File name:

Install_CopyTransControlCenter.exe

Full analysis: https://app.any.run/tasks/8ec9f73e-1ad4-402e-b902-2643d0310e4e
Verdict: Malicious activity
Analysis date: November 01, 2024, 16:10:14
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
themida
arch-exec
arch-doc
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

243CD3B54966DCEF29B4C15F58829A2C

SHA1:

4771B761430BC6BA77A41C2CE5948AC316BFCE51

SHA256:

54CE07811B5B120F0775D7ED7924F39347007CB86D63AACE32D2E78F92109FF9

SSDEEP:

98304:ZIHab8eoGVZEbINNJ022iSUdIfomTwOfjwyVPIWijyqx/NLSsTnNyNgRwUPfS9Bn:9LaQ47ZG2xtF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the BIOS version

      • Install_CopyTransControlCenter.exe (PID: 6128)
    • Executable content was dropped or overwritten

      • Install_CopyTransControlCenter.exe (PID: 6128)
      • CopyTransControlCenter.exe (PID: 6280)
      • CopyTrans.exe (PID: 5640)
    • Starts itself from another location

      • Install_CopyTransControlCenter.exe (PID: 6128)
    • Starts POWERSHELL.EXE for commands execution

      • CopyTrans.exe (PID: 5640)
  • INFO

    • Reads Environment values

      • Install_CopyTransControlCenter.exe (PID: 6128)
    • Checks supported languages

      • Install_CopyTransControlCenter.exe (PID: 6128)
    • Reads the computer name

      • Install_CopyTransControlCenter.exe (PID: 6128)
    • Reads product name

      • Install_CopyTransControlCenter.exe (PID: 6128)
    • Creates files in the program directory

      • Install_CopyTransControlCenter.exe (PID: 6128)
    • Themida protector has been detected

      • Install_CopyTransControlCenter.exe (PID: 6128)
    • Reads CPU info

      • Install_CopyTransControlCenter.exe (PID: 6128)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:03:25 22:46:29+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 6847488
InitializedDataSize: 7066112
UninitializedDataSize: -
EntryPoint: 0x1309058
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 5.0.0.3
ProductVersionNumber: 5.0.0.3
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Unknown (0009)
CharacterSet: Unicode
CompanyName: UrsaMinor Ltd.
FileDescription: CopyTransControlCenter
FileVersion: 5.0.0.3
InternalName: CopyTransControlCenter
LegalCopyright: Copyright (C) 2007 - 2022
OriginalFileName: CopytTransControlCenter.exe
ProductName: CopyTransControlCenter
ProductVersion: 5.0.0.3
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
145
Monitored processes
10
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start THREAT install_copytranscontrolcenter.exe copytranscontrolcenter.exe copytrans.exe powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs copytransmdhelper.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2416\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2888\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4548powershell.exe Get-AppxPackage -Name AppleInc.AppleDevices | Out-String -width 4096C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCopyTrans.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
5640"C:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyPod\CopyTrans.exe" C:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyPod\CopyTrans.exe
CopyTransControlCenter.exe
User:
admin
Company:
Ursa Minor Ltd.
Integrity Level:
MEDIUM
Exit code:
0
Version:
6.5.0.1
Modules
Images
c:\users\admin\appdata\roaming\windsolutions\copytranscontrolcenter\applications\copypod\copytrans.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
6128"C:\Users\admin\AppData\Local\Temp\Install_CopyTransControlCenter.exe" C:\Users\admin\AppData\Local\Temp\Install_CopyTransControlCenter.exe
explorer.exe
User:
admin
Company:
UrsaMinor Ltd.
Integrity Level:
MEDIUM
Description:
CopyTransControlCenter
Exit code:
0
Version:
5.0.0.3
Modules
Images
c:\users\admin\appdata\local\temp\install_copytranscontrolcenter.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
6240"C:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyPod\CopyTransMDHelper.exe" /l PL00001608 /x 5640 /n P00001608 /i "CopyTrans" /iv "6.501" /a C:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyPod\CopyTransMDHelper.exeCopyTrans.exe
User:
admin
Company:
UrsaMinor Ltd.
Integrity Level:
MEDIUM
Description:
CopyTransMDHelper
Exit code:
0
Version:
2.0.0.4
Modules
Images
c:\users\admin\appdata\roaming\windsolutions\copytranscontrolcenter\applications\copypod\copytransmdhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
6280"C:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyTransControlCenter.exe" /sleepC:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyTransControlCenter.exe
Install_CopyTransControlCenter.exe
User:
admin
Company:
UrsaMinor Ltd.
Integrity Level:
MEDIUM
Description:
CopyTransControlCenter
Exit code:
0
Version:
5.0.0.3
Modules
Images
c:\users\admin\appdata\roaming\windsolutions\copytranscontrolcenter\applications\copytranscontrolcenter.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
6760powershell.exe Get-AppxPackage -Name AppleInc.iCloud | Out-String -width 4096C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCopyTrans.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
6900\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7040powershell.exe Get-AppxPackage -Name AppleInc.iTunes | Out-String -width 4096C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCopyTrans.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
Total events
20 928
Read events
20 920
Write events
8
Delete events
0

Modification events

(PID) Process:(6128) Install_CopyTransControlCenter.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CopyTrans Suite
Operation:writeName:DisplayName
Value:
CopyTrans Control Center Uninstall Only
(PID) Process:(6128) Install_CopyTransControlCenter.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CopyTrans Suite
Operation:writeName:DisplayVersion
Value:
5.003
(PID) Process:(6128) Install_CopyTransControlCenter.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CopyTrans Suite
Operation:writeName:Publisher
Value:
WindSolutions
(PID) Process:(6128) Install_CopyTransControlCenter.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CopyTrans Suite
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyTransControlCenter.exe
(PID) Process:(6128) Install_CopyTransControlCenter.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CopyTrans Suite
Operation:writeName:UninstallString
Value:
C:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyTransControlCenter.exe /usermode /uninstall
(PID) Process:(5640) CopyTrans.exeKey:HKEY_CURRENT_USER\SOFTWARE\CopyTrans\CopyTrans
Operation:writeName:Uc_ct
Value:
1
(PID) Process:(5640) CopyTrans.exeKey:HKEY_CURRENT_USER\SOFTWARE\CopyTrans\CopyTrans
Operation:writeName:Fud_ct
Value:
ABFD246700000000
(PID) Process:(5640) CopyTrans.exeKey:HKEY_CURRENT_USER\SOFTWARE\CopyTrans
Operation:writeName:Faaud
Value:
ABFD246700000000
Executable files
5
Suspicious files
22
Text files
30
Unknown types
0

Dropped files

PID
Process
Filename
Type
6128Install_CopyTransControlCenter.exeC:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\CopyTransControlCenter.inibinary
MD5:08FD5E387A382BF5FF059C31702508F7
SHA256:86483FDA9CFBEF4BA87E9BA41F53C9F4CCE94759E4CA171F78C85D399A8D223C
6128Install_CopyTransControlCenter.exeC:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyTransControlCenter.exeexecutable
MD5:243CD3B54966DCEF29B4C15F58829A2C
SHA256:54CE07811B5B120F0775D7ED7924F39347007CB86D63AACE32D2E78F92109FF9
6280CopyTransControlCenter.exeC:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Cache\CopyTransTuneSwift.icoimage
MD5:1E80388A8EFEBC9673C0322965B1F7B9
SHA256:AC2BB70FF3302F1E8F45B7FE5FCDE03F64EBDBCBE11DD50B5916CB0F4E934D09
6128Install_CopyTransControlCenter.exeC:\Users\admin\AppData\Local\Temp\Uninstall CopyTrans Control Center.lnkbinary
MD5:D1AB42E510336B0B274EB32D0BE63045
SHA256:812B20DCA5647E8D89A29EB725B65B711A370A8900489724F1A44A905F118429
6280CopyTransControlCenter.exeC:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Cache\CopyTransManager.icoimage
MD5:4CC22DDA633E3341243AD7F66B652561
SHA256:B8358997BAB93ACA7B14CAC74D0CC34121163E92FE90DF9DCC3D688FABE423D0
6280CopyTransControlCenter.exeC:\ProgramData\WindSolutions\CopyTransControlCenter\Logs\Log_2024-11-01_1.txttext
MD5:D517BA13884FDDD94171EBD3F3D35904
SHA256:12A17F72A3BD05D50E479D29BC70A126B819AA669720840E8220A83D7F74B207
6280CopyTransControlCenter.exeC:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Cache\CopyTrans Backup Extractor.icoimage
MD5:AB6103C11AC17865159FB713DD917191
SHA256:DC6795052547B18E5CCD760A7EC421F9A55D766D67A9B718C6DDD25D04E95AD8
6280CopyTransControlCenter.exeC:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Cache\programs.kxxml
MD5:466DB886115D6CFC5D9412BAFB4D560C
SHA256:84874A9DD687DC8213053A93A601975361951A2ECE18EF51B2688B17FA359345
6280CopyTransControlCenter.exeC:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Cache\CopyTrans Filey.icoimage
MD5:E12C43AED9DA44CDF290F74F8C95A443
SHA256:BC42C79E314930EB676F63E32162F1B2B7975733EAACCD63C250E72FD383A2A2
6280CopyTransControlCenter.exeC:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Cache\CopyTrans Contacts.icoimage
MD5:0787D82E24EFCAA525E8085FF48671D7
SHA256:7824A602B3979F3B53FC20F2F0F8D8612EF7F021269ECF06BBD5446EF42F9FE0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
24
TCP/UDP connections
52
DNS requests
27
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6944
svchost.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
624
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6944
svchost.exe
GET
200
23.48.23.193:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
748
lsass.exe
GET
200
23.53.40.162:80
http://r11.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBQaUrm0WeTDM5ghfoZtS72KO9ZnzgQUCLkRO6XQhRi06g%2BgrZ%2BGHo78OCcCEgQt9wPvLUKR%2FenJIJA9UiP%2Blw%3D%3D
unknown
whitelisted
204
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6280
CopyTransControlCenter.exe
GET
200
52.47.178.141:80
http://api.copytrans.net/en/CTCC/ico/CT.ico
unknown
unknown
6280
CopyTransControlCenter.exe
GET
200
52.47.178.141:80
http://api.copytrans.net/en/CTCC/ico/CTP.ico
unknown
unknown
6280
CopyTransControlCenter.exe
GET
200
52.47.178.141:80
http://api.copytrans.net/en/CTCC/ico/CTS-icon.ico
unknown
unknown
6280
CopyTransControlCenter.exe
GET
200
52.47.178.141:80
http://api.copytrans.net/en/CTCC/ico/CopyTransCloudly_Icon.ico
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6944
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1248
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5488
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
6944
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6944
svchost.exe
23.48.23.193:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6944
svchost.exe
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4360
SearchApp.exe
104.126.37.179:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 20.73.194.208
  • 51.104.136.2
whitelisted
google.com
  • 142.250.186.142
whitelisted
crl.microsoft.com
  • 23.48.23.193
  • 23.48.23.159
  • 23.48.23.141
  • 23.48.23.194
  • 23.48.23.145
  • 23.48.23.164
  • 23.48.23.173
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 23.52.120.96
whitelisted
www.bing.com
  • 104.126.37.179
  • 104.126.37.161
  • 104.126.37.185
  • 104.126.37.178
  • 104.126.37.163
  • 104.126.37.155
  • 104.126.37.177
  • 104.126.37.160
  • 104.126.37.153
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.133
  • 40.126.32.134
  • 40.126.32.138
  • 20.190.160.17
  • 40.126.32.136
  • 40.126.32.140
  • 20.190.160.14
  • 40.126.32.74
whitelisted
th.bing.com
  • 104.126.37.177
  • 104.126.37.161
  • 104.126.37.153
  • 104.126.37.160
  • 104.126.37.155
  • 104.126.37.178
  • 104.126.37.144
  • 104.126.37.163
  • 104.126.37.145
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted

Threats

No threats detected
No debug info