File name:

66666.exe

Full analysis: https://app.any.run/tasks/ec372cb5-8e53-40d0-a191-ec68cc911b06
Verdict: Malicious activity
Analysis date: April 29, 2025, 08:34:25
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

5C5D3A35F9C21B6D8E9E128C51ED2286

SHA1:

DBD6127D5FB6D1E4A3C32AC9FC86C58CCB9F19C1

SHA256:

42FD7C4E0D21D10C7C4CC13B642845ABB5ACAFFA7E963796474D6A54E101A893

SSDEEP:

6144:evUG1UEFGkJSpmfMdPfEaEmBnike+t0VDHU3d/9vp:5ZNYMdPfEaNBnifwQSx9vp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • 66666.exe (PID: 5112)
    • Starts CMD.EXE for commands execution

      • 66666.exe (PID: 5112)
    • Executing commands from a ".bat" file

      • 66666.exe (PID: 5112)
    • Uses ATTRIB.EXE to modify file attributes

      • cmd.exe (PID: 4692)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 4692)
  • INFO

    • Create files in a temporary directory

      • 66666.exe (PID: 5112)
    • Checks supported languages

      • 66666.exe (PID: 5112)
    • Reads the computer name

      • 66666.exe (PID: 5112)
    • Process checks computer location settings

      • 66666.exe (PID: 5112)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2014:08:02 23:47:05+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 45056
InitializedDataSize: 77824
UninitializedDataSize: -
EntryPoint: 0x6074
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
237
Monitored processes
106
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 66666.exe no specs cmd.exe no specs conhost.exe no specs attrib.exe no specs powerpnt.exe timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs sppextcomobj.exe no specs slui.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs powerpnt.exe no specs timeout.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
632timeout /t 1 C:\Windows\SysWOW64\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1040"C:\Program Files\Microsoft Office\Root\Office16\POWERPNT.EXE" /s "C:\Users\admin\AppData\Local\Temp\afolder\ihack.ppsx" /ou ""C:\Program Files\Microsoft Office\root\Office16\POWERPNT.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft PowerPoint
Exit code:
0
Version:
16.0.16026.20146
Modules
Images
c:\program files\microsoft office\root\office16\powerpnt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\program files\common files\microsoft shared\clicktorun\appvisvsubsystems64.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1096"C:\Program Files\Microsoft Office\Root\Office16\POWERPNT.EXE" /s "C:\Users\admin\AppData\Local\Temp\afolder\ihack.ppsx" /ou ""C:\Program Files\Microsoft Office\root\Office16\POWERPNT.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft PowerPoint
Exit code:
0
Version:
16.0.16026.20146
Modules
Images
c:\program files\microsoft office\root\office16\powerpnt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\program files\common files\microsoft shared\clicktorun\appvisvsubsystems64.dll
c:\windows\system32\rpcrt4.dll
1244timeout /t 1 C:\Windows\SysWOW64\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1244"C:\Program Files\Microsoft Office\Root\Office16\POWERPNT.EXE" /s "C:\Users\admin\AppData\Local\Temp\afolder\ihack.ppsx" /ou ""C:\Program Files\Microsoft Office\root\Office16\POWERPNT.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft PowerPoint
Exit code:
0
Version:
16.0.16026.20146
Modules
Images
c:\program files\microsoft office\root\office16\powerpnt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\program files\common files\microsoft shared\clicktorun\appvisvsubsystems64.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
1280"C:\Program Files\Microsoft Office\Root\Office16\POWERPNT.EXE" /s "C:\Users\admin\AppData\Local\Temp\afolder\ihack.ppsx" /ou ""C:\Program Files\Microsoft Office\root\Office16\POWERPNT.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft PowerPoint
Exit code:
0
Version:
16.0.16026.20146
Modules
Images
c:\program files\microsoft office\root\office16\powerpnt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1328timeout /t 1 C:\Windows\SysWOW64\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1852timeout /t 1 C:\Windows\SysWOW64\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1852"C:\Program Files\Microsoft Office\Root\Office16\POWERPNT.EXE" /s "C:\Users\admin\AppData\Local\Temp\afolder\ihack.ppsx" /ou ""C:\Program Files\Microsoft Office\root\Office16\POWERPNT.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft PowerPoint
Exit code:
0
Version:
16.0.16026.20146
Modules
Images
c:\program files\microsoft office\root\office16\powerpnt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\program files\common files\microsoft shared\clicktorun\appvisvsubsystems64.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2136timeout /t 1 C:\Windows\SysWOW64\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
60 487
Read events
58 338
Write events
1 838
Delete events
311

Modification events

(PID) Process:(4692) cmd.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsx\OpenWithProgids
Operation:writeName:PowerPoint.SlideShow.12
Value:
(PID) Process:(4692) cmd.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{01BE4CFB-129A-452B-A209-F9D40B3B84A5} {886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99} 0xFFFF
Value:
01000000000000006025F789E1B8DB01
(PID) Process:(5680) POWERPNT.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\ClientTelemetry\Sampling
Operation:writeName:3
Value:
011C08000000001000B24E9A3E01000000000000000300000000000000
(PID) Process:(5680) POWERPNT.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\CrashPersistence\POWERPNT\5680
Operation:writeName:0
Value:
0B0E109FE10497FA79A54CB70536FBBE1C5F6023004689EE97D9989CEEED016A04102400449A7D64B29D01008500A907556E6B6E6F776EC906022222CA0DC2190000C91003783634C511B02CD2120C70006F0077006500720070006E0074002E00650078006500C51620C517808004C91808323231322D44656300
(PID) Process:(5680) POWERPNT.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:it-it
Value:
2
(PID) Process:(5680) POWERPNT.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:ko-kr
Value:
2
(PID) Process:(5680) POWERPNT.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:pt-br
Value:
2
(PID) Process:(5680) POWERPNT.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\PowerPoint\Resiliency\StartupItems
Operation:writeName:h-9
Value:
682D390030160000010000000000000061104C8BE1B8DB0100000000
(PID) Process:(5680) POWERPNT.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\PowerPoint\Resiliency\StartupItems
Operation:writeName:'.9
Value:
272E3900301600000000054001000000709E558BE1B8DB01240000009FE10497FA79A54CB70536FBBE1C5F6000001000B24E9A3E000000000000000000000000
(PID) Process:(5680) POWERPNT.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common
Operation:writeName:SessionId
Value:
96ABE46EE7AA334AB4ABD644C01A8098
Executable files
17
Suspicious files
111
Text files
56
Unknown types
0

Dropped files

PID
Process
Filename
Type
511266666.exeC:\Users\admin\AppData\Local\Temp\afolder\ihack.ppsxcompressed
MD5:EBB59D48902E31CEE6472DFCBBABA3F1
SHA256:B64C671EF1A8288716B22D407EAC89E70F5573422DAB04E80407820261F1FA02
511266666.exeC:\Users\admin\AppData\Local\Temp\ytmp\t5459.battext
MD5:45337EC8AEF5EEF6E81FA219C192CA28
SHA256:4F52C73C8D0C561CF2BF3E42D4B6432BE0C7BC183F9B0510576F6CCF7577F07B
5680POWERPNT.EXEC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9binary
MD5:FB60FF789C58BC6CDCCF1F388665810F
SHA256:D0D379988D4ED6E4ACBE57E83246B62FE36DACBF96793173F626B7E31FDFB8E4
4408POWERPNT.EXEC:\Users\admin\AppData\Local\Temp\138D6BA.tmptext
MD5:CC739448CA572948B0C114AA8EA7E3F0
SHA256:386D7424F2EC0034226825189F989E6122C396B107936E489280B9919148FBBC
511266666.exeC:\Users\admin\AppData\Local\Temp\ytmp\t5508.exetext
MD5:3C52638971EAD82B5929D605C1314EE0
SHA256:5614459EC05FDF6110FA8CE54C34E859671EEFFBA2B7BB4B1AD6C2C6706855AB
4300POWERPNT.EXEC:\Users\admin\AppData\Local\Temp\0CCD246.tmptext
MD5:CC739448CA572948B0C114AA8EA7E3F0
SHA256:386D7424F2EC0034226825189F989E6122C396B107936E489280B9919148FBBC
5376POWERPNT.EXEC:\Users\admin\AppData\Local\Temp\500D330.tmptext
MD5:CC739448CA572948B0C114AA8EA7E3F0
SHA256:386D7424F2EC0034226825189F989E6122C396B107936E489280B9919148FBBC
5680POWERPNT.EXEC:\Users\admin\AppData\Local\Microsoft\Office\16.0\AddInClassifierCache\OfficeSharedEntities.bintext
MD5:CC90D669144261B198DEAD45AA266572
SHA256:89C701EEFF939A44F28921FD85365ECD87041935DCD0FE0BAF04957DA12C9899
7248POWERPNT.EXEC:\Users\admin\AppData\Local\Temp\C50DF07.tmptext
MD5:CC739448CA572948B0C114AA8EA7E3F0
SHA256:386D7424F2EC0034226825189F989E6122C396B107936E489280B9919148FBBC
5680POWERPNT.EXEC:\Users\admin\AppData\Local\Microsoft\Office\16.0\AddInClassifierCache\OfficeSharedEntitiesUpdated.bintext
MD5:7444A90E70091C5E22C0149B004D6141
SHA256:CCFE947884C7E37347FCACE86EED8099E197B4A8D1676AF6D56C7C1BCFB3B067
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
69
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
2.16.164.51:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5680
POWERPNT.EXE
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5680
POWERPNT.EXE
GET
200
23.216.77.21:80
http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl
unknown
whitelisted
5680
POWERPNT.EXE
GET
200
23.216.77.21:80
http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl
unknown
whitelisted
5680
POWERPNT.EXE
GET
200
23.216.77.21:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5680
POWERPNT.EXE
GET
200
23.216.77.21:80
http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl
unknown
whitelisted
5680
POWERPNT.EXE
GET
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
5680
POWERPNT.EXE
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
192.168.100.255:137
whitelisted
5496
MoUsoCoreWorker.exe
2.16.164.51:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
5496
MoUsoCoreWorker.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
2104
svchost.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
5680
POWERPNT.EXE
52.109.89.18:443
officeclient.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5680
POWERPNT.EXE
52.123.130.14:443
ecs.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5680
POWERPNT.EXE
2.16.168.119:443
omex.cdn.office.net
Akamai International B.V.
RU
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.78
whitelisted
crl.microsoft.com
  • 2.16.164.51
  • 2.16.164.42
  • 2.16.164.27
  • 2.16.164.99
  • 2.16.164.106
  • 2.16.164.43
  • 2.16.164.32
  • 2.16.164.9
  • 23.216.77.21
  • 23.216.77.25
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 23.35.229.160
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
officeclient.microsoft.com
  • 52.109.89.18
whitelisted
ecs.office.com
  • 52.123.130.14
  • 52.123.131.14
whitelisted
omex.cdn.office.net
  • 2.16.168.119
  • 2.16.168.101
whitelisted
roaming.officeapps.live.com
  • 52.109.76.243
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
messaging.engagement.office.com
  • 52.109.136.13
whitelisted

Threats

No threats detected
No debug info