File name:

Albertino.RAT.v2.2+SourceCode.rar

Full analysis: https://app.any.run/tasks/350bdb6c-1a74-40e8-a601-6e31e5f78213
Verdict: Malicious activity
Analysis date: May 23, 2025, 20:09:18
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
netreactor
delphi
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

436CDC8725DC9B5D266F5EF040C6AC69

SHA1:

1F24D0D635AB86E6B454CB8672A65FAC0ECE5A4B

SHA256:

3B1BFD34BB7EAF814E0D980D69FE26A95503D1BC443B3401849D86AC29B27C33

SSDEEP:

98304:C7IxuYSuVF4H8rXavTdBJElDN9/LksJU2L/+9nixIwwh/tUTJqGCem9fLwDS+Xz/:47rUC3bMG1oQ46q3X

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • STM.exe (PID: 6388)
    • Create files in the Startup directory

      • STM.exe (PID: 6388)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • WinRAR.exe (PID: 7364)
      • wetwegter.exe (PID: 7752)
    • Detected use of alternative data streams (AltDS)

      • ARC.exe (PID: 7228)
    • The process creates files with name similar to system file names

      • WinRAR.exe (PID: 7364)
    • There is functionality for taking screenshot (YARA)

      • ARC.exe (PID: 7228)
    • Reads security settings of Internet Explorer

      • ARC.exe (PID: 7228)
      • wetwegter.exe (PID: 7752)
    • Creates file in the systems drive root

      • ARC.exe (PID: 7228)
      • explorer.exe (PID: 7484)
    • Starts a Microsoft application from unusual location

      • KL.exe (PID: 6468)
      • winupdate.exe (PID: 7808)
    • Executable content was dropped or overwritten

      • ARC.exe (PID: 7228)
      • STM.exe (PID: 6388)
      • wetwegter.exe (PID: 7752)
    • Likely accesses (executes) a file from the Public directory

      • winupdate.exe (PID: 7808)
  • INFO

    • Reads the machine GUID from the registry

      • ARC.exe (PID: 7228)
      • KL.exe (PID: 6468)
      • STM.exe (PID: 6388)
      • wetwegter.exe (PID: 7752)
      • winupdate.exe (PID: 7808)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 7364)
    • Manual execution by a user

      • ARC.exe (PID: 7228)
      • KL.exe (PID: 6468)
      • STM.exe (PID: 6388)
    • Reads the computer name

      • ARC.exe (PID: 7228)
      • KL.exe (PID: 6468)
      • STM.exe (PID: 6388)
      • wetwegter.exe (PID: 7752)
      • winupdate.exe (PID: 7808)
    • Checks supported languages

      • ARC.exe (PID: 7228)
      • KL.exe (PID: 6468)
      • STM.exe (PID: 6388)
      • wetwegter.exe (PID: 7752)
      • winupdate.exe (PID: 7808)
    • .NET Reactor protector has been detected

      • ARC.exe (PID: 7228)
      • wetwegter.exe (PID: 7752)
    • Compiled with Borland Delphi (YARA)

      • ARC.exe (PID: 7228)
    • Reads the software policy settings

      • slui.exe (PID: 7520)
      • slui.exe (PID: 6184)
    • Reads Environment values

      • KL.exe (PID: 6468)
      • winupdate.exe (PID: 7808)
    • Creates files or folders in the user directory

      • STM.exe (PID: 6388)
    • Checks proxy server information

      • slui.exe (PID: 6184)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 7484)
    • Process checks computer location settings

      • ARC.exe (PID: 7228)
      • wetwegter.exe (PID: 7752)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
145
Monitored processes
12
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe rundll32.exe no specs arc.exe slui.exe kl.exe no specs stm.exe explorer.exe no specs explorer.exe no specs wetwegter.exe winupdate.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3156"C:\Windows\System32\explorer.exe" C:\Users\admin\Desktop\Albertino.RAT.v2.2+SourceCode\Albertino RAT v2.2\AARCC:\Windows\SysWOW64\explorer.exeARC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
1
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcp_win.dll
6184C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6388"C:\Users\admin\Desktop\Albertino.RAT.v2.2+SourceCode\Albertino RAT v2.2\AARC\STM.exe" C:\Users\admin\Desktop\Albertino.RAT.v2.2+SourceCode\Albertino RAT v2.2\AARC\STM.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Microsoft Library Component
Exit code:
0
Version:
2.2
Modules
Images
c:\users\admin\desktop\albertino.rat.v2.2+sourcecode\albertino rat v2.2\aarc\stm.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
6468"C:\Users\admin\Desktop\Albertino.RAT.v2.2+SourceCode\Albertino RAT v2.2\AARC\KL.exe" C:\Users\admin\Desktop\Albertino.RAT.v2.2+SourceCode\Albertino RAT v2.2\AARC\KL.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Help Engine application file
Version:
3.10.0.2555
Modules
Images
c:\users\admin\desktop\albertino.rat.v2.2+sourcecode\albertino rat v2.2\aarc\kl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
7228"C:\Users\admin\Desktop\Albertino.RAT.v2.2+SourceCode\Albertino RAT v2.2\AARC\ARC.exe" C:\Users\admin\Desktop\Albertino.RAT.v2.2+SourceCode\Albertino RAT v2.2\AARC\ARC.exe
explorer.exe
User:
admin
Company:
Albertino LTD. and GeoGenSoft LTD.
Integrity Level:
HIGH
Description:
Albertino Advanced RAT Creator
Version:
2.2.1.0
Modules
Images
c:\users\admin\desktop\albertino.rat.v2.2+sourcecode\albertino rat v2.2\aarc\arc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
7364"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\Albertino.RAT.v2.2+SourceCode.rarC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
7484C:\WINDOWS\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shcore.dll
7488C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7520"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7752"C:\Users\admin\Desktop\Albertino.RAT.v2.2+SourceCode\Albertino RAT v2.2\AARC\wetwegter.exe" C:\Users\admin\Desktop\Albertino.RAT.v2.2+SourceCode\Albertino RAT v2.2\AARC\wetwegter.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Microsoft Library Component
Version:
2.2
Modules
Images
c:\users\admin\desktop\albertino.rat.v2.2+sourcecode\albertino rat v2.2\aarc\wetwegter.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
Total events
15 908
Read events
15 804
Write events
96
Delete events
8

Modification events

(PID) Process:(7364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(7364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(7364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(7364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(7364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Albertino.RAT.v2.2+SourceCode.rar
(PID) Process:(7364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7364) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7228) ARC.exeKey:HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{45006200-5000-6900-5000-580064007200}
Operation:writeName:1
Value:
6ZoABO4TfMHgfve8hXGYyzGETCjNmdWkZiOxYpMSbnEn+dD67UmDTqI26JmX0APuvxilQmIuy9BbEA9q9ud1Pp8+bFo1fC7xXOMTgmziFBgi0XZuOngQvVBj4gAqRM6R
Executable files
47
Suspicious files
67
Text files
228
Unknown types
0

Dropped files

PID
Process
Filename
Type
7364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb7364.28519\Albertino.RAT.v2.2+SourceCode\AARC\KL.exeexecutable
MD5:F3244B7FF4F0D02C71622E38B459711B
SHA256:298B911716E8E00DB371D0BA90A51B1E887AB4EDAFE2E998D73964CE1F85ACE6
7364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb7364.28519\Albertino.RAT.v2.2+SourceCode\Albertino RAT v2.2\AARC\Readme.txttext
MD5:82C11DFD921BD3B267BF3C7BDA24A63B
SHA256:B583F3D5600C52549BF34A74672D170B14DF76C3479E80121CAA40F1FE126798
7364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb7364.28519\Albertino.RAT.v2.2+SourceCode\AARC\AARCnew.licensebinary
MD5:0EB9228D58C6D7341A16065ED6BA747D
SHA256:CE352C93BDE442C164EBF7D5694364415F29BD5A0127C825B9ED72178DBEB082
7364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb7364.28519\Albertino.RAT.v2.2+SourceCode\AARC\Readme.txttext
MD5:F343A1724869DD03D8A1C037F3792A1F
SHA256:5DADA3D5A006E8B2D1F37FA1AD9BD76324E37E7DAFE19DB2E954C7467C6AECCC
7364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb7364.28519\Albertino.RAT.v2.2+SourceCode\Albertino RAT v2.2\AARC\KL.exeexecutable
MD5:F3244B7FF4F0D02C71622E38B459711B
SHA256:298B911716E8E00DB371D0BA90A51B1E887AB4EDAFE2E998D73964CE1F85ACE6
7364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb7364.28519\Albertino.RAT.v2.2+SourceCode\Albertino RAT v2.2\AARC\ARC.exeexecutable
MD5:A80D8CA8EE61763A40EEE782930AA6EC
SHA256:F02FAF2B5816DB6BD67FDBE432B87AD6C9E2D79A7251E81A0C9ACD3D8DD28BBA
7364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb7364.28519\Albertino.RAT.v2.2+SourceCode\Albertino RAT v2.2\Source\Albertino RAT Source VB.NET\AKC Advanced\bin\Debug\winupdate.exeexecutable
MD5:0EDCFB4A64AC055C3959DF7BA6BD2DBA
SHA256:05CD2E1560111ADDD338FAAB64138B642F8EC40F344FE62F32F2CB762C94BCC3
7364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb7364.28519\Albertino.RAT.v2.2+SourceCode\Albertino RAT v2.2\AARC\STM.exeexecutable
MD5:968864DE5CCE875A623D39D4B0CC86A1
SHA256:E18997DA91A7BFCB5F6C35A843E35C3CF727DDD8B1DEC167C9DFF8AF5F700F67
7364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb7364.28519\Albertino.RAT.v2.2+SourceCode\Albertino RAT v2.2\Source\Albertino RAT Source VB.NET\AKC Advanced\AKC Advanced.vbproj.usertext
MD5:7FBFF98B64D947ECB8664144197FCC02
SHA256:81B92620A7E96099D2DA4ACA1CF952568F9010583F8832B3CAA58BABDC304B9A
7364WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb7364.28519\Albertino.RAT.v2.2+SourceCode\Albertino RAT v2.2\Source\Albertino RAT Source VB.NET\AKC Advanced\AKC Advanced.vbprojxml
MD5:E4B5FEA3A9C376FA319C5F1464FE15F5
SHA256:39592AD0091D9416DE382B001E76AA1DD7B66C80B387320F697EDF20222EA267
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
24
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.32.238.34:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8152
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
8152
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
23.32.238.34:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2.16.253.202:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5496
MoUsoCoreWorker.exe
2.16.253.202:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.32.134:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.32.238.34
  • 2.19.198.194
whitelisted
google.com
  • 142.250.186.174
whitelisted
www.microsoft.com
  • 2.16.253.202
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 40.126.32.134
  • 40.126.32.138
  • 20.190.160.128
  • 20.190.160.67
  • 20.190.160.2
  • 20.190.160.5
  • 20.190.160.65
  • 20.190.160.64
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
  • 20.83.72.98
whitelisted

Threats

No threats detected
No debug info