File name:

20950944987.zip

Full analysis: https://app.any.run/tasks/4e4b4c95-0450-45eb-9f4f-e0ab3dac6bbe
Verdict: Malicious activity
Analysis date: January 27, 2025, 07:57:19
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
qrcode
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

90C514B7A2F91336514E992B044F4571

SHA1:

646C2D5B671CF411EB0128C4AAA85C11EEFBCFD0

SHA256:

31D843CCAD9A3D38E4D83E8C9729E47465FD587D573B2C6636F39EF11BD9717E

SSDEEP:

98304:/cyaulaegeDMF2p5FYqwFNc+wyrcQ7Ar2of55dBiXe7pko27Ioikzxx3EodX0p2u:51Y6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • a.exe (PID: 7160)
    • Changes the autorun value in the registry

      • OriginLegacyCLI.exe (PID: 2216)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • a.exe (PID: 7160)
      • irsetup.exe (PID: 3224)
    • Reads security settings of Internet Explorer

      • a.exe (PID: 7160)
      • irsetup.exe (PID: 3224)
      • AdobeCollabSync.exe (PID: 6260)
      • AdobeCollabSync.exe (PID: 6296)
    • Creates a software uninstall entry

      • irsetup.exe (PID: 3224)
    • Application launched itself

      • AdobeCollabSync.exe (PID: 6260)
    • Checks Windows Trust Settings

      • AdobeCollabSync.exe (PID: 6296)
  • INFO

    • Manual execution by a user

      • a.exe (PID: 7160)
    • The sample compiled with english language support

      • a.exe (PID: 7160)
      • WinRAR.exe (PID: 4944)
      • irsetup.exe (PID: 3224)
    • Checks supported languages

      • a.exe (PID: 7160)
      • irsetup.exe (PID: 3224)
      • OriginLegacyCLI.exe (PID: 2216)
      • AdobeCollabSync.exe (PID: 6260)
      • AdobeCollabSync.exe (PID: 6296)
      • FullTrustNotifier.exe (PID: 6388)
    • Create files in a temporary directory

      • a.exe (PID: 7160)
      • irsetup.exe (PID: 3224)
    • Reads the computer name

      • a.exe (PID: 7160)
      • irsetup.exe (PID: 3224)
      • AdobeCollabSync.exe (PID: 6260)
      • AdobeCollabSync.exe (PID: 6296)
      • FullTrustNotifier.exe (PID: 6388)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 4944)
    • Process checks computer location settings

      • a.exe (PID: 7160)
      • irsetup.exe (PID: 3224)
    • Creates files in the program directory

      • irsetup.exe (PID: 3224)
    • Creates files or folders in the user directory

      • irsetup.exe (PID: 3224)
      • AdobeCollabSync.exe (PID: 6296)
    • Checks proxy server information

      • AdobeCollabSync.exe (PID: 6260)
      • AdobeCollabSync.exe (PID: 6296)
    • Application launched itself

      • Acrobat.exe (PID: 4320)
      • AcroCEF.exe (PID: 6444)
    • Reads the machine GUID from the registry

      • AdobeCollabSync.exe (PID: 6296)
    • Reads the software policy settings

      • AdobeCollabSync.exe (PID: 6296)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0009
ZipCompression: Deflated
ZipModifyDate: 1980:00:00 00:00:00
ZipCRC: 0x2d134076
ZipCompressedSize: 2014474
ZipUncompressedSize: 2212280
ZipFileName: 5f14648a1153e45b77cf309595e0f91fd41642b1f538cd1bdbf8e70e23e13748
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
150
Monitored processes
21
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe a.exe irsetup.exe acrobat.exe originlegacycli.exe waitfor.exe conhost.exe no specs acrobat.exe no specs adobecollabsync.exe no specs adobecollabsync.exe fulltrustnotifier.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs acrocef.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
836"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" --type=renderer /prefetch:1 "C:\programdata\session\2567_MDES0204_8_20134.pdf"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeAcrobat.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe Acrobat
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrobat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2136"C:\Windows\SysWOW64\waitfor.exe" "Event19030000000"C:\Windows\SysWOW64\waitfor.exe
OriginLegacyCLI.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
waitfor - wait/send a signal over a network
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\waitfor.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2216c:\programdata\session\OriginLegacyCLI.exeC:\ProgramData\session\OriginLegacyCLI.exe
irsetup.exe
User:
admin
Company:
Electronic Arts
Integrity Level:
MEDIUM
Description:
OriginLegacyCLI
Exit code:
0
Version:
8,1,0,1556
Modules
Images
c:\programdata\session\originlegacycli.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
3224"C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe" __IRAOFF:1747314 "__IRAFN:C:\Users\admin\Desktop\a.exe" "__IRCT:0" "__IRTSS:0" "__IRSID:S-1-5-21-1693682860-607145093-2874071422-1001"C:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe
a.exe
User:
admin
Company:
Indigo Rose Corporation
Integrity Level:
MEDIUM
Description:
Setup Application
Exit code:
0
Version:
9.1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\_ir_sf_temp_0\irsetup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4136\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exewaitfor.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4320"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\programdata\session\2567_MDES0204_8_20134.pdf"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
irsetup.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Adobe Acrobat
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrobat.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4944"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\20950944987.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5556"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=renderer --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --touch-events=enabled --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2148 --field-trial-handle=1636,i,7263749210584006948,7705149560482157897,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:1C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Exit code:
0
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6208"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=gpu-process --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --lang=en-US --gpu-preferences=UAAAAAAAAADgACAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=1576 --field-trial-handle=1636,i,7263749210584006948,7705149560482157897,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:2C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Exit code:
0
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6260"C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe" -cC:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exeAcrobat.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
MEDIUM
Description:
Acrobat Collaboration Synchronizer 23.1
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\adobecollabsync.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
21 774
Read events
21 583
Write events
173
Delete events
18

Modification events

(PID) Process:(4944) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(4944) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(4944) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(4944) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\20950944987.zip
(PID) Process:(4944) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4944) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4944) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(4944) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4944) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:15
Value:
(PID) Process:(4944) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:14
Value:
Executable files
7
Suspicious files
202
Text files
16
Unknown types
1

Dropped files

PID
Process
Filename
Type
4944WinRAR.exeC:\Users\admin\Desktop\5f14648a1153e45b77cf309595e0f91fd41642b1f538cd1bdbf8e70e23e13748executable
MD5:DFE0C87B2B2B7FC18A7BF6FF372FE6A1
SHA256:5F14648A1153E45B77CF309595E0F91FD41642B1F538CD1BDBF8E70E23E13748
3224irsetup.exeC:\ProgramData\session\lua5.1.dllexecutable
MD5:B5FC476C1BF08D5161346CC7DD4CB0BA
SHA256:12CB9B8F59C00EF40EA8F28BFC59A29F12DC28332BF44B1A5D8D6A8823365650
3224irsetup.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.datbinary
MD5:E0456345518547FEFB19DD8E172EEACF
SHA256:A0677537B272A197C49EAE86B039371FCB39877C4867CF8381F5C51E21E82D1D
3224irsetup.exeC:\ProgramData\session\Uninstall\uninstall.datbinary
MD5:D1684E03CD0A60A7A2807936C270F76E
SHA256:D839F47D4066A72D2F314872E4634AD0FF17A694F434599180234EF92AC05AF7
3224irsetup.exeC:\ProgramData\session\Uninstall\uniD9B9.tmpbinary
MD5:32BB4D11A207D7B5B3A7CA8795D99905
SHA256:111460F7124D4B001418E9AC2088BF7BCEA5A3566983D02D0CBCE9C3A210DFD0
3224irsetup.exeC:\ProgramData\session\uninstall.exeexecutable
MD5:F1309DF61E1DC5DF781B90894C2E7DAC
SHA256:69A23AA500C5350612A42EA2B0297DE3F344C7C97A47B98EA770510DE69AFFEE
7160a.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exeexecutable
MD5:F1309DF61E1DC5DF781B90894C2E7DAC
SHA256:69A23AA500C5350612A42EA2B0297DE3F344C7C97A47B98EA770510DE69AFFEE
3224irsetup.exeC:\Users\admin\AppData\Local\Temp\_ir_sf_temp_0\IRIMG2.JPGimage
MD5:AC40DED6736E08664F2D86A65C47EF60
SHA256:F35985FE1E46A767BE7DCEA35F8614E1EDD60C523442E6C2C2397D1E23DBD3EA
3224irsetup.exeC:\ProgramData\session\Uninstall\uninstall.xmlxml
MD5:96969B014E92A577E5BE33C61966448B
SHA256:D11C4AB1F8947C03B713448D8F2BBCEDC7FDD07C8321E9558E2C09B720AA847D
6296AdobeCollabSync.exeC:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\Acrobat\RFL\LocalMapping\RFLDB230-journalbinary
MD5:C696F31E3BB94B08B65D2116152D5181
SHA256:F15B9E901B42B01840899A093A669E14513F83967B6835A510C61FEBB00CA112
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
81
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7032
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7032
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6296
AdobeCollabSync.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
whitelisted
6568
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
4320
Acrobat.exe
POST
200
2.17.190.73:80
http://ocsp.digicert.com/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4712
MoUsoCoreWorker.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
640
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
40.126.32.133:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1076
svchost.exe
23.35.238.131:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
4712
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
login.live.com
  • 40.126.32.133
  • 40.126.32.136
  • 40.126.32.138
  • 20.190.160.14
  • 40.126.32.68
  • 40.126.32.134
  • 40.126.32.74
  • 40.126.32.140
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 2.17.190.73
whitelisted
fd.api.iris.microsoft.com
  • 20.31.169.57
whitelisted
www.militarytc.com
  • 193.56.255.179
unknown

Threats

No threats detected
No debug info