File name:

FiveM (1).exe

Full analysis: https://app.any.run/tasks/f4be57cd-50ed-4bcc-9377-ed1fc4f1bb64
Verdict: Malicious activity
Analysis date: July 07, 2024, 03:49:26
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

C397F272B00FF8221678E28CDF0F7E3A

SHA1:

721E8237EDA2F3EBA05307B50EDB49162B06D0DC

SHA256:

2A17EECCA2D73F4F148C81938F18463887561703CEA09565EBF85DC39E5B2C65

SSDEEP:

98304:Cs1u/BuMzTdCvx4JQfXBAk9XJrCmA1bjgy1klNPB0E+0lnJyKOaB05He/tzFEeeL:u1mL+MFe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • FiveM (1).exe (PID: 5872)
      • CitizenFX.exe.new (PID: 6060)
      • FiveM (1).exe (PID: 4220)
      • FiveM.exe (PID: 1824)
    • Actions looks like stealing of personal data

      • FiveM.exe (PID: 1824)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • FiveM (1).exe (PID: 4220)
      • FiveM (1).exe (PID: 5872)
      • CitizenFX.exe.new (PID: 6060)
      • FiveM.exe (PID: 1824)
    • Reads security settings of Internet Explorer

      • FiveM (1).exe (PID: 5872)
      • FiveM.exe (PID: 1824)
      • GameBar.exe (PID: 736)
      • ShellExperienceHost.exe (PID: 2652)
      • CitizenFX.exe.new (PID: 6060)
    • Starts application with an unusual extension

      • FiveM (1).exe (PID: 5872)
    • Starts itself from another location

      • FiveM (1).exe (PID: 4220)
      • CitizenFX.exe.new (PID: 6060)
    • Creates a software uninstall entry

      • FiveM.exe (PID: 1824)
    • Write to the desktop.ini file (may be used to cloak folders)

      • FiveM.exe (PID: 1824)
    • Process drops legitimate windows executable

      • FiveM.exe (PID: 1824)
    • Executes as Windows Service

      • vds.exe (PID: 776)
    • Reads the date of Windows installation

      • CitizenFX.exe.new (PID: 6060)
  • INFO

    • Creates files or folders in the user directory

      • FiveM (1).exe (PID: 4220)
      • FiveM.exe (PID: 1824)
    • Reads the computer name

      • FiveM (1).exe (PID: 5872)
      • CitizenFX.exe.new (PID: 6060)
      • FiveM.exe (PID: 1824)
      • GameBar.exe (PID: 736)
      • ShellExperienceHost.exe (PID: 2652)
      • FiveM (1).exe (PID: 4220)
    • Checks supported languages

      • FiveM (1).exe (PID: 5872)
      • CitizenFX.exe.new (PID: 6060)
      • FiveM.exe (PID: 1824)
      • ShellExperienceHost.exe (PID: 2652)
      • GameBar.exe (PID: 736)
      • FiveM (1).exe (PID: 4220)
    • Create files in a temporary directory

      • FiveM (1).exe (PID: 5872)
      • CitizenFX.exe.new (PID: 6060)
    • Manual execution by a user

      • WINWORD.EXE (PID: 1644)
    • Process checks computer location settings

      • CitizenFX.exe.new (PID: 6060)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:06:25 16:09:06+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.36
CodeSize: 3393024
InitializedDataSize: 1921536
UninitializedDataSize: -
EntryPoint: 0x28e3b0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.8691
ProductVersionNumber: 2.0.0.8691
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Cfx.re
FileDescription: FiveM
InternalName: FiveM
FileVersion: 2.0.0.8691
LegalCopyright: (C) 2015-2022 Cfx.re
OriginalFileName: CitizenMP.exe
ProductName: FiveM
ProductVersion: 2.0.0.8691
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
162
Monitored processes
14
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start fivem (1).exe citizenfx.exe.new fivem (1).exe fivem.exe winword.exe ai.exe no specs gamebarpresencewriter.exe no specs gamebar.exe no specs sppextcomobj.exe no specs slui.exe no specs gamebarpresencewriter.exe no specs shellexperiencehost.exe no specs vdsldr.exe no specs vds.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
736"C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exe" -ServerName:App.AppXbdkk0yrkwpcgeaem8zk81k8py1eaahny.mcaC:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exesvchost.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\program files\windowsapps\microsoft.xboxgamingoverlay_2.34.28001.0_x64__8wekyb3d8bbwe\gamebar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\vcruntime140_app.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\concrt140_app.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\vccorlib140_app.dll
776C:\WINDOWS\System32\vds.exeC:\Windows\System32\vds.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Virtual Disk Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vds.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1644"C:\Program Files\Microsoft Office\Root\Office16\WINWORD.EXE" /n "C:\Users\admin\Desktop\familiesfind.rtf" /o ""C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Exit code:
0
Version:
16.0.16026.20146
Modules
Images
c:\program files\microsoft office\root\office16\winword.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1824"C:\Users\admin\AppData\Local\FiveM\FiveM.exe"C:\Users\admin\AppData\Local\FiveM\FiveM.exe
FiveM (1).exe
User:
admin
Company:
Cfx.re
Integrity Level:
MEDIUM
Description:
FiveM
Exit code:
0
Version:
2.0.0.8830
Modules
Images
c:\users\admin\appdata\local\fivem\fivem.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\comctl32.dll
c:\windows\system32\win32u.dll
2652"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mcaC:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Shell Experience Host
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\msvcp_win.dll
3972"C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exe" "66965DDC-95B2-4D3B-B4DB-E73F92484D78" "307E0096-7283-47D1-ACCE-ACE95AFFC7C0" "1644"C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exeWINWORD.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Artificial Intelligence (AI) Host for the Microsoft® Windows® Operating System and Platform x64.
Exit code:
0
Version:
0.12.2.0
Modules
Images
c:\program files\microsoft office\root\vfs\programfilescommonx64\microsoft shared\office16\ai.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files\common files\microsoft shared\clicktorun\appvisvsubsystems64.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
4220"C:\Users\admin\AppData\Local\Temp\FiveM (1).exe" C:\Users\admin\AppData\Local\Temp\FiveM (1).exe
CitizenFX.exe.new
User:
admin
Company:
Cfx.re
Integrity Level:
MEDIUM
Description:
FiveM
Exit code:
0
Version:
2.0.0.8830
Modules
Images
c:\users\admin\appdata\local\temp\fivem (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5504C:\WINDOWS\System32\vdsldr.exe -EmbeddingC:\Windows\System32\vdsldr.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Virtual Disk Service Loader
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vdsldr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5872"C:\Users\admin\AppData\Local\Temp\FiveM (1).exe" C:\Users\admin\AppData\Local\Temp\FiveM (1).exe
explorer.exe
User:
admin
Company:
Cfx.re
Integrity Level:
MEDIUM
Description:
FiveM
Exit code:
0
Version:
2.0.0.8830
Modules
Images
c:\users\admin\appdata\local\temp\fivem (1).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6060CitizenFX.exe.new -bootstrap "C:\Users\admin\AppData\Local\Temp\FiveM (1).exe"C:\Users\admin\AppData\Local\Temp\CitizenFX.exe.new
FiveM (1).exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\citizenfx.exe.new
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
46 338
Read events
45 988
Write events
319
Delete events
31

Modification events

(PID) Process:(5872) FiveM (1).exeKey:HKEY_CURRENT_USER\SOFTWARE\CitizenFX\FiveM
Operation:writeName:Last Run Location
Value:
C:\Users\admin\AppData\Local\Temp\
(PID) Process:(6060) CitizenFX.exe.newKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6060) CitizenFX.exe.newKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6060) CitizenFX.exe.newKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6060) CitizenFX.exe.newKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(4220) FiveM (1).exeKey:HKEY_CURRENT_USER\SOFTWARE\CitizenFX\FiveM
Operation:writeName:Last Run Location
Value:
C:\Users\admin\AppData\Local\Temp\
(PID) Process:(1824) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\CitizenFX\FiveM
Operation:writeName:Last Run Location
Value:
C:\Users\admin\AppData\Local\FiveM\FiveM.app\
(PID) Process:(1824) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:DisplayName
Value:
FiveM
(PID) Process:(1824) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\FiveM\FiveM.exe,0
(PID) Process:(1824) FiveM.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CitizenFX_FiveM
Operation:writeName:HelpLink
Value:
https://cfx.re/
Executable files
158
Suspicious files
41
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
5872FiveM (1).exeC:\Users\admin\AppData\Local\Temp\CitizenFX.exe.newexecutable
MD5:EF65EFBC444E7B9F4088981E696F18A5
SHA256:E146CFCAB4F65054859C4124E2CF6EB8F61FECFF92B5E9D6428B1A3EF686F133
5872FiveM (1).exeC:\Users\admin\AppData\Local\Temp\CitizenFX.exe.new.tmpexecutable
MD5:EF65EFBC444E7B9F4088981E696F18A5
SHA256:E146CFCAB4F65054859C4124E2CF6EB8F61FECFF92B5E9D6428B1A3EF686F133
6060CitizenFX.exe.newC:\Users\admin\AppData\Local\Temp\FiveM (1).exeexecutable
MD5:EF65EFBC444E7B9F4088981E696F18A5
SHA256:E146CFCAB4F65054859C4124E2CF6EB8F61FECFF92B5E9D6428B1A3EF686F133
4220FiveM (1).exeC:\Users\admin\AppData\Local\FiveM\FiveM.exeexecutable
MD5:EF65EFBC444E7B9F4088981E696F18A5
SHA256:E146CFCAB4F65054859C4124E2CF6EB8F61FECFF92B5E9D6428B1A3EF686F133
6060CitizenFX.exe.newC:\Users\admin\AppData\Local\Temp\FiveM (1).exe.oldexecutable
MD5:C397F272B00FF8221678E28CDF0F7E3A
SHA256:2A17EECCA2D73F4F148C81938F18463887561703CEA09565EBF85DC39E5B2C65
4220FiveM (1).exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FiveM.lnklnk
MD5:7810B01ED72F012F7A37D0E26D6BE656
SHA256:EFC449DEB9CE8E7A8DE4A923059142861DC761AB79E8A5E10EF3DE1E25811E78
1824FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.VisualElementsManifest.xmltext
MD5:B8180561E3C94A6371383B4541FFFFD0
SHA256:0B6FCF104FDF32515ADFFBF1633E0DF97F1C674884178848BACF981D9311D81F
1824FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM - Cfx.re Development Kit (FxDK).lnklnk
MD5:EDF61639177D728C6B53402E5D8A5DDB
SHA256:2D61EE407380D8C4C46DEC30698A8930A2B67BC81EA94FA8744071E02BE915EE
4220FiveM (1).exeC:\Users\admin\Desktop\FiveM.lnklnk
MD5:0C93D0AB1FB8D672502C0035F95E92B2
SHA256:C2B2FF71681EDC0FE920AA552699BD7E0543D32BE55E8CEEB63521CE1557A185
1824FiveM.exeC:\Users\admin\AppData\Local\FiveM\FiveM.app\CitizenFX_SubProcess_chrome.bin.tmpexecutable
MD5:D24DE909700775C27A0886E37A90D8BA
SHA256:85D2F3C53F4165BA2FC4DA291234B80E1894C31B9B0C2C9871C2E7937D277FB1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
55
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3676
svchost.exe
GET
200
2.16.164.72:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
3676
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
2568
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
4656
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
unknown
1644
WINWORD.EXE
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4032
svchost.exe
239.255.255.250:1900
whitelisted
188
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1972
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5872
FiveM (1).exe
172.64.153.85:443
content.cfx.re
CLOUDFLARENET
US
unknown
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4220
FiveM (1).exe
172.64.153.85:443
content.cfx.re
CLOUDFLARENET
US
unknown
1824
FiveM.exe
172.64.153.85:443
content.cfx.re
CLOUDFLARENET
US
unknown
3676
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4656
SearchApp.exe
104.126.37.178:443
www.bing.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
content.cfx.re
  • 172.64.153.85
  • 104.18.34.171
unknown
www.bing.com
  • 104.126.37.178
  • 104.126.37.131
  • 104.126.37.163
  • 2.23.209.130
  • 2.23.209.182
  • 2.23.209.187
  • 2.23.209.133
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.16.164.72
  • 2.16.164.120
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
officeclient.microsoft.com
  • 52.109.32.97
whitelisted
ecs.office.com
  • 52.113.194.132
whitelisted
omex.cdn.office.net
  • 2.19.126.151
  • 2.19.126.160
whitelisted
login.live.com
  • 40.126.32.72
  • 40.126.32.134
  • 40.126.32.136
  • 40.126.32.133
  • 40.126.32.138
  • 40.126.32.76
  • 20.190.160.22
  • 20.190.160.14
whitelisted

Threats

No threats detected
Process
Message
WINWORD.EXE
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
WINWORD.EXE
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
WINWORD.EXE
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.