URL:

https://www.strokesplus.com/files/strokesplussetup_2.8.6.4_x64_signed.exe

Full analysis: https://app.any.run/tasks/8e1173a4-99ab-4b08-8494-cb65ce7ea5ac
Verdict: Malicious activity
Analysis date: August 21, 2018, 12:11:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

0C933DCF24760D072AA6808621E7F540

SHA1:

1F7EEA56C7E179DAE5DE774B4191A26965143A9B

SHA256:

42DB14AE1B7B4FB47C214C2DDD5228F44B942B793B7F7221B1917A2B39155CB3

SSDEEP:

3:N8DSLmA00K37RpV8pLcdd+J:2OLrG7RpV8udd+J

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • strokesplussetup_2.8.6.4_x64_signed[1].exe (PID: 1872)
      • strokesplussetup_2.8.6.4_x64_signed[1].exe (PID: 608)
      • strokesplussetup_2.8.6.4_x86_signed[1].exe (PID: 3496)
      • strokesplussetup_2.8.6.4_x86_signed[1].exe (PID: 3256)
      • StrokesPlus.exe (PID: 2208)
      • StrokesPlus.exe (PID: 2960)
    • Writes to a start menu file

      • strokesplussetup_2.8.6.4_x86_signed[1].tmp (PID: 3484)
    • Changes settings of System certificates

      • certutil.exe (PID: 3020)
    • Loads dropped or rewritten executable

      • StrokesPlus.exe (PID: 2208)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 2616)
      • iexplore.exe (PID: 3932)
      • strokesplussetup_2.8.6.4_x64_signed[1].exe (PID: 608)
      • strokesplussetup_2.8.6.4_x64_signed[1].exe (PID: 1872)
      • strokesplussetup_2.8.6.4_x64_signed[1].tmp (PID: 2556)
      • iexplore.exe (PID: 3952)
      • iexplore.exe (PID: 2996)
      • strokesplussetup_2.8.6.4_x86_signed[1].exe (PID: 3496)
      • strokesplussetup_2.8.6.4_x86_signed[1].exe (PID: 3256)
      • strokesplussetup_2.8.6.4_x86_signed[1].tmp (PID: 3484)
    • Creates files in the user directory

      • strokesplussetup_2.8.6.4_x86_signed[1].tmp (PID: 3484)
    • Starts CMD.EXE for commands execution

      • strokesplussetup_2.8.6.4_x86_signed[1].tmp (PID: 3484)
    • Creates files in the Windows directory

      • certutil.exe (PID: 3020)
    • Removes files from Windows directory

      • certutil.exe (PID: 3020)
  • INFO

    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3932)
      • iexplore.exe (PID: 2616)
      • iexplore.exe (PID: 2664)
      • iexplore.exe (PID: 3952)
    • Changes internet zones settings

      • iexplore.exe (PID: 2616)
      • iexplore.exe (PID: 2996)
    • Dropped object may contain URL's

      • strokesplussetup_2.8.6.4_x64_signed[1].exe (PID: 608)
      • iexplore.exe (PID: 3932)
      • iexplore.exe (PID: 2616)
      • strokesplussetup_2.8.6.4_x64_signed[1].exe (PID: 1872)
      • iexplore.exe (PID: 2996)
      • strokesplussetup_2.8.6.4_x86_signed[1].exe (PID: 3496)
      • iexplore.exe (PID: 2664)
      • strokesplussetup_2.8.6.4_x86_signed[1].tmp (PID: 3484)
      • StrokesPlus.exe (PID: 2208)
      • strokesplussetup_2.8.6.4_x86_signed[1].exe (PID: 3256)
    • Application was dropped or rewritten from another process

      • strokesplussetup_2.8.6.4_x64_signed[1].tmp (PID: 2556)
      • strokesplussetup_2.8.6.4_x64_signed[1].tmp (PID: 2632)
      • strokesplussetup_2.8.6.4_x86_signed[1].tmp (PID: 3460)
      • strokesplussetup_2.8.6.4_x86_signed[1].tmp (PID: 3484)
    • Loads dropped or rewritten executable

      • strokesplussetup_2.8.6.4_x64_signed[1].tmp (PID: 2556)
      • strokesplussetup_2.8.6.4_x86_signed[1].tmp (PID: 3484)
    • Reads internet explorer settings

      • iexplore.exe (PID: 2664)
      • iexplore.exe (PID: 3952)
      • iexplore.exe (PID: 3824)
    • Reads settings of System Certificates

      • iexplore.exe (PID: 2664)
    • Creates files in the user directory

      • iexplore.exe (PID: 2664)
      • FlashUtil32_27_0_0_187_ActiveX.exe (PID: 3984)
      • iexplore.exe (PID: 2996)
    • Changes settings of System certificates

      • iexplore.exe (PID: 2996)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 2996)
    • Application launched itself

      • iexplore.exe (PID: 2996)
    • Creates a software uninstall entry

      • strokesplussetup_2.8.6.4_x86_signed[1].tmp (PID: 3484)
    • Creates files in the program directory

      • strokesplussetup_2.8.6.4_x86_signed[1].tmp (PID: 3484)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
19
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe strokesplussetup_2.8.6.4_x64_signed[1].exe strokesplussetup_2.8.6.4_x64_signed[1].tmp no specs strokesplussetup_2.8.6.4_x64_signed[1].exe strokesplussetup_2.8.6.4_x64_signed[1].tmp iexplore.exe iexplore.exe flashutil32_27_0_0_187_activex.exe no specs iexplore.exe strokesplussetup_2.8.6.4_x86_signed[1].exe strokesplussetup_2.8.6.4_x86_signed[1].tmp no specs strokesplussetup_2.8.6.4_x86_signed[1].exe strokesplussetup_2.8.6.4_x86_signed[1].tmp cmd.exe no specs certutil.exe no specs strokesplus.exe no specs strokesplus.exe iexplore.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
608"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GUFVP8I9\strokesplussetup_2.8.6.4_x64_signed[1].exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GUFVP8I9\strokesplussetup_2.8.6.4_x64_signed[1].exe
iexplore.exe
User:
admin
Company:
Rob Larkin
Integrity Level:
MEDIUM
Description:
StrokesPlus Setup
Exit code:
1
Version:
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\gufvp8i9\strokesplussetup_2.8.6.4_x64_signed[1].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1872"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GUFVP8I9\strokesplussetup_2.8.6.4_x64_signed[1].exe" /SPAWNWND=$2001E2 /NOTIFYWND=$16021A C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GUFVP8I9\strokesplussetup_2.8.6.4_x64_signed[1].exe
strokesplussetup_2.8.6.4_x64_signed[1].tmp
User:
admin
Company:
Rob Larkin
Integrity Level:
HIGH
Description:
StrokesPlus Setup
Exit code:
1
Version:
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\gufvp8i9\strokesplussetup_2.8.6.4_x64_signed[1].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2208"C:\Program Files\StrokesPlus\StrokesPlus.exe" C:\Program Files\StrokesPlus\StrokesPlus.exe
explorer.exe
User:
admin
Company:
Rob Yapchanyk
Integrity Level:
HIGH
Description:
StrokesPlus
Exit code:
0
Version:
2.8.6.4
Modules
Images
c:\program files\strokesplus\strokesplus.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2556"C:\Users\admin\AppData\Local\Temp\is-R6N3H.tmp\strokesplussetup_2.8.6.4_x64_signed[1].tmp" /SL5="$E0246,1327664,74752,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GUFVP8I9\strokesplussetup_2.8.6.4_x64_signed[1].exe" /SPAWNWND=$2001E2 /NOTIFYWND=$16021A C:\Users\admin\AppData\Local\Temp\is-R6N3H.tmp\strokesplussetup_2.8.6.4_x64_signed[1].tmp
strokesplussetup_2.8.6.4_x64_signed[1].exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
1
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-r6n3h.tmp\strokesplussetup_2.8.6.4_x64_signed[1].tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2616"C:\Program Files\Internet Explorer\iexplore.exe" https://www.strokesplus.com/files/strokesplussetup_2.8.6.4_x64_signed.exeC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2632"C:\Users\admin\AppData\Local\Temp\is-0N94N.tmp\strokesplussetup_2.8.6.4_x64_signed[1].tmp" /SL5="$16021A,1327664,74752,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GUFVP8I9\strokesplussetup_2.8.6.4_x64_signed[1].exe" C:\Users\admin\AppData\Local\Temp\is-0N94N.tmp\strokesplussetup_2.8.6.4_x64_signed[1].tmpstrokesplussetup_2.8.6.4_x64_signed[1].exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-0n94n.tmp\strokesplussetup_2.8.6.4_x64_signed[1].tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2664"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2996 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2812"cmd.exe" /c certutil.exe -f -addstore Root "C:\Program Files\StrokesPlus\StrokesPlus.cer"C:\Windows\system32\cmd.exestrokesplussetup_2.8.6.4_x86_signed[1].tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2960"C:\Program Files\StrokesPlus\StrokesPlus.exe" C:\Program Files\StrokesPlus\StrokesPlus.exeexplorer.exe
User:
admin
Company:
Rob Yapchanyk
Integrity Level:
MEDIUM
Description:
StrokesPlus
Exit code:
3221226540
Version:
2.8.6.4
Modules
Images
c:\program files\strokesplus\strokesplus.exe
c:\systemroot\system32\ntdll.dll
2996"C:\Program Files\Internet Explorer\iexplore.exe" C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
2 935
Read events
2 648
Write events
271
Delete events
16

Modification events

(PID) Process:(2616) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2616) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2616) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2616) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(2616) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2616) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000048000000010000000000000000000000000000000000000000000000B096B68868EBD301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000D8BFD602040000000000000000000000000000000000000000000000F4BFD602040000000000000000000000000000000000000000000000D8372A0000000000FFFFFFFF000000000000000000000000010000002E00000000000000000000000000000002000000C0A801640000000000000000D84ED505AC02000005000000010000000000000000000000010000000000000000000000BF060000000000000000000000000000000000001000000088C0D60204000000000000000000000000000000000000000000000000000000C8E40C00000000000C0000000000000000000000
(PID) Process:(2616) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{6D9890F1-A53B-11E8-ACE5-5254004AAD11}
Value:
0
(PID) Process:(2616) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(2616) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
10
(PID) Process:(2616) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E2070800020015000C000C000A003D03
Executable files
13
Suspicious files
12
Text files
97
Unknown types
14

Dropped files

PID
Process
Filename
Type
2616iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HHUAAB7W\favicon[1].ico
MD5:
SHA256:
2616iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3932iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab4D55.tmp
MD5:
SHA256:
3932iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Tar4D56.tmp
MD5:
SHA256:
3932iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab4D66.tmp
MD5:
SHA256:
3932iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Tar4D67.tmp
MD5:
SHA256:
3932iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Cab4E05.tmp
MD5:
SHA256:
3932iexplore.exeC:\Users\admin\AppData\Local\Temp\Low\Tar4E06.tmp
MD5:
SHA256:
2616iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF4EC9E5AC5C14958A.TMP
MD5:
SHA256:
2616iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFB3B2AA06C4773C32.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
34
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2664
iexplore.exe
GET
303
173.248.132.35:80
http://www.strokesplus.com/
US
html
151 b
unknown
2664
iexplore.exe
GET
303
173.248.132.35:80
http://strokesplus.com/
US
html
147 b
unknown
3952
iexplore.exe
GET
303
173.248.132.35:80
http://www.strokesplus.com/files/StrokesPlus_2.8.6.4_x86.zip
US
html
184 b
unknown
3952
iexplore.exe
GET
303
173.248.132.35:80
http://www.strokesplus.com/files/StrokesPlusSetup_2.8.6.4_x86_Signed.exe
US
html
196 b
unknown
3932
iexplore.exe
GET
200
192.35.177.64:80
http://apps.identrust.com/roots/dstrootcax3.p7c
US
cat
893 b
shared
2616
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
3932
iexplore.exe
GET
200
93.184.221.240:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
52.8 Kb
whitelisted
2996
iexplore.exe
GET
200
204.79.197.229:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
2996
iexplore.exe
GET
200
204.79.197.229:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
2996
iexplore.exe
GET
200
204.79.197.229:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3932
iexplore.exe
173.248.132.35:443
www.strokesplus.com
Handy Networks, LLC
US
unknown
2616
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3932
iexplore.exe
192.35.177.64:80
apps.identrust.com
IdenTrust
US
malicious
2996
iexplore.exe
204.79.197.229:80
www.bing.com
Microsoft Corporation
US
whitelisted
2664
iexplore.exe
173.248.132.35:80
www.strokesplus.com
Handy Networks, LLC
US
unknown
3932
iexplore.exe
93.184.221.240:80
www.download.windowsupdate.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2664
iexplore.exe
173.248.132.35:443
www.strokesplus.com
Handy Networks, LLC
US
unknown
2664
iexplore.exe
172.217.168.42:443
ajax.googleapis.com
Google Inc.
US
whitelisted
2664
iexplore.exe
104.25.15.32:443
api.alternativeto.net
Cloudflare Inc
US
shared
2664
iexplore.exe
172.217.23.142:443
www.youtube.com
Google Inc.
US
whitelisted

DNS requests

Domain
IP
Reputation
www.strokesplus.com
  • 173.248.132.35
unknown
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
  • 204.79.197.229
whitelisted
apps.identrust.com
  • 192.35.177.64
shared
www.download.windowsupdate.com
  • 93.184.221.240
whitelisted
strokesplus.com
  • 173.248.132.35
unknown
ajax.googleapis.com
  • 172.217.168.42
  • 172.217.168.74
  • 216.58.215.234
  • 172.217.168.10
whitelisted
api.alternativeto.net
  • 104.25.15.32
  • 104.25.14.32
suspicious
connect.facebook.net
  • 31.13.92.14
whitelisted
www.youtube.com
  • 172.217.23.142
  • 216.58.206.14
  • 216.58.207.46
  • 216.58.207.78
  • 216.58.214.46
  • 216.58.214.78
  • 172.217.16.174
  • 216.58.208.46
  • 172.217.22.78
  • 172.217.22.110
  • 216.58.210.14
  • 216.58.205.238
  • 172.217.21.206
  • 172.217.21.238
  • 172.217.22.14
  • 172.217.18.14
whitelisted
www.paypalobjects.com
  • 2.18.233.20
whitelisted

Threats

No threats detected
No debug info