
624dotnet-runtime-8.0.404-win-x64.exeC:\Windows\Temp\{6CC0DADE-744B-452E-8A8A-C669B0307157}\.ba\bg.pngimage
MD5:9EB0320DFBF2BD541E6A55C01DDC9F20
SHA256:9095BF7B6BAA0107B40A4A6D727215BE077133A190F4CA9BD89A176842141E79
624dotnet-runtime-8.0.404-win-x64.exeC:\Windows\Temp\{6CC0DADE-744B-452E-8A8A-C669B0307157}\.ba\1040\thm.wxlxml
MD5:29AECDE585E557A812B86141F0656043
SHA256:04FAD78A493E7123CABCFD4E0A405AF3FD2175CF24AD4CE93B30539029FEC5C3
624dotnet-runtime-8.0.404-win-x64.exeC:\Windows\Temp\{6CC0DADE-744B-452E-8A8A-C669B0307157}\.ba\1036\thm.wxlxml
MD5:D6EE9DCF43CB004B3098959CC0FE6F5A
SHA256:7236A5B0527BCA84AED153568914BCC6AFF5C97676B0749EA565AE8881583B2C
624dotnet-runtime-8.0.404-win-x64.exeC:\Windows\Temp\{6CC0DADE-744B-452E-8A8A-C669B0307157}\dotnet_runtime_8.0.11_win_x64.msi
MD5:
SHA256:
624dotnet-runtime-8.0.404-win-x64.exeC:\Windows\Temp\{6CC0DADE-744B-452E-8A8A-C669B0307157}\.ba\1042\thm.wxlxml
MD5:676E54598F3D02298D6E7B09009B4F9D
SHA256:53094DBF95BD71458E20E4CE0292730D6606E9DEEE290BCCCA13F1D1F8D4E9E3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
32
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.209.214.100:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6252
SIHClient.exe
GET
200
23.209.214.100:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6252
SIHClient.exe
GET
200
23.209.214.100:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5236
msiexec.exe
GET
200
2.19.11.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.209.214.100:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
23.209.214.100:80
www.microsoft.com
PT. Telekomunikasi Selular
ID
whitelisted
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5064
SearchApp.exe
95.101.170.199:443
www.bing.com
Akamai International B.V.
BR
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
6284
Velocity Bootstrapper.exe
199.232.214.172:443
download.visualstudio.microsoft.com
FASTLY
US
whitelisted
1520
RUXIMICS.exe
20.73.194.208:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
20.190.160.3:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
www.microsoft.com
  • 23.209.214.100
whitelisted
google.com
  • 142.250.185.238
whitelisted
www.bing.com
  • 95.101.170.199
  • 95.101.170.201
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
download.visualstudio.microsoft.com
  • 199.232.214.172
  • 199.232.210.172
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
login.live.com
  • 20.190.160.3
  • 40.126.32.133
  • 40.126.32.138
  • 20.190.160.65
  • 40.126.32.74
  • 20.190.160.132
  • 20.190.160.130
  • 40.126.32.72
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

No threats detected
No debug info