download:

/c2r/download.aspx

Full analysis: https://app.any.run/tasks/d3eea808-856a-45ae-90c8-1fde4b98fd65
Verdict: Malicious activity
Analysis date: August 25, 2024, 17:05:16
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

4A11708662B962EE806A390681B2072B

SHA1:

83F8F9E46F838633A6AE6F21FEF68202CCF93D40

SHA256:

54A4BD2791EB79C5389E52CAE1046F47078A27E862629BE4A3BEDD184398BD78

SSDEEP:

98304:nh7/rcpc1FbuxzSqCz/cN+wKdd3RpNJ61NKhQOf5wneWlJbVRRz8LE5o6HnAKLiJ:En7a

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Scans artifacts that could help determine the target

      • download.aspx.exe (PID: 7008)
      • download.aspx.exe (PID: 6872)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • download.aspx.exe (PID: 6872)
      • OfficeClickToRun.exe (PID: 7112)
      • OfficeClickToRun.exe (PID: 2008)
    • Drops the executable file immediately after the start

      • download.aspx.exe (PID: 6872)
      • OfficeClickToRun.exe (PID: 7112)
      • OfficeClickToRun.exe (PID: 2008)
    • Starts a Microsoft application from unusual location

      • download.aspx.exe (PID: 6872)
      • download.aspx.exe (PID: 7008)
    • Reads security settings of Internet Explorer

      • download.aspx.exe (PID: 6872)
      • download.aspx.exe (PID: 7008)
    • Reads the date of Windows installation

      • download.aspx.exe (PID: 6872)
    • Application launched itself

      • download.aspx.exe (PID: 6872)
    • Checks Windows Trust Settings

      • download.aspx.exe (PID: 7008)
      • download.aspx.exe (PID: 6872)
    • Searches for installed software

      • download.aspx.exe (PID: 7008)
    • Executable content was dropped or overwritten

      • OfficeClickToRun.exe (PID: 7112)
      • OfficeClickToRun.exe (PID: 2008)
    • The process drops C-runtime libraries

      • OfficeClickToRun.exe (PID: 7112)
  • INFO

    • Reads the computer name

      • download.aspx.exe (PID: 6872)
      • download.aspx.exe (PID: 7008)
      • OfficeClickToRun.exe (PID: 7112)
      • OfficeClickToRun.exe (PID: 2008)
      • OfficeClickToRun.exe (PID: 7000)
    • Checks supported languages

      • download.aspx.exe (PID: 6872)
      • download.aspx.exe (PID: 7008)
      • OfficeClickToRun.exe (PID: 7112)
      • OfficeClickToRun.exe (PID: 2008)
      • OfficeClickToRun.exe (PID: 7000)
    • Reads the machine GUID from the registry

      • download.aspx.exe (PID: 6872)
      • download.aspx.exe (PID: 7008)
      • OfficeClickToRun.exe (PID: 2008)
      • OfficeClickToRun.exe (PID: 7112)
      • OfficeClickToRun.exe (PID: 7000)
    • Reads Microsoft Office registry keys

      • download.aspx.exe (PID: 6872)
      • download.aspx.exe (PID: 7008)
      • OfficeClickToRun.exe (PID: 7112)
      • OfficeClickToRun.exe (PID: 2008)
      • OfficeClickToRun.exe (PID: 7000)
    • Process checks computer location settings

      • download.aspx.exe (PID: 6872)
      • download.aspx.exe (PID: 7008)
    • Process checks whether UAC notifications are on

      • download.aspx.exe (PID: 6872)
    • Checks proxy server information

      • download.aspx.exe (PID: 6872)
      • download.aspx.exe (PID: 7008)
      • OfficeClickToRun.exe (PID: 7112)
      • OfficeClickToRun.exe (PID: 2008)
      • OfficeClickToRun.exe (PID: 7000)
    • Creates files or folders in the user directory

      • download.aspx.exe (PID: 6872)
      • download.aspx.exe (PID: 7008)
      • OfficeClickToRun.exe (PID: 7112)
      • OfficeClickToRun.exe (PID: 7000)
    • Reads the software policy settings

      • download.aspx.exe (PID: 6872)
      • download.aspx.exe (PID: 7008)
      • OfficeClickToRun.exe (PID: 7112)
      • OfficeClickToRun.exe (PID: 7000)
    • Create files in a temporary directory

      • download.aspx.exe (PID: 7008)
      • OfficeClickToRun.exe (PID: 7112)
      • download.aspx.exe (PID: 6872)
      • OfficeClickToRun.exe (PID: 7000)
    • Reads Environment values

      • download.aspx.exe (PID: 6872)
      • download.aspx.exe (PID: 7008)
    • Creates files in the program directory

      • OfficeClickToRun.exe (PID: 7112)
      • OfficeClickToRun.exe (PID: 2008)
    • Executes as Windows Service

      • OfficeClickToRun.exe (PID: 2008)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:08:10 16:41:45+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.38
CodeSize: 4558848
InitializedDataSize: 2993664
UninitializedDataSize: -
EntryPoint: 0x3e0472
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 16.0.17830.20166
ProductVersionNumber: 16.0.17830.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Windows, Latin1
CompanyName: Microsoft Corporation
FileDescription: Microsoft 365 and Office
FileVersion: 16.0.17830.20166
InternalName: Bootstrapper.exe
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFileName: Bootstrapper.exe
ProductName: Microsoft Office
ProductVersion: 16.0.17830.20166
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
6
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start download.aspx.exe download.aspx.exe officeclicktorun.exe Delivery Optimization User no specs officeclicktorun.exe officeclicktorun.exe

Process information

PID
CMD
Path
Indicators
Parent process
2008"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /serviceC:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Office Click-to-Run (SxS)
Version:
16.0.17830.20166
Modules
Images
c:\program files\common files\microsoft shared\clicktorun\officeclicktorun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\gdi32.dll
6200C:\WINDOWS\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
6872"C:\Users\admin\AppData\Local\Temp\download.aspx.exe" C:\Users\admin\AppData\Local\Temp\download.aspx.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft 365 and Office
Exit code:
17002
Version:
16.0.17830.20166
Modules
Images
c:\users\admin\appdata\local\temp\download.aspx.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7000OfficeClickToRun.exe platform=x64 culture=en-us productstoadd=Word2024Retail.16_en-us_x-none cdnbaseurl.16=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 baseurl.16=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 version.16=16.0.17830.20166 mediatype.16=CDN sourcetype.16=CDN Word2024Retail.excludedapps.16=groove updatesenabled.16=False bitnessmigration=False deliverymechanism=492350f6-3a01-4f97-b9c0-c7c6ddf67d60 flt.useoutlookshareaddon=unknown flt.useofficehelperaddon=unknown flt.UseTeamsOnInstallConsumer=unknown flt.UseTeamsOnUpdateConsumer=unknown uninstallcentennial=TrueC:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
download.aspx.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Office Click-to-Run (SxS)
Exit code:
17002
Version:
16.0.17830.20166
Modules
Images
c:\program files\common files\microsoft shared\clicktorun\officeclicktorun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
7008"C:\Users\admin\AppData\Local\Temp\download.aspx.exe" ELEVATED sid=S-1-5-21-1693682860-607145093-2874071422-1001 C:\Users\admin\AppData\Local\Temp\download.aspx.exe
download.aspx.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft 365 and Office
Exit code:
17002
Version:
16.0.17830.20166
Modules
Images
c:\users\admin\appdata\local\temp\download.aspx.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7112OfficeClickToRun.exe platform=x64 culture=en-us productstoadd=Word2024Retail.16_en-us_x-none cdnbaseurl=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 baseurl=http://officecdn.microsoft.com/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60 version=16.0.17830.20166 mediatype=CDN sourcetype=CDN Word2024Retail.excludedapps=groove updatesenabled=False bitnessmigration=False deliverymechanism=492350f6-3a01-4f97-b9c0-c7c6ddf67d60 flt.useoutlookshareaddon=unknown flt.useofficehelperaddon=unknown flt.UseTeamsOnInstallConsumer=unknown flt.UseTeamsOnUpdateConsumer=unknown uninstallcentennial=True scenario=CLIENTUPDATEC:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
download.aspx.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Office Click-to-Run (SxS)
Exit code:
0
Version:
16.0.16026.20140
Modules
Images
c:\program files\common files\microsoft shared\clicktorun\officeclicktorun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
22 015
Read events
21 517
Write events
276
Delete events
222

Modification events

(PID) Process:(6872) download.aspx.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:en-US
Value:
2
(PID) Process:(6872) download.aspx.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:de-de
Value:
2
(PID) Process:(6872) download.aspx.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:fr-fr
Value:
2
(PID) Process:(6872) download.aspx.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:es-es
Value:
2
(PID) Process:(6872) download.aspx.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:it-it
Value:
2
(PID) Process:(6872) download.aspx.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:ja-jp
Value:
2
(PID) Process:(6872) download.aspx.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:ko-kr
Value:
2
(PID) Process:(6872) download.aspx.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:pt-br
Value:
2
(PID) Process:(6872) download.aspx.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:ru-ru
Value:
2
(PID) Process:(6872) download.aspx.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:tr-tr
Value:
2
Executable files
391
Suspicious files
22
Text files
44
Unknown types
4

Dropped files

PID
Process
Filename
Type
7008download.aspx.exeC:\Users\admin\AppData\Local\Microsoft\Office\OTele\download.aspx.exe.db-journalbinary
MD5:611FF760E3072862E27A18DDCB4E26EE
SHA256:F88E29783D6A96B7505B0C9AD91CE0FAFB71D61EF11E653B3B9EA8511ABC64BA
7008download.aspx.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\A583E2A51BFBDC1E492A57B7C8325850der
MD5:C7D1234376F3389D6C220F0DCF24341B
SHA256:F67F7E62B47D1C4D9059F9F01FF40D52044EE81F594C5B8C8925C254381061E5
7008download.aspx.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\A583E2A51BFBDC1E492A57B7C8325850binary
MD5:A7D64784789E37201AE354FD9A9107D9
SHA256:477DE597294014A0200515015CFDA990A342258F996541C3038ABEFCCBB5C260
6872download.aspx.exeC:\Users\admin\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\152AC26E-1CE8-48D5-BF8E-B72889CDFBA4xml
MD5:B4D6A087C4DCD6304205DF76D7CEA815
SHA256:7DAE23C01A7491FC531A44A3C85CC6292667FE8A5AA5DCFC08A0403632B62C9B
7008download.aspx.exeC:\Users\admin\AppData\Local\Temp\OfficeC2RF504FBB2-3E35-4F34-A3A1-FBDA4DC98BE2\v64.hashtext
MD5:B8074EEF87A25A2E40247E00B96E3881
SHA256:50EF5AD7AD8D1F52D77807FD1C25A38B5D2917B08B19EEA8B59E88E7934C564C
7008download.aspx.exeC:\Users\admin\AppData\Local\Temp\OfficeC2RF504FBB2-3E35-4F34-A3A1-FBDA4DC98BE2\v64_16.0.17830.20166.cabcompressed
MD5:43F3F0AEBBABD1B44B075DF9062DA29C
SHA256:5D12DCE0D86BF9D7C1BAE57893DCB73E992C2BE1F60A39098759C061DDB5DBBA
7008download.aspx.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\36AC0BE60E1243344AE145F746D881FEbinary
MD5:5917B6F9DBE6F64D4B9598908335ECE3
SHA256:8FE55D0A82DC9B67667EFD7399BFEE3B6CE350D64C9102BE8DCB5D448DE3922D
7008download.aspx.exeC:\Users\admin\AppData\Local\Temp\OfficeC2RF504FBB2-3E35-4F34-A3A1-FBDA4DC98BE2OfficeC2R26C26DEF-F883-46BF-8D21-C921F110D898\v64.hashtext
MD5:B8074EEF87A25A2E40247E00B96E3881
SHA256:50EF5AD7AD8D1F52D77807FD1C25A38B5D2917B08B19EEA8B59E88E7934C564C
7008download.aspx.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0B8A20E1F3F4D73D52A19929F922C892binary
MD5:AD2FB9EC56B0843EB98EF04BE4ED6E4F
SHA256:69D0B105C80F6F51B46010F80FEFCF365FA429C0BEC3C954CC3F0B3FD9F8852C
7008download.aspx.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\36AC0BE60E1243344AE145F746D881FEder
MD5:DDF4DE0DC1AC39C22F605957A1FE614B
SHA256:0ACF9791F2CBBF8330653DF8D90E760108DD7ED3B5DB03C4DE164BD5047E4D4A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
47
TCP/UDP connections
40
DNS requests
30
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7008
download.aspx.exe
HEAD
200
23.50.131.73:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.16026.20146.cab
unknown
whitelisted
7008
download.aspx.exe
HEAD
200
23.50.131.73:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.17830.20166.cab
unknown
whitelisted
7008
download.aspx.exe
HEAD
200
23.50.131.73:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.17830.20166.cab
unknown
whitelisted
7008
download.aspx.exe
GET
200
23.50.131.73:80
http://f.c2r.ts.cdn.office.net/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/v64_16.0.17830.20166.cab
unknown
whitelisted
7008
download.aspx.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
7008
download.aspx.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_2010-07-06.crl
unknown
whitelisted
7008
download.aspx.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
unknown
whitelisted
3180
svchost.exe
GET
200
95.168.195.202:80
http://95.168.195.202/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/16.0.17830.20166/i640.cab.phf?cacheHostOrigin=officecdn.microsoft.com
unknown
unknown
3180
svchost.exe
GET
206
95.168.195.202:80
http://95.168.195.202/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/16.0.17830.20166/i640.cab?cacheHostOrigin=f.c2r.ts.cdn.office.net
unknown
unknown
3180
svchost.exe
GET
206
95.168.195.202:80
http://95.168.195.202/pr/492350f6-3a01-4f97-b9c0-c7c6ddf67d60/Office/Data/16.0.17830.20166/i640.cab?cacheHostOrigin=f.c2r.ts.cdn.office.net
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5284
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
3208
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6872
download.aspx.exe
52.109.76.240:443
officeclient.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
6872
download.aspx.exe
52.113.194.132:443
ecs.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
7008
download.aspx.exe
52.109.89.117:443
mrodevicemgr.officeapps.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
7008
download.aspx.exe
23.50.131.73:80
f.c2r.ts.cdn.office.net
Akamai International B.V.
DE
unknown
7008
download.aspx.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
  • 51.104.136.2
whitelisted
google.com
  • 142.250.185.206
whitelisted
officeclient.microsoft.com
  • 52.109.76.240
whitelisted
ecs.office.com
  • 52.113.194.132
whitelisted
mrodevicemgr.officeapps.live.com
  • 52.109.89.117
whitelisted
f.c2r.ts.cdn.office.net
  • 23.50.131.73
  • 23.50.131.95
  • 152.199.21.175
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
officecdn.microsoft.com
  • 152.199.21.175
whitelisted
geo.prod.do.dsp.mp.microsoft.com
  • 13.74.187.43
whitelisted

Threats

No threats detected
No debug info