File name:

Install_CopyTransControlCenter.exe

Full analysis: https://app.any.run/tasks/8ec9f73e-1ad4-402e-b902-2643d0310e4e
Verdict: Malicious activity
Analysis date: November 01, 2024, 16:10:14
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
themida
arch-exec
arch-doc
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 11 sections
MD5:

243CD3B54966DCEF29B4C15F58829A2C

SHA1:

4771B761430BC6BA77A41C2CE5948AC316BFCE51

SHA256:

54CE07811B5B120F0775D7ED7924F39347007CB86D63AACE32D2E78F92109FF9

SSDEEP:

98304:ZIHab8eoGVZEbINNJ022iSUdIfomTwOfjwyVPIWijyqx/NLSsTnNyNgRwUPfS9Bn:9LaQ47ZG2xtF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the BIOS version

      • Install_CopyTransControlCenter.exe (PID: 6128)
    • Executable content was dropped or overwritten

      • Install_CopyTransControlCenter.exe (PID: 6128)
      • CopyTransControlCenter.exe (PID: 6280)
      • CopyTrans.exe (PID: 5640)
    • Starts itself from another location

      • Install_CopyTransControlCenter.exe (PID: 6128)
    • Starts POWERSHELL.EXE for commands execution

      • CopyTrans.exe (PID: 5640)
  • INFO

    • Reads product name

      • Install_CopyTransControlCenter.exe (PID: 6128)
    • Creates files in the program directory

      • Install_CopyTransControlCenter.exe (PID: 6128)
    • Reads Environment values

      • Install_CopyTransControlCenter.exe (PID: 6128)
    • Reads the computer name

      • Install_CopyTransControlCenter.exe (PID: 6128)
    • Checks supported languages

      • Install_CopyTransControlCenter.exe (PID: 6128)
    • Themida protector has been detected

      • Install_CopyTransControlCenter.exe (PID: 6128)
    • Reads CPU info

      • Install_CopyTransControlCenter.exe (PID: 6128)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:03:25 22:46:29+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 6847488
InitializedDataSize: 7066112
UninitializedDataSize: -
EntryPoint: 0x1309058
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 5.0.0.3
ProductVersionNumber: 5.0.0.3
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Unknown (0009)
CharacterSet: Unicode
CompanyName: UrsaMinor Ltd.
FileDescription: CopyTransControlCenter
FileVersion: 5.0.0.3
InternalName: CopyTransControlCenter
LegalCopyright: Copyright (C) 2007 - 2022
OriginalFileName: CopytTransControlCenter.exe
ProductName: CopyTransControlCenter
ProductVersion: 5.0.0.3
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
145
Monitored processes
10
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start THREAT install_copytranscontrolcenter.exe copytranscontrolcenter.exe copytrans.exe powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs copytransmdhelper.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2416\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2888\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4548powershell.exe Get-AppxPackage -Name AppleInc.AppleDevices | Out-String -width 4096C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCopyTrans.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
5640"C:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyPod\CopyTrans.exe" C:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyPod\CopyTrans.exe
CopyTransControlCenter.exe
User:
admin
Company:
Ursa Minor Ltd.
Integrity Level:
MEDIUM
Exit code:
0
Version:
6.5.0.1
Modules
Images
c:\users\admin\appdata\roaming\windsolutions\copytranscontrolcenter\applications\copypod\copytrans.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
6128"C:\Users\admin\AppData\Local\Temp\Install_CopyTransControlCenter.exe" C:\Users\admin\AppData\Local\Temp\Install_CopyTransControlCenter.exe
explorer.exe
User:
admin
Company:
UrsaMinor Ltd.
Integrity Level:
MEDIUM
Description:
CopyTransControlCenter
Exit code:
0
Version:
5.0.0.3
Modules
Images
c:\users\admin\appdata\local\temp\install_copytranscontrolcenter.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
6240"C:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyPod\CopyTransMDHelper.exe" /l PL00001608 /x 5640 /n P00001608 /i "CopyTrans" /iv "6.501" /a C:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyPod\CopyTransMDHelper.exeCopyTrans.exe
User:
admin
Company:
UrsaMinor Ltd.
Integrity Level:
MEDIUM
Description:
CopyTransMDHelper
Exit code:
0
Version:
2.0.0.4
Modules
Images
c:\users\admin\appdata\roaming\windsolutions\copytranscontrolcenter\applications\copypod\copytransmdhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
6280"C:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyTransControlCenter.exe" /sleepC:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyTransControlCenter.exe
Install_CopyTransControlCenter.exe
User:
admin
Company:
UrsaMinor Ltd.
Integrity Level:
MEDIUM
Description:
CopyTransControlCenter
Exit code:
0
Version:
5.0.0.3
Modules
Images
c:\users\admin\appdata\roaming\windsolutions\copytranscontrolcenter\applications\copytranscontrolcenter.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
6760powershell.exe Get-AppxPackage -Name AppleInc.iCloud | Out-String -width 4096C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCopyTrans.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
6900\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7040powershell.exe Get-AppxPackage -Name AppleInc.iTunes | Out-String -width 4096C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCopyTrans.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
Total events
20 928
Read events
20 920
Write events
8
Delete events
0

Modification events

(PID) Process:(6128) Install_CopyTransControlCenter.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CopyTrans Suite
Operation:writeName:DisplayName
Value:
CopyTrans Control Center Uninstall Only
(PID) Process:(6128) Install_CopyTransControlCenter.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CopyTrans Suite
Operation:writeName:DisplayVersion
Value:
5.003
(PID) Process:(6128) Install_CopyTransControlCenter.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CopyTrans Suite
Operation:writeName:Publisher
Value:
WindSolutions
(PID) Process:(6128) Install_CopyTransControlCenter.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CopyTrans Suite
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyTransControlCenter.exe
(PID) Process:(6128) Install_CopyTransControlCenter.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CopyTrans Suite
Operation:writeName:UninstallString
Value:
C:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyTransControlCenter.exe /usermode /uninstall
(PID) Process:(5640) CopyTrans.exeKey:HKEY_CURRENT_USER\SOFTWARE\CopyTrans\CopyTrans
Operation:writeName:Uc_ct
Value:
1
(PID) Process:(5640) CopyTrans.exeKey:HKEY_CURRENT_USER\SOFTWARE\CopyTrans\CopyTrans
Operation:writeName:Fud_ct
Value:
ABFD246700000000
(PID) Process:(5640) CopyTrans.exeKey:HKEY_CURRENT_USER\SOFTWARE\CopyTrans
Operation:writeName:Faaud
Value:
ABFD246700000000
Executable files
5
Suspicious files
22
Text files
30
Unknown types
0

Dropped files

PID
Process
Filename
Type
6128Install_CopyTransControlCenter.exeC:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyTransControlCenter.exeexecutable
MD5:243CD3B54966DCEF29B4C15F58829A2C
SHA256:54CE07811B5B120F0775D7ED7924F39347007CB86D63AACE32D2E78F92109FF9
6128Install_CopyTransControlCenter.exeC:\Users\admin\Desktop\CopyTrans Control Center.lnklnk
MD5:EAEDF74D18E8AD9552F6D1B23FAED6D6
SHA256:9A28BE26953CE1C99392EA6C42D5CEBC5078CC705A70A96FE28CE3538BC3A4F3
6128Install_CopyTransControlCenter.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CopyTrans Control Center\CopyTrans Control Center.lnklnk
MD5:2DF7FDAE5D69F2EEC3F16EBF3A70CBEF
SHA256:4BEA89C6125B961BDE4A9FAA00BAC5D608B8ABC246A8501276ADA4C0C0ADC9F9
6128Install_CopyTransControlCenter.exeC:\Users\admin\AppData\Local\Temp\CopyTrans Control Center.lnkbinary
MD5:EAEDF74D18E8AD9552F6D1B23FAED6D6
SHA256:9A28BE26953CE1C99392EA6C42D5CEBC5078CC705A70A96FE28CE3538BC3A4F3
6128Install_CopyTransControlCenter.exeC:\Users\admin\AppData\Local\Temp\Uninstall CopyTrans Control Center.lnkbinary
MD5:D1AB42E510336B0B274EB32D0BE63045
SHA256:812B20DCA5647E8D89A29EB725B65B711A370A8900489724F1A44A905F118429
6128Install_CopyTransControlCenter.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CopyTrans Control Center\Uninstall CopyTrans Control Center.lnkbinary
MD5:D1AB42E510336B0B274EB32D0BE63045
SHA256:812B20DCA5647E8D89A29EB725B65B711A370A8900489724F1A44A905F118429
6280CopyTransControlCenter.exeC:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Cache\CopyTrans Contacts.icoimage
MD5:0787D82E24EFCAA525E8085FF48671D7
SHA256:7824A602B3979F3B53FC20F2F0F8D8612EF7F021269ECF06BBD5446EF42F9FE0
6128Install_CopyTransControlCenter.exeC:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\uninstaller.xmlxml
MD5:E108AC8404C1C60EB848A210C2C9C71F
SHA256:5F4CDBEF99BB966FFBA5E7B8FD6F76AA37AB9AD5E32D01C54C41A44BDB77F08B
6128Install_CopyTransControlCenter.exeC:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\CopyTransControlCenter.inibinary
MD5:08FD5E387A382BF5FF059C31702508F7
SHA256:86483FDA9CFBEF4BA87E9BA41F53C9F4CCE94759E4CA171F78C85D399A8D223C
6280CopyTransControlCenter.exeC:\Users\admin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Cache\CopyTrans Shelbee.icoimage
MD5:FB1F01C36E6C53DA258C15F06C75AC13
SHA256:E2AE795E497CC69F63A11F68083C4C7DA08063B7C4D614C843919AF11EF0E0F1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
24
TCP/UDP connections
52
DNS requests
27
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6944
svchost.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6280
CopyTransControlCenter.exe
GET
200
52.47.178.141:80
http://www.copytrans.net/bin/CopyTransv6.501.wsp
unknown
unknown
6944
svchost.exe
GET
200
23.48.23.193:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
204
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
204
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
624
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
748
lsass.exe
GET
200
23.53.40.162:80
http://r11.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBQaUrm0WeTDM5ghfoZtS72KO9ZnzgQUCLkRO6XQhRi06g%2BgrZ%2BGHo78OCcCEgQt9wPvLUKR%2FenJIJA9UiP%2Blw%3D%3D
unknown
whitelisted
6280
CopyTransControlCenter.exe
GET
200
52.47.178.141:80
http://api.copytrans.net/en/CTCC/ico/CT.ico
unknown
unknown
6280
CopyTransControlCenter.exe
GET
200
52.47.178.141:80
http://api.copytrans.net/en/CTCC/ico/CTC.ico
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6944
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1248
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5488
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
6944
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6944
svchost.exe
23.48.23.193:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6944
svchost.exe
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4360
SearchApp.exe
104.126.37.179:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 20.73.194.208
  • 51.104.136.2
whitelisted
google.com
  • 142.250.186.142
whitelisted
crl.microsoft.com
  • 23.48.23.193
  • 23.48.23.159
  • 23.48.23.141
  • 23.48.23.194
  • 23.48.23.145
  • 23.48.23.164
  • 23.48.23.173
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 23.52.120.96
whitelisted
www.bing.com
  • 104.126.37.179
  • 104.126.37.161
  • 104.126.37.185
  • 104.126.37.178
  • 104.126.37.163
  • 104.126.37.155
  • 104.126.37.177
  • 104.126.37.160
  • 104.126.37.153
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.133
  • 40.126.32.134
  • 40.126.32.138
  • 20.190.160.17
  • 40.126.32.136
  • 40.126.32.140
  • 20.190.160.14
  • 40.126.32.74
whitelisted
th.bing.com
  • 104.126.37.177
  • 104.126.37.161
  • 104.126.37.153
  • 104.126.37.160
  • 104.126.37.155
  • 104.126.37.178
  • 104.126.37.144
  • 104.126.37.163
  • 104.126.37.145
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted

Threats

No threats detected
No debug info