File name:

PWA Identity Proxy

Full analysis: https://app.any.run/tasks/032ccecb-570b-45f6-bb47-daa32206bb9e
Verdict: Malicious activity
Analysis date: March 14, 2025, 11:02:04
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

95DC6CFB19D7C6F21795410F665F201A

SHA1:

1C3AF362771535C44D38BCF85FE7457747CE4A8A

SHA256:

40183652B178BBB018185D714C0D023D81CE1943183EB7F563AD58FC2925CD88

SSDEEP:

3072:8v6NICQA9LI9sNAcuLRhRE6zL9QxIRHOnskAi8uLYqXGP/3Hg04hAlPzevkaif2c:8CTpY+pKK6v9Q5skAi8uLA3BpJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • down.exe (PID: 8136)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • PWA Identity Proxy.exe (PID: 7268)
    • Executable content was dropped or overwritten

      • PWA Identity Proxy.exe (PID: 7268)
    • Starts a Microsoft application from unusual location

      • PWA Identity Proxy.exe (PID: 7268)
    • Reads security settings of Internet Explorer

      • PWA Identity Proxy.exe (PID: 7268)
      • down.exe (PID: 8136)
    • Connects to unusual port

      • down.exe (PID: 8136)
  • INFO

    • Reads the computer name

      • PWA Identity Proxy.exe (PID: 7268)
      • down.exe (PID: 8136)
    • Disables trace logs

      • PWA Identity Proxy.exe (PID: 7268)
    • Reads the machine GUID from the registry

      • PWA Identity Proxy.exe (PID: 7268)
      • down.exe (PID: 8136)
    • Checks proxy server information

      • PWA Identity Proxy.exe (PID: 7268)
      • BackgroundTransferHost.exe (PID: 6516)
    • Reads the software policy settings

      • PWA Identity Proxy.exe (PID: 7268)
      • BackgroundTransferHost.exe (PID: 6516)
      • down.exe (PID: 8136)
      • slui.exe (PID: 7488)
    • Checks supported languages

      • PWA Identity Proxy.exe (PID: 7268)
      • down.exe (PID: 8136)
    • Process checks computer location settings

      • PWA Identity Proxy.exe (PID: 7268)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 6516)
      • BackgroundTransferHost.exe (PID: 6576)
      • BackgroundTransferHost.exe (PID: 7660)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 6516)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:02:14 16:55:01+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 12800
InitializedDataSize: 2048
UninitializedDataSize: -
EntryPoint: 0x31af4
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 133.0.3065.69
ProductVersionNumber: 133.0.3065.69
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
FileVersion: 133.0.3065.69
ProductVersion: 133.0.3065.69
FileDescription: PwaHelper executable for Identity Proxy
CompanyName: Microsoft Corporation
OriginalFileName: PWA Identity Proxy
ProductName: Microsoft Edge
LegalCopyright: Copyright Microsoft Corporation. All rights reserved.
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
10
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start pwa identity proxy.exe sppextcomobj.exe no specs slui.exe down.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1812C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5588"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
6516"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
6576"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
7268"C:\Users\admin\AppData\Local\Temp\PWA Identity Proxy.exe" C:\Users\admin\AppData\Local\Temp\PWA Identity Proxy.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PwaHelper executable for Identity Proxy
Exit code:
0
Version:
133.0.3065.69
Modules
Images
c:\users\admin\appdata\local\temp\pwa identity proxy.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
7456C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7488"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7660"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
8064"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
8136"C:\Users\admin\e6ab4454-fe89-47bf-a5bc-ff25b59f6ba3@27\down.exe" C:\Users\admin\e6ab4454-fe89-47bf-a5bc-ff25b59f6ba3@27\down.exe
PWA Identity Proxy.exe
User:
admin
Company:
ShenZhen Thunder Networking Technologies Ltd.
Integrity Level:
MEDIUM
Description:
Xunlei Browser Process Shell
Version:
1.2.8.121
Modules
Images
c:\users\admin\e6ab4454-fe89-47bf-a5bc-ff25b59f6ba3@27\down.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
Total events
3 764
Read events
3 734
Write events
30
Delete events
0

Modification events

(PID) Process:(7268) PWA Identity Proxy.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\PWA Identity Proxy_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7268) PWA Identity Proxy.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\PWA Identity Proxy_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7268) PWA Identity Proxy.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\PWA Identity Proxy_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(7268) PWA Identity Proxy.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\PWA Identity Proxy_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(7268) PWA Identity Proxy.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\PWA Identity Proxy_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(7268) PWA Identity Proxy.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\PWA Identity Proxy_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(7268) PWA Identity Proxy.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\PWA Identity Proxy_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(7268) PWA Identity Proxy.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\PWA Identity Proxy_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7268) PWA Identity Proxy.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\PWA Identity Proxy_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7268) PWA Identity Proxy.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\PWA Identity Proxy_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
2
Suspicious files
7
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
6516BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\3fea3c2a-c092-4ce5-953a-f8e016557bf4.down_data
MD5:
SHA256:
7268PWA Identity Proxy.exeC:\Users\admin\e6ab4454-fe89-47bf-a5bc-ff25b59f6ba3@27\down.exeexecutable
MD5:93E322F54A584C5082425EADC4AB225C
SHA256:685E784070DAA010BB3D051E2BCBCE2736F1A198B18C6D738C70171F1674B385
6516BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:31B6B0A0AB7826FAB6E179D01CA4EDC7
SHA256:FC3311F12DE01AB6E5074D70A8A20838971187819403982625A4FE89FF643223
7268PWA Identity Proxy.exeC:\Users\admin\e6ab4454-fe89-47bf-a5bc-ff25b59f6ba3@27\image.jpgbinary
MD5:D0C1E586BC522B335A96B206D5E85F33
SHA256:01E001FF68F779744CBE6537FAD8E0C20876B75C3A62A702D7317432AE4BE233
6516BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:69DE54E86D360A49BF1B973E4F2FA820
SHA256:0AAF0F2348624541D386D642982CB7B683C6A5242809990849723F7E5E930C58
6516BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\3fea3c2a-c092-4ce5-953a-f8e016557bf4.f53cb685-9512-4e26-9017-88d6b3362083.down_metabinary
MD5:179A6F4068E19A25F5B4776A8E6592EB
SHA256:25AD5CA0F6207DCEF0F939DE20798605DD70A94FB9A02B9202E7940F66F88265
7268PWA Identity Proxy.exeC:\Users\admin\e6ab4454-fe89-47bf-a5bc-ff25b59f6ba3@27\xlbrowser.dllexecutable
MD5:88D44D2FFF8524190449F07D408D0FD0
SHA256:006D604BAB898FBEFDF07815BF9165F68C14F8CE365E64A91CD43A6BCDFF43A5
7268PWA Identity Proxy.exeC:\Users\admin\e6ab4454-fe89-47bf-a5bc-ff25b59f6ba3@27\log.datbinary
MD5:F1F263D4895449E15CA27EF844DE4EE9
SHA256:6AAF2C32B09F595A53E0D75D3FAD7EFDB67801A9BDE93F6255D9C8992A2DAC96
6516BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\90d7f310-ed57-4b1a-ade1-927e9428eb4f.up_meta_securebinary
MD5:73671444E8CF7ABC206F8C8EF4F1D435
SHA256:6423580FA3DCF4786FB3000D610E7952D2B13175FC8A4EACC824CECFDEDE027B
6516BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\90d7f310-ed57-4b1a-ade1-927e9428eb4f.f53cb685-9512-4e26-9017-88d6b3362083.down_metabinary
MD5:179A6F4068E19A25F5B4776A8E6592EB
SHA256:25AD5CA0F6207DCEF0F939DE20798605DD70A94FB9A02B9202E7940F66F88265
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
39
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2104
svchost.exe
GET
200
23.48.23.188:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5008
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5008
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6516
BackgroundTransferHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
7324
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
192.168.100.255:137
whitelisted
2104
svchost.exe
23.48.23.188:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
20.198.162.78:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
SG
whitelisted
6544
svchost.exe
20.190.159.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
7268
PWA Identity Proxy.exe
52.219.133.55:443
csfaga.s3.ap-southeast-1.amazonaws.com
AMAZON-02
SG
shared
6544
svchost.exe
20.190.159.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.48.23.188
  • 23.48.23.134
  • 23.48.23.169
  • 23.48.23.168
  • 23.48.23.173
  • 23.48.23.180
  • 23.48.23.166
  • 23.48.23.191
  • 23.48.23.192
whitelisted
google.com
  • 142.250.185.238
whitelisted
client.wns.windows.com
  • 20.198.162.78
whitelisted
login.live.com
  • 20.190.159.73
  • 40.126.31.2
  • 40.126.31.1
  • 20.190.159.129
  • 40.126.31.71
  • 20.190.159.64
  • 20.190.159.131
  • 20.190.159.130
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
csfaga.s3.ap-southeast-1.amazonaws.com
  • 52.219.133.55
  • 3.5.146.7
  • 3.5.151.177
  • 3.5.148.100
  • 52.219.132.59
  • 3.5.148.109
  • 52.219.125.51
  • 3.5.149.122
shared
arc.msn.com
  • 20.103.156.88
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
www.microsoft.com
  • 23.219.150.101
whitelisted

Threats

No threats detected
No debug info