File name:

startup.exe

Full analysis: https://app.any.run/tasks/82a73dfd-6a64-4cce-8b8a-e1dfb6271b60
Verdict: Malicious activity
Analysis date: April 29, 2025, 20:10:55
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

C20F1D9C4B9D6E5B57BCED75FA0625ED

SHA1:

EE6E9FBA2CE2A677F2653B38CA0A8CD9FFFD9DC0

SHA256:

49C50278CC879EDED20E3303D9F2A02433F9261C0D1A7CC975A58C9F2E20098A

SSDEEP:

98304:KJ70OtKMmo5PJecdpC+ZCY82yq/OjzNrE4gy0b685ggYSBgzCYryem+ROMFFef39:j7K4tU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • startup.exe (PID: 7344)
      • startup.exe (PID: 4400)
      • startup.exe (PID: 4200)
    • Reads security settings of Internet Explorer

      • setup_ui.exe (PID: 7388)
      • startup.exe (PID: 7344)
      • setup_ui.exe (PID: 6028)
      • startup.exe (PID: 4200)
    • Starts itself from another location

      • startup.exe (PID: 4400)
    • The process verifies whether the antivirus software is installed

      • startup.exe (PID: 4200)
    • Application launched itself

      • startup.exe (PID: 7344)
  • INFO

    • Checks supported languages

      • startup.exe (PID: 7344)
      • setup_ui.exe (PID: 7388)
      • startup.exe (PID: 4200)
      • setup_ui.exe (PID: 6028)
      • startup.exe (PID: 4400)
    • The sample compiled with english language support

      • startup.exe (PID: 7344)
      • startup.exe (PID: 4200)
      • startup.exe (PID: 4400)
    • Reads the computer name

      • startup.exe (PID: 7344)
      • setup_ui.exe (PID: 7388)
      • startup.exe (PID: 4400)
      • startup.exe (PID: 4200)
      • setup_ui.exe (PID: 6028)
    • Reads the machine GUID from the registry

      • startup.exe (PID: 7344)
      • setup_ui.exe (PID: 7388)
      • setup_ui.exe (PID: 6028)
      • startup.exe (PID: 4200)
    • Create files in a temporary directory

      • startup.exe (PID: 7344)
      • startup.exe (PID: 4200)
    • Reads the software policy settings

      • startup.exe (PID: 7344)
      • slui.exe (PID: 7528)
      • startup.exe (PID: 4200)
    • Checks proxy server information

      • startup.exe (PID: 7344)
      • startup.exe (PID: 4200)
    • Checks for the presence of KasperskyLab

      • startup.exe (PID: 7344)
      • startup.exe (PID: 4200)
    • Creates files in the program directory

      • startup.exe (PID: 7344)
      • startup.exe (PID: 4200)
    • Process checks whether UAC notifications are on

      • startup.exe (PID: 7344)
      • startup.exe (PID: 4200)
    • Creates files or folders in the user directory

      • startup.exe (PID: 7344)
    • Process checks computer location settings

      • startup.exe (PID: 7344)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:04:16 07:20:24+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 255488
InitializedDataSize: 4747264
UninitializedDataSize: -
EntryPoint: 0x3b10
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 21.21.7.384
ProductVersionNumber: 21.21.7.384
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Kaspersky
FileDescription: Kaspersky [21.21.7.384.0.115.0]
FileVersion: 21.21.7.384
LegalCopyright: © 2025 AO Kaspersky Lab
LegalTrademarks: Eingetragene Markenzeichen und Handelsmarken sind das Eigentum ihrer Besitzer
ProductName: Kaspersky
ProductVersion: 21.21.7.384
InternalName: Setup
OriginalFileName: Setup.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start startup.exe setup_ui.exe no specs sppextcomobj.exe no specs slui.exe startup.exe startup.exe setup_ui.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
4200"C:\WINDOWS\temp\851BAE2363520F114BDE817F87F669EE\startup.exe" /-elevated=;"C:\Users\admin\AppData\Local\Temp\startup.exe"C:\Windows\Temp\851BAE2363520F114BDE817F87F669EE\startup.exe
startup.exe
User:
admin
Company:
Kaspersky
Integrity Level:
HIGH
Description:
Kaspersky [21.21.7.384.0.115.0]
Version:
21.21.7.384
Modules
Images
c:\windows\temp\851bae2363520f114bde817f87f669ee\startup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\version.dll
4400"C:\Users\admin\AppData\Local\Temp\startup.exe" /-elevated=;"C:\Users\admin\AppData\Local\Temp\startup.exe"C:\Users\admin\AppData\Local\Temp\startup.exe
startup.exe
User:
admin
Company:
Kaspersky
Integrity Level:
HIGH
Description:
Kaspersky [21.21.7.384.0.115.0]
Version:
21.21.7.384
Modules
Images
c:\users\admin\appdata\local\temp\startup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\version.dll
6004C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6028"C:\Users\admin\AppData\Local\Temp\4E81F13363520F114BDE817F87F669EE\setup_ui.exe" -cp=objref:TUVPVwEAAAAAAAAAAAAAAMAAAAAAAABGgQIAAAAAAAACRIkPs6r4hg8v9BFpRMiCAsAAAGgQ///3bG9+cAhKlDgAIgAHAEQARQBTAEsAVABPAFAALQBKAEcATABMAEoATABEAAAABwAxADkAMgAuADEANgA4AC4AMQAwADAALgAxADUAAAAAAAkA//8AAB4A//8AABAA//8AAAoA//8AABYA//8AAB8A//8AAA4A//8AAAAA:C:\Users\admin\AppData\Local\Temp\4E81F13363520F114BDE817F87F669EE\setup_ui.exestartup.exe
User:
admin
Company:
Kaspersky
Integrity Level:
MEDIUM
Description:
Kaspersky [21.21.7.384.0.115.0]
Version:
21.21.7.384
Modules
Images
c:\users\admin\appdata\local\temp\4e81f13363520f114bde817f87f669ee\setup_ui.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\version.dll
7344"C:\Users\admin\AppData\Local\Temp\startup.exe" C:\Users\admin\AppData\Local\Temp\startup.exe
explorer.exe
User:
admin
Company:
Kaspersky
Integrity Level:
MEDIUM
Description:
Kaspersky [21.21.7.384.0.115.0]
Version:
21.21.7.384
Modules
Images
c:\users\admin\appdata\local\temp\startup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\version.dll
7388"C:\Users\admin\AppData\Local\Temp\E3FBA19163520F114BDE817F87F669EE\setup_ui.exe" -cp=objref:TUVPVwEAAAAAAAAAAAAAAMAAAAAAAABGgQIAAAAAAABbMSZeyVrXUSj5WMu/cDQiAlAAALAc//8iuesYQFznlzgAIgAHAEQARQBTAEsAVABPAFAALQBKAEcATABMAEoATABEAAAABwAxADkAMgAuADEANgA4AC4AMQAwADAALgAxADUAAAAAAAkA//8AAB4A//8AABAA//8AAAoA//8AABYA//8AAB8A//8AAA4A//8AAAAA:C:\Users\admin\AppData\Local\Temp\E3FBA19163520F114BDE817F87F669EE\setup_ui.exestartup.exe
User:
admin
Company:
Kaspersky
Integrity Level:
MEDIUM
Description:
Kaspersky [21.21.7.384.0.115.0]
Exit code:
0
Version:
21.21.7.384
Modules
Images
c:\users\admin\appdata\local\temp\e3fba19163520f114bde817f87f669ee\setup_ui.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\version.dll
7472C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7528"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
10 288
Read events
10 150
Write events
138
Delete events
0

Modification events

(PID) Process:(7344) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.115.0\volatile
Operation:writeName:cp_storedResolvedType
Value:
-1
(PID) Process:(7344) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.115.0\volatile
Operation:writeName:cp_storedResolvedProductTier
Value:
0
(PID) Process:(7344) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.115.0\volatile
Operation:writeName:cp_storedResolvedStartupScenario
Value:
(PID) Process:(7344) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.115.0\volatile
Operation:writeName:cp_storedResolvedType
Value:
7
(PID) Process:(7344) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.115.0\volatile
Operation:writeName:cp_storedResolvedProductTier
Value:
290
(PID) Process:(7344) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.115.0\volatile
Operation:writeName:PreferredUI
Value:
0
(PID) Process:(7344) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.115.0\volatile
Operation:writeName:PreferredUI
Value:
1
(PID) Process:(7344) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.115.0
Operation:writeName:TrashFiles
Value:
C:\Users\admin\AppData\Local\Temp\discovery.cfg
(PID) Process:(7344) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.115.0
Operation:writeName:TrashFiles
Value:
C:\Users\admin\AppData\Local\Temp\discovery.cfg C:\ProgramData\Kaspersky Lab Setup Files\PREMIUM21.21.7.384.0.115.0
(PID) Process:(7344) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.115.0
Operation:writeName:TrashFiles
Value:
C:\Users\admin\AppData\Local\Temp\discovery.cfg C:\ProgramData\Kaspersky Lab Setup Files\PREMIUM21.21.7.384.0.115.0 C:\ProgramData\Kaspersky Lab Setup Files
Executable files
35
Suspicious files
36
Text files
50
Unknown types
1

Dropped files

PID
Process
Filename
Type
7344startup.exeC:\Users\admin\AppData\Local\Temp\191ABF3F-2536-11F0-B4ED-18F7786F96EE\downloader_neutral.inibinary
MD5:C680AE9D92EC985BE36D2E7DA55AEBB6
SHA256:A79A176BFE77730C20D64C914775D7D9D7C7F3402ADBDD39C9F26263AD8F8C5F
7344startup.exeC:\Users\admin\AppData\Local\Temp\191ABF3F-2536-11F0-B4ED-18F7786F96EE\GuiStrings_PREMIUM.loctext
MD5:ECAA88F7FA0BF610A5A26CF545DCD3AA
SHA256:F1945CD6C19E56B3C1C78943EF5EC18116907A4CA1EFC40A57D48AB1DB7ADFC5
7344startup.exeC:\Users\admin\AppData\Local\Temp\kl-setup-2025-04-29-20-11-14_KAV.21.21.7.384.logbinary
MD5:490A5E9FDFFFA0BD3978438E0B7E61FE
SHA256:29AED7D61A5E6F7A1C53F6FBB104B70D2551EFEBD4B19874A6ACF1577AA867B2
7344startup.exeC:\Users\admin\AppData\Local\Temp\E3FBA19163520F114BDE817F87F669EE\sharpvectorcore.dllexecutable
MD5:FC428DD22B409CCF0AE64744187462EB
SHA256:656C06CC1EDE41F47EF754A95420466CB89543DF323AD6065565000C3C6F24B6
7344startup.exeC:\Users\admin\AppData\Local\Temp\E3FBA19163520F114BDE817F87F669EE\kl.setup.ui.interoplayer.dllexecutable
MD5:E0870F2E74C69063E63610ED3CA69713
SHA256:A1628623B49E28E6F0BA34CDFBF26BFF98A29815F82D44F7146E778CBB68F57D
7344startup.exeC:\Users\admin\AppData\Local\Temp\kl-setup-2025-04-29-20-11-14_PREMIUM.21.21.7.384.logbinary
MD5:490A5E9FDFFFA0BD3978438E0B7E61FE
SHA256:29AED7D61A5E6F7A1C53F6FBB104B70D2551EFEBD4B19874A6ACF1577AA867B2
7344startup.exeC:\Users\admin\AppData\Local\Temp\E3FBA19163520F114BDE817F87F669EE\kl.ui.framework.uikit.b2c.dllexecutable
MD5:6B4F048788E042DAA3B4B83F6136FA41
SHA256:845B7CE5F3DC81DF6E67B2CF6F44403CFF0CDCABDE1E229D8BD059C1AF0BA46A
7344startup.exeC:\Users\admin\AppData\Local\Temp\E3FBA19163520F114BDE817F87F669EE\kl.setup.ui.core.dllexecutable
MD5:9A1F97D8B717A07492AE65C8B0F6C824
SHA256:23DE41D5D15BC3E3847326834042F54FDEEB2DB5148E238920810DBD26E00766
7344startup.exeC:\Users\admin\AppData\Local\Temp\E3FBA19163520F114BDE817F87F669EE\kl.ui.framework.dllexecutable
MD5:7712DECC281FEBD03EBFFBC9538FEA09
SHA256:ED0BB23234EDA94743776F511605855A2CC4F74B8CFDADA9FA54B345D9A2A35E
7344startup.exeC:\Users\admin\AppData\Local\Temp\E3FBA19163520F114BDE817F87F669EE\kl.ui.framework.uikit.media.setup.dllexecutable
MD5:17D1C9110FA11EB91677EC69D60CC022
SHA256:5D6CCDBC780AA7C0530AE9AD7732B0EF6F359B4016176AE660AC3BA0A30E4091
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
47
DNS requests
27
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.41:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7952
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7952
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7344
startup.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
whitelisted
4784
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
4784
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.41:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.31.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
5496
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7344
startup.exe
62.67.238.152:443
ds.kaspersky.com
LEVEL3
GB
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 142.250.186.142
whitelisted
crl.microsoft.com
  • 23.216.77.41
  • 23.216.77.43
  • 23.216.77.39
  • 23.216.77.7
  • 23.216.77.38
  • 23.216.77.6
  • 23.216.77.11
  • 23.216.77.5
  • 23.216.77.42
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 2.23.246.101
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 40.126.31.2
  • 20.190.159.75
  • 20.190.159.68
  • 20.190.159.23
  • 20.190.159.129
  • 20.190.159.64
  • 20.190.159.73
  • 40.126.31.73
whitelisted
ocsp.digicert.com
  • 184.30.131.245
  • 2.23.77.188
whitelisted
ds.kaspersky.com
  • 62.67.238.152
  • 82.202.184.184
  • 81.19.104.172
  • 82.202.185.148
  • 62.67.238.151
  • 82.202.185.146
  • 46.8.206.90
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted

Threats

No threats detected
No debug info