File name:

startup.exe

Full analysis: https://app.any.run/tasks/82a73dfd-6a64-4cce-8b8a-e1dfb6271b60
Verdict: Malicious activity
Analysis date: April 29, 2025, 20:10:55
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

C20F1D9C4B9D6E5B57BCED75FA0625ED

SHA1:

EE6E9FBA2CE2A677F2653B38CA0A8CD9FFFD9DC0

SHA256:

49C50278CC879EDED20E3303D9F2A02433F9261C0D1A7CC975A58C9F2E20098A

SSDEEP:

98304:KJ70OtKMmo5PJecdpC+ZCY82yq/OjzNrE4gy0b685ggYSBgzCYryem+ROMFFef39:j7K4tU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • startup.exe (PID: 7344)
      • startup.exe (PID: 4400)
      • startup.exe (PID: 4200)
    • Reads security settings of Internet Explorer

      • setup_ui.exe (PID: 7388)
      • startup.exe (PID: 7344)
      • setup_ui.exe (PID: 6028)
      • startup.exe (PID: 4200)
    • Application launched itself

      • startup.exe (PID: 7344)
    • Starts itself from another location

      • startup.exe (PID: 4400)
    • The process verifies whether the antivirus software is installed

      • startup.exe (PID: 4200)
  • INFO

    • Reads the computer name

      • startup.exe (PID: 7344)
      • setup_ui.exe (PID: 7388)
      • startup.exe (PID: 4200)
      • setup_ui.exe (PID: 6028)
      • startup.exe (PID: 4400)
    • Checks supported languages

      • startup.exe (PID: 7344)
      • setup_ui.exe (PID: 7388)
      • startup.exe (PID: 4400)
      • startup.exe (PID: 4200)
      • setup_ui.exe (PID: 6028)
    • Create files in a temporary directory

      • startup.exe (PID: 7344)
      • startup.exe (PID: 4200)
    • Reads the machine GUID from the registry

      • startup.exe (PID: 7344)
      • setup_ui.exe (PID: 7388)
      • setup_ui.exe (PID: 6028)
      • startup.exe (PID: 4200)
    • The sample compiled with english language support

      • startup.exe (PID: 7344)
      • startup.exe (PID: 4400)
      • startup.exe (PID: 4200)
    • Reads the software policy settings

      • startup.exe (PID: 7344)
      • startup.exe (PID: 4200)
      • slui.exe (PID: 7528)
    • Checks proxy server information

      • startup.exe (PID: 7344)
      • startup.exe (PID: 4200)
    • Creates files or folders in the user directory

      • startup.exe (PID: 7344)
    • Creates files in the program directory

      • startup.exe (PID: 7344)
      • startup.exe (PID: 4200)
    • Checks for the presence of KasperskyLab

      • startup.exe (PID: 7344)
      • startup.exe (PID: 4200)
    • Process checks computer location settings

      • startup.exe (PID: 7344)
    • Process checks whether UAC notifications are on

      • startup.exe (PID: 7344)
      • startup.exe (PID: 4200)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:04:16 07:20:24+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 255488
InitializedDataSize: 4747264
UninitializedDataSize: -
EntryPoint: 0x3b10
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 21.21.7.384
ProductVersionNumber: 21.21.7.384
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Kaspersky
FileDescription: Kaspersky [21.21.7.384.0.115.0]
FileVersion: 21.21.7.384
LegalCopyright: © 2025 AO Kaspersky Lab
LegalTrademarks: Eingetragene Markenzeichen und Handelsmarken sind das Eigentum ihrer Besitzer
ProductName: Kaspersky
ProductVersion: 21.21.7.384
InternalName: Setup
OriginalFileName: Setup.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start startup.exe setup_ui.exe no specs sppextcomobj.exe no specs slui.exe startup.exe startup.exe setup_ui.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
4200"C:\WINDOWS\temp\851BAE2363520F114BDE817F87F669EE\startup.exe" /-elevated=;"C:\Users\admin\AppData\Local\Temp\startup.exe"C:\Windows\Temp\851BAE2363520F114BDE817F87F669EE\startup.exe
startup.exe
User:
admin
Company:
Kaspersky
Integrity Level:
HIGH
Description:
Kaspersky [21.21.7.384.0.115.0]
Version:
21.21.7.384
Modules
Images
c:\windows\temp\851bae2363520f114bde817f87f669ee\startup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\version.dll
4400"C:\Users\admin\AppData\Local\Temp\startup.exe" /-elevated=;"C:\Users\admin\AppData\Local\Temp\startup.exe"C:\Users\admin\AppData\Local\Temp\startup.exe
startup.exe
User:
admin
Company:
Kaspersky
Integrity Level:
HIGH
Description:
Kaspersky [21.21.7.384.0.115.0]
Version:
21.21.7.384
Modules
Images
c:\users\admin\appdata\local\temp\startup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\version.dll
6004C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6028"C:\Users\admin\AppData\Local\Temp\4E81F13363520F114BDE817F87F669EE\setup_ui.exe" -cp=objref:TUVPVwEAAAAAAAAAAAAAAMAAAAAAAABGgQIAAAAAAAACRIkPs6r4hg8v9BFpRMiCAsAAAGgQ///3bG9+cAhKlDgAIgAHAEQARQBTAEsAVABPAFAALQBKAEcATABMAEoATABEAAAABwAxADkAMgAuADEANgA4AC4AMQAwADAALgAxADUAAAAAAAkA//8AAB4A//8AABAA//8AAAoA//8AABYA//8AAB8A//8AAA4A//8AAAAA:C:\Users\admin\AppData\Local\Temp\4E81F13363520F114BDE817F87F669EE\setup_ui.exestartup.exe
User:
admin
Company:
Kaspersky
Integrity Level:
MEDIUM
Description:
Kaspersky [21.21.7.384.0.115.0]
Version:
21.21.7.384
Modules
Images
c:\users\admin\appdata\local\temp\4e81f13363520f114bde817f87f669ee\setup_ui.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\version.dll
7344"C:\Users\admin\AppData\Local\Temp\startup.exe" C:\Users\admin\AppData\Local\Temp\startup.exe
explorer.exe
User:
admin
Company:
Kaspersky
Integrity Level:
MEDIUM
Description:
Kaspersky [21.21.7.384.0.115.0]
Version:
21.21.7.384
Modules
Images
c:\users\admin\appdata\local\temp\startup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\version.dll
7388"C:\Users\admin\AppData\Local\Temp\E3FBA19163520F114BDE817F87F669EE\setup_ui.exe" -cp=objref:TUVPVwEAAAAAAAAAAAAAAMAAAAAAAABGgQIAAAAAAABbMSZeyVrXUSj5WMu/cDQiAlAAALAc//8iuesYQFznlzgAIgAHAEQARQBTAEsAVABPAFAALQBKAEcATABMAEoATABEAAAABwAxADkAMgAuADEANgA4AC4AMQAwADAALgAxADUAAAAAAAkA//8AAB4A//8AABAA//8AAAoA//8AABYA//8AAB8A//8AAA4A//8AAAAA:C:\Users\admin\AppData\Local\Temp\E3FBA19163520F114BDE817F87F669EE\setup_ui.exestartup.exe
User:
admin
Company:
Kaspersky
Integrity Level:
MEDIUM
Description:
Kaspersky [21.21.7.384.0.115.0]
Exit code:
0
Version:
21.21.7.384
Modules
Images
c:\users\admin\appdata\local\temp\e3fba19163520f114bde817f87f669ee\setup_ui.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\version.dll
7472C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7528"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
10 288
Read events
10 150
Write events
138
Delete events
0

Modification events

(PID) Process:(7344) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.115.0\volatile
Operation:writeName:cp_storedResolvedType
Value:
-1
(PID) Process:(7344) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.115.0\volatile
Operation:writeName:cp_storedResolvedProductTier
Value:
0
(PID) Process:(7344) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.115.0\volatile
Operation:writeName:cp_storedResolvedStartupScenario
Value:
(PID) Process:(7344) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.115.0\volatile
Operation:writeName:cp_storedResolvedType
Value:
7
(PID) Process:(7344) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.115.0\volatile
Operation:writeName:cp_storedResolvedProductTier
Value:
290
(PID) Process:(7344) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.115.0\volatile
Operation:writeName:PreferredUI
Value:
0
(PID) Process:(7344) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.115.0\volatile
Operation:writeName:PreferredUI
Value:
1
(PID) Process:(7344) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.115.0
Operation:writeName:TrashFiles
Value:
C:\Users\admin\AppData\Local\Temp\discovery.cfg
(PID) Process:(7344) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.115.0
Operation:writeName:TrashFiles
Value:
C:\Users\admin\AppData\Local\Temp\discovery.cfg C:\ProgramData\Kaspersky Lab Setup Files\PREMIUM21.21.7.384.0.115.0
(PID) Process:(7344) startup.exeKey:HKEY_CURRENT_USER\SOFTWARE\KasperskyLabSetup\Setup21.21.7.384.0.115.0
Operation:writeName:TrashFiles
Value:
C:\Users\admin\AppData\Local\Temp\discovery.cfg C:\ProgramData\Kaspersky Lab Setup Files\PREMIUM21.21.7.384.0.115.0 C:\ProgramData\Kaspersky Lab Setup Files
Executable files
35
Suspicious files
36
Text files
50
Unknown types
1

Dropped files

PID
Process
Filename
Type
7344startup.exeC:\Users\admin\AppData\Local\Temp\kl-setup-2025-04-29-20-11-14_PREMIUM.21.21.7.384.logbinary
MD5:490A5E9FDFFFA0BD3978438E0B7E61FE
SHA256:29AED7D61A5E6F7A1C53F6FBB104B70D2551EFEBD4B19874A6ACF1577AA867B2
7344startup.exeC:\Users\admin\AppData\Local\Temp\E3FBA19163520F114BDE817F87F669EE\sharpvectorconverterswpf.dllexecutable
MD5:75E2C2A995C7DE9B2692A6EE33FBC4D8
SHA256:D45C5A1FA99A15D738B3716ACF7D2014D0E7AE658C0427097ED9A2671BA6A70A
7344startup.exeC:\Users\admin\AppData\Local\Temp\E3FBA19163520F114BDE817F87F669EE\kl.ui.framework.dllexecutable
MD5:7712DECC281FEBD03EBFFBC9538FEA09
SHA256:ED0BB23234EDA94743776F511605855A2CC4F74B8CFDADA9FA54B345D9A2A35E
7344startup.exeC:\Users\admin\AppData\Local\Temp\E3FBA19163520F114BDE817F87F669EE\kl.ui.framework.uikit.dllbinary
MD5:4E3218D45A99D57C205F7DF4CDD939C0
SHA256:C80BB296C0700D0D045729EFB9F2B4F8F15AC431CABB9A955C2C258651B2AC6D
7344startup.exeC:\Users\admin\AppData\Local\Temp\E3FBA19163520F114BDE817F87F669EE\kl.setup.ui.interoplayer.dllexecutable
MD5:E0870F2E74C69063E63610ED3CA69713
SHA256:A1628623B49E28E6F0BA34CDFBF26BFF98A29815F82D44F7146E778CBB68F57D
7344startup.exeC:\Users\admin\AppData\Local\Temp\E3FBA19163520F114BDE817F87F669EE\kl.setup.ui.dllexecutable
MD5:35464B0B8281A7A6F6577436A3042312
SHA256:9366179168B998AD9929E6BF3C610CB9EBE809C9B1C34D1D1BDAF2B34044B742
7344startup.exeC:\Users\admin\AppData\Local\Temp\191ABF3F-2536-11F0-B4ED-18F7786F96EE\downloader_neutral_PREMIUM.initext
MD5:1F8CE4B3A1AEE2EB28B106927CF8B76F
SHA256:B61D7E0071A6EB32A09A26105F0144FDDE42FBEB0BBBF8B9997B8E3431DC81E4
7344startup.exeC:\Users\admin\AppData\Local\Temp\E3FBA19163520F114BDE817F87F669EE\sharpvectorcss.dllexecutable
MD5:B066FE6AD311183FC5F3284644B03383
SHA256:E99D8CCAB6C41D84199D77B12EFE5F8138083517FDC8926D513F1B711D30E35B
7344startup.exeC:\Users\admin\AppData\Local\Temp\191ABF3F-2536-11F0-B4ED-18F7786F96EE\GuiStrings_PREMIUM.loctext
MD5:ECAA88F7FA0BF610A5A26CF545DCD3AA
SHA256:F1945CD6C19E56B3C1C78943EF5EC18116907A4CA1EFC40A57D48AB1DB7ADFC5
7344startup.exeC:\Users\admin\AppData\Local\Temp\kl-setup-2025-04-29-20-11-14_KAV.21.21.7.384.logbinary
MD5:490A5E9FDFFFA0BD3978438E0B7E61FE
SHA256:29AED7D61A5E6F7A1C53F6FBB104B70D2551EFEBD4B19874A6ACF1577AA867B2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
47
DNS requests
27
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.41:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7952
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4784
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
7952
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7344
startup.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAbY2QTVWENG9oovp1QifsQ%3D
unknown
whitelisted
4784
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.41:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.31.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
5496
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7344
startup.exe
62.67.238.152:443
ds.kaspersky.com
LEVEL3
GB
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 142.250.186.142
whitelisted
crl.microsoft.com
  • 23.216.77.41
  • 23.216.77.43
  • 23.216.77.39
  • 23.216.77.7
  • 23.216.77.38
  • 23.216.77.6
  • 23.216.77.11
  • 23.216.77.5
  • 23.216.77.42
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 2.23.246.101
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 40.126.31.2
  • 20.190.159.75
  • 20.190.159.68
  • 20.190.159.23
  • 20.190.159.129
  • 20.190.159.64
  • 20.190.159.73
  • 40.126.31.73
whitelisted
ocsp.digicert.com
  • 184.30.131.245
  • 2.23.77.188
whitelisted
ds.kaspersky.com
  • 62.67.238.152
  • 82.202.184.184
  • 81.19.104.172
  • 82.202.185.148
  • 62.67.238.151
  • 82.202.185.146
  • 46.8.206.90
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted

Threats

No threats detected
No debug info