File name:

UltraVNC_1_3_81_X64_Setup.exe

Full analysis: https://app.any.run/tasks/3411370a-a44d-4f96-93bc-41eaa2eca916
Verdict: Malicious activity
Analysis date: November 28, 2024, 12:17:59
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections
MD5:

8531AEEE8C139076E61E8F12C2BEFFC3

SHA1:

B528580543539832734F35B483CBF0E7349D2CF3

SHA256:

3FCEA8139A906FDEBA697337584E5A942969962FB8BB94EAED5137B9911834EE

SSDEEP:

98304:X+QqZ8fL4XrewpzSM/T74C8JK1RdEdYUWsowjE4tBSr7x/chkC3RmqZ2K5KRYSZD:QXXX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Starts NET.EXE for service management

      • UltraVNC_1_3_81_X64_Setup.tmp (PID: 6432)
      • winvnc.exe (PID: 6736)
      • net.exe (PID: 6756)
      • net.exe (PID: 6532)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • UltraVNC_1_3_81_X64_Setup.tmp (PID: 5092)
    • Executable content was dropped or overwritten

      • UltraVNC_1_3_81_X64_Setup.exe (PID: 4876)
      • UltraVNC_1_3_81_X64_Setup.exe (PID: 6408)
      • UltraVNC_1_3_81_X64_Setup.tmp (PID: 6432)
      • winvnc.exe (PID: 4932)
      • drvinst.exe (PID: 2212)
    • Executes as Windows Service

      • winvnc.exe (PID: 3220)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • UltraVNC_1_3_81_X64_Setup.tmp (PID: 6432)
    • Application launched itself

      • winvnc.exe (PID: 3220)
  • INFO

    • Checks supported languages

      • UltraVNC_1_3_81_X64_Setup.exe (PID: 4876)
      • UltraVNC_1_3_81_X64_Setup.exe (PID: 6408)
      • UltraVNC_1_3_81_X64_Setup.tmp (PID: 5092)
      • UltraVNC_1_3_81_X64_Setup.tmp (PID: 6432)
    • Create files in a temporary directory

      • UltraVNC_1_3_81_X64_Setup.exe (PID: 4876)
    • Reads the computer name

      • UltraVNC_1_3_81_X64_Setup.tmp (PID: 5092)
      • UltraVNC_1_3_81_X64_Setup.tmp (PID: 6432)
    • Process checks computer location settings

      • UltraVNC_1_3_81_X64_Setup.tmp (PID: 5092)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (53.5)
.exe | InstallShield setup (21)
.exe | Win32 EXE PECompact compressed (generic) (20.2)
.exe | Win32 Executable (generic) (2.1)
.exe | Win16/32 Executable Delphi generic (1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:06:03 08:09:11+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741376
InitializedDataSize: 330752
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.3.8.1
ProductVersionNumber: 1.3.8.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: uvnc bvba
FileDescription: UltraVNC Setup
FileVersion: 1.3.8.1
LegalCopyright: UltraVnc Team
OriginalFileName:
ProductName: UltraVnc
ProductVersion: 1.3.8.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
158
Monitored processes
32
Malicious processes
1
Suspicious processes
3

Behavior graph

Click at the process to see the details
start ultravnc_1_3_81_x64_setup.exe ultravnc_1_3_81_x64_setup.tmp no specs ultravnc_1_3_81_x64_setup.exe ultravnc_1_3_81_x64_setup.tmp certutil.exe no specs conhost.exe no specs winvnc.exe conhost.exe no specs drvinst.exe certutil.exe no specs conhost.exe no specs setpasswd.exe no specs conhost.exe no specs setcad.exe no specs conhost.exe no specs winvnc.exe no specs net.exe no specs conhost.exe no specs net.exe no specs conhost.exe no specs net1.exe no specs net1.exe no specs winvnc.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs winvnc.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1512\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenetsh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1620\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenetsh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1744\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesetpasswd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2076\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenetsh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2212DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{2e19cf8d-4226-ef4a-bd75-e1041bf6e128}\UVncVirtualDisplay.inf" "9" "4b054afff" "00000000000001E0" "WinSta0\Default" "00000000000001F0" "208" "C:\Program Files\uvnc bvba\UltraVNC\UVncVirtualDisplay64"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
2612\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execertutil.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2996"C:\WINDOWS\SysWOW64\netsh" firewall add portopening TCP 5900 vnc5900C:\Windows\SysWOW64\netsh.exeUltraVNC_1_3_81_X64_Setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
3220"C:\Program Files\uvnc bvba\UltraVNC\WinVNC.exe" -serviceC:\Program Files\uvnc bvba\UltraVNC\winvnc.exeservices.exe
User:
SYSTEM
Company:
UltraVNC
Integrity Level:
SYSTEM
Description:
VNC server
Version:
1.3.8.1
Modules
Images
c:\program files\uvnc bvba\ultravnc\winvnc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
3620"certutil.exe" -delstore trustedpublisher 01302f6c9f56b5a7b00d148510a5a59eC:\Windows\System32\certutil.exeUltraVNC_1_3_81_X64_Setup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
CertUtil.exe
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\certutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4468"C:\Program Files\uvnc bvba\UltraVNC\setcad.exe"C:\Program Files\uvnc bvba\UltraVNC\setcad.exeUltraVNC_1_3_81_X64_Setup.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\uvnc bvba\ultravnc\setcad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
6 405
Read events
6 365
Write events
36
Delete events
4

Modification events

(PID) Process:(6348) certutil.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.60.3.1!7
Operation:writeName:Name
Value:
szOID_ROOT_PROGRAM_AUTO_UPDATE_CA_REVOCATION
(PID) Process:(6348) certutil.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.60.3.2!7
Operation:writeName:Name
Value:
szOID_ROOT_PROGRAM_AUTO_UPDATE_END_REVOCATION
(PID) Process:(6348) certutil.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.60.3.3!7
Operation:writeName:Name
Value:
szOID_ROOT_PROGRAM_NO_OCSP_FAILOVER_TO_CRL
(PID) Process:(6432) UltraVNC_1_3_81_X64_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ultravnc2_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.0
(PID) Process:(6432) UltraVNC_1_3_81_X64_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ultravnc2_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\uvnc bvba\UltraVNC
(PID) Process:(6432) UltraVNC_1_3_81_X64_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ultravnc2_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\uvnc bvba\UltraVNC\
(PID) Process:(6432) UltraVNC_1_3_81_X64_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ultravnc2_is1
Operation:writeName:Inno Setup: Icon Group
Value:
UltraVNC
(PID) Process:(6432) UltraVNC_1_3_81_X64_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ultravnc2_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(6432) UltraVNC_1_3_81_X64_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ultravnc2_is1
Operation:writeName:Inno Setup: Setup Type
Value:
full
(PID) Process:(6432) UltraVNC_1_3_81_X64_Setup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ultravnc2_is1
Operation:writeName:Inno Setup: Selected Components
Value:
ultravnc_server,ultravnc_viewer,ultravnc_repeater
Executable files
55
Suspicious files
25
Text files
11
Unknown types
3

Dropped files

PID
Process
Filename
Type
4876UltraVNC_1_3_81_X64_Setup.exeC:\Users\admin\AppData\Local\Temp\is-CGE93.tmp\UltraVNC_1_3_81_X64_Setup.tmpexecutable
MD5:1A637FAF14F98EDD45CF383A8E6173F7
SHA256:919C049F40BA361B7B28EA3B5BDD8B837D2F89F844B054ABCF9952ACC4484BCF
6432UltraVNC_1_3_81_X64_Setup.tmpC:\Users\admin\AppData\Local\Temp\is-S1HOO.tmp\isdonate.bmpimage
MD5:6239A3BF88132514BF3D879352639195
SHA256:C925160C8686390A4420FF9C35DED0654E2B7D4B432B0BF18290B843FC2E5B12
6432UltraVNC_1_3_81_X64_Setup.tmpC:\Program Files\uvnc bvba\UltraVNC\is-0DGLA.tmptext
MD5:B57928B65E9D3A9BC3E58AD2A14AAAB9
SHA256:2328C5DF5462899FA0BE7A7FD4DFC5B0261FE0AB07520D6BF3C520B48F7D222B
6432UltraVNC_1_3_81_X64_Setup.tmpC:\Program Files\uvnc bvba\UltraVNC\Whatsnew.rtftext
MD5:B57928B65E9D3A9BC3E58AD2A14AAAB9
SHA256:2328C5DF5462899FA0BE7A7FD4DFC5B0261FE0AB07520D6BF3C520B48F7D222B
6432UltraVNC_1_3_81_X64_Setup.tmpC:\Program Files\uvnc bvba\UltraVNC\Licence.rtftext
MD5:C464BC7DB69665DE38C6D0722476E72E
SHA256:DC0A3DF8A989A552B13FBF914C7E55BECEAC9E80ED5E4D5C483EA20BDDC02CA8
6432UltraVNC_1_3_81_X64_Setup.tmpC:\Program Files\uvnc bvba\UltraVNC\is-2QGO2.tmpbinary
MD5:8D739886740F8B4042B62E6F52D99FBC
SHA256:EDB06C7AAFAD3567266849F78B86D97258E7E9A792F06B74AEFF095F10732C29
6408UltraVNC_1_3_81_X64_Setup.exeC:\Users\admin\AppData\Local\Temp\is-8ROR6.tmp\UltraVNC_1_3_81_X64_Setup.tmpexecutable
MD5:1A637FAF14F98EDD45CF383A8E6173F7
SHA256:919C049F40BA361B7B28EA3B5BDD8B837D2F89F844B054ABCF9952ACC4484BCF
6432UltraVNC_1_3_81_X64_Setup.tmpC:\Users\admin\AppData\Local\Temp\is-S1HOO.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
6432UltraVNC_1_3_81_X64_Setup.tmpC:\Users\admin\AppData\Local\Temp\is-S1HOO.tmp\isskin.dllexecutable
MD5:92C2E247392E0E02261DEA67E1BB1A5E
SHA256:25FDB94E386F8A41F10ABA00ED092A91B878339F8E256A7252B11169122B0A68
6432UltraVNC_1_3_81_X64_Setup.tmpC:\Program Files\uvnc bvba\UltraVNC\is-3KCRV.tmpexecutable
MD5:1A637FAF14F98EDD45CF383A8E6173F7
SHA256:919C049F40BA361B7B28EA3B5BDD8B837D2F89F844B054ABCF9952ACC4484BCF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
31
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
973 b
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.107:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
1.01 Kb
whitelisted
7028
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
408 b
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
314 b
whitelisted
848
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
whitelisted
7028
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
418 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
444
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.107:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
20.190.160.22:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5064
SearchApp.exe
2.23.209.175:443
www.bing.com
Akamai International B.V.
GB
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 2.16.164.107
  • 2.16.164.17
  • 2.16.164.106
  • 2.16.164.9
  • 2.16.164.24
  • 2.16.164.89
  • 2.16.164.114
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
google.com
  • 142.250.184.206
whitelisted
login.live.com
  • 20.190.160.22
  • 40.126.32.138
  • 20.190.160.17
  • 20.190.160.20
  • 40.126.32.72
  • 40.126.32.133
  • 40.126.32.68
  • 40.126.32.134
whitelisted
www.bing.com
  • 2.23.209.175
  • 2.23.209.177
  • 2.23.209.178
  • 2.23.209.189
  • 2.23.209.188
  • 2.23.209.181
  • 2.23.209.183
  • 2.23.209.176
  • 2.23.209.185
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 23.32.186.57
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted

Threats

No threats detected
No debug info