File name:

windowsdesktop-runtime-6.0.33-win-x64.exe

Full analysis: https://app.any.run/tasks/603a4dc0-015a-49f2-80af-24260fa53bca
Verdict: Malicious activity
Analysis date: September 30, 2024, 04:47:13
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

2FD32B6746DC63036A057139AA35F839

SHA1:

93F290BE5799938E82E92AC572DEAA22CCC16ECB

SHA256:

6B1B7BFFE4024D86C4FEB6E881648DE557C6BFF2E16E867E3CE1A2ED39489A53

SSDEEP:

393216:W5roB7MQdyp4HAxVf0S0FWDzUdqqBRioGMEx6DiTga3wuxnhIKFE4kt:WGB/d6WygWDzSRiopEUilwuxhIJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 4976)
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 5044)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 4472)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 4976)
    • Process drops legitimate windows executable

      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 5044)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 4472)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 4976)
      • msiexec.exe (PID: 4668)
    • Executable content was dropped or overwritten

      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 4472)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 5044)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 4976)
    • Searches for installed software

      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 4472)
    • Reads security settings of Internet Explorer

      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 4472)
    • Starts itself from another location

      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 4472)
    • Creates a software uninstall entry

      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 4976)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 4668)
    • Checks Windows Trust Settings

      • msiexec.exe (PID: 4668)
    • The process creates files with name similar to system file names

      • msiexec.exe (PID: 4668)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 4668)
  • INFO

    • Checks supported languages

      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 5044)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 4472)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 4976)
      • msiexec.exe (PID: 4668)
      • msiexec.exe (PID: 6456)
    • Create files in a temporary directory

      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 5044)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 4472)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 4976)
    • Reads the computer name

      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 4472)
      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 4976)
      • msiexec.exe (PID: 4668)
      • msiexec.exe (PID: 6456)
    • The process uses the downloaded file

      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 4472)
    • Process checks computer location settings

      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 4472)
    • Creates files in the program directory

      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 4976)
    • Reads the machine GUID from the registry

      • windowsdesktop-runtime-6.0.33-win-x64.exe (PID: 4976)
      • msiexec.exe (PID: 4668)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 4668)
    • Reads the software policy settings

      • msiexec.exe (PID: 4668)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 4668)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:22 22:14:43+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.16
CodeSize: 314368
InitializedDataSize: 164352
UninitializedDataSize: -
EntryPoint: 0x302e5
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 6.0.33.33916
ProductVersionNumber: 6.0.33.33916
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Microsoft Corporation
FileDescription: Microsoft Windows Desktop Runtime - 6.0.33 (x64)
FileVersion: 6.0.33.33916
InternalName: setup
LegalCopyright: Copyright (c) Microsoft Corporation. All rights reserved.
OriginalFileName: windowsdesktop-runtime-6.0.33-win-x64.exe
ProductName: Microsoft Windows Desktop Runtime - 6.0.33 (x64)
ProductVersion: 6.0.33.33916
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
127
Monitored processes
8
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start windowsdesktop-runtime-6.0.33-win-x64.exe windowsdesktop-runtime-6.0.33-win-x64.exe windowsdesktop-runtime-6.0.33-win-x64.exe msiexec.exe msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2476C:\Windows\syswow64\MsiExec.exe -Embedding 1AC3B7E406C6AF96521D14505974A8C6C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
4472"C:\Users\admin\AppData\Local\Temp\{DDE4DC5A-797A-47C6-A529-32D93EE3A08F}\.cr\windowsdesktop-runtime-6.0.33-win-x64.exe" -burn.clean.room="C:\Users\admin\Desktop\windowsdesktop-runtime-6.0.33-win-x64.exe" -burn.filehandle.attached=580 -burn.filehandle.self=588 C:\Users\admin\AppData\Local\Temp\{DDE4DC5A-797A-47C6-A529-32D93EE3A08F}\.cr\windowsdesktop-runtime-6.0.33-win-x64.exe
windowsdesktop-runtime-6.0.33-win-x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Desktop Runtime - 6.0.33 (x64)
Exit code:
0
Version:
6.0.33.33916
Modules
Images
c:\users\admin\appdata\local\temp\{dde4dc5a-797a-47c6-a529-32d93ee3a08f}\.cr\windowsdesktop-runtime-6.0.33-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4668C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
4880C:\Windows\syswow64\MsiExec.exe -Embedding 2FE918B6E8698D52E93AFEA1322E64E0C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
4976"C:\Users\admin\AppData\Local\Temp\{72F4BB34-04D7-4F8A-AAF6-5F37138EDF1E}\.be\windowsdesktop-runtime-6.0.33-win-x64.exe" -q -burn.elevated BurnPipe.{BE5D2618-0565-4C66-B09F-5971BA50D1F9} {B361BBC8-1D68-4028-8047-654D174BFF5E} 4472C:\Users\admin\AppData\Local\Temp\{72F4BB34-04D7-4F8A-AAF6-5F37138EDF1E}\.be\windowsdesktop-runtime-6.0.33-win-x64.exe
windowsdesktop-runtime-6.0.33-win-x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Windows Desktop Runtime - 6.0.33 (x64)
Exit code:
0
Version:
6.0.33.33916
Modules
Images
c:\users\admin\appdata\local\temp\{72f4bb34-04d7-4f8a-aaf6-5f37138edf1e}\.be\windowsdesktop-runtime-6.0.33-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5044"C:\Users\admin\Desktop\windowsdesktop-runtime-6.0.33-win-x64.exe" C:\Users\admin\Desktop\windowsdesktop-runtime-6.0.33-win-x64.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Desktop Runtime - 6.0.33 (x64)
Exit code:
0
Version:
6.0.33.33916
Modules
Images
c:\users\admin\desktop\windowsdesktop-runtime-6.0.33-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6456C:\Windows\syswow64\MsiExec.exe -Embedding 7911B532AF44DECF2A6F675E8E9829B4C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6796C:\Windows\syswow64\MsiExec.exe -Embedding 46DAF6FB5ADADB1A87F1F7CD12DE6441C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
9 966
Read events
9 017
Write events
905
Delete events
44

Modification events

(PID) Process:(4976) windowsdesktop-runtime-6.0.33-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{ecb94bc3-963d-412a-b141-8b7c32ef103f}
Operation:writeName:BundleCachePath
Value:
C:\ProgramData\Package Cache\{ecb94bc3-963d-412a-b141-8b7c32ef103f}\windowsdesktop-runtime-6.0.33-win-x64.exe
(PID) Process:(4976) windowsdesktop-runtime-6.0.33-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{ecb94bc3-963d-412a-b141-8b7c32ef103f}
Operation:writeName:BundleUpgradeCode
Value:
{E50DC420-5C2F-5516-1DA5-0F8B584F9E0D}
(PID) Process:(4976) windowsdesktop-runtime-6.0.33-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{ecb94bc3-963d-412a-b141-8b7c32ef103f}
Operation:writeName:BundleAddonCode
Value:
(PID) Process:(4976) windowsdesktop-runtime-6.0.33-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{ecb94bc3-963d-412a-b141-8b7c32ef103f}
Operation:writeName:BundleDetectCode
Value:
(PID) Process:(4976) windowsdesktop-runtime-6.0.33-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{ecb94bc3-963d-412a-b141-8b7c32ef103f}
Operation:writeName:BundlePatchCode
Value:
(PID) Process:(4976) windowsdesktop-runtime-6.0.33-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{ecb94bc3-963d-412a-b141-8b7c32ef103f}
Operation:writeName:BundleVersion
Value:
6.0.33.33916
(PID) Process:(4976) windowsdesktop-runtime-6.0.33-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{ecb94bc3-963d-412a-b141-8b7c32ef103f}
Operation:writeName:VersionMajor
Value:
6
(PID) Process:(4976) windowsdesktop-runtime-6.0.33-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{ecb94bc3-963d-412a-b141-8b7c32ef103f}
Operation:writeName:VersionMinor
Value:
0
(PID) Process:(4976) windowsdesktop-runtime-6.0.33-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{ecb94bc3-963d-412a-b141-8b7c32ef103f}
Operation:writeName:BundleProviderKey
Value:
{ecb94bc3-963d-412a-b141-8b7c32ef103f}
(PID) Process:(4976) windowsdesktop-runtime-6.0.33-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{ecb94bc3-963d-412a-b141-8b7c32ef103f}
Operation:writeName:BundleTag
Value:
Executable files
525
Suspicious files
70
Text files
29
Unknown types
1

Dropped files

PID
Process
Filename
Type
5044windowsdesktop-runtime-6.0.33-win-x64.exeC:\Users\admin\AppData\Local\Temp\{DDE4DC5A-797A-47C6-A529-32D93EE3A08F}\.cr\windowsdesktop-runtime-6.0.33-win-x64.exeexecutable
MD5:69FD3B5245ABA65BF93952FDAA398B73
SHA256:52C79844D1F4758C49577903C276CF681BE4FD4AFAD26DCE7F4372A993877A6C
4472windowsdesktop-runtime-6.0.33-win-x64.exeC:\Users\admin\AppData\Local\Temp\{72F4BB34-04D7-4F8A-AAF6-5F37138EDF1E}\.ba\thm.xmlxml
MD5:302563A713B142EE41B59E3EEAC53A90
SHA256:83CA096F7BA2C83FC3B3AEB697B8139A788FA35EB8632943E26BB9FFF7C78E63
4472windowsdesktop-runtime-6.0.33-win-x64.exeC:\Users\admin\AppData\Local\Temp\{72F4BB34-04D7-4F8A-AAF6-5F37138EDF1E}\.ba\1029\thm.wxlxml
MD5:27411946EF45B3B8236319421770E5AD
SHA256:C92D3EFD72D6D14148F9931128EE4143AFFD1DA517EB358AB88ED4138C1434A4
4472windowsdesktop-runtime-6.0.33-win-x64.exeC:\Users\admin\AppData\Local\Temp\{72F4BB34-04D7-4F8A-AAF6-5F37138EDF1E}\.ba\1028\thm.wxlxml
MD5:B9428C94444693B5E3A392C8D0B95170
SHA256:C0413EDFD13FD27EEAB7B8CE60963668236466C48F4173C29F84093011C281AF
4472windowsdesktop-runtime-6.0.33-win-x64.exeC:\Users\admin\AppData\Local\Temp\{72F4BB34-04D7-4F8A-AAF6-5F37138EDF1E}\.ba\bg.pngimage
MD5:9EB0320DFBF2BD541E6A55C01DDC9F20
SHA256:9095BF7B6BAA0107B40A4A6D727215BE077133A190F4CA9BD89A176842141E79
4472windowsdesktop-runtime-6.0.33-win-x64.exeC:\Users\admin\AppData\Local\Temp\{72F4BB34-04D7-4F8A-AAF6-5F37138EDF1E}\.ba\1036\thm.wxlxml
MD5:9F779700FF90DF7211AE3A3340DDD5FC
SHA256:6AF5C2BC88B1E5CE188A97DD9204061D66369EC2689B3657AFF1DC6188F44F22
4472windowsdesktop-runtime-6.0.33-win-x64.exeC:\Users\admin\AppData\Local\Temp\{72F4BB34-04D7-4F8A-AAF6-5F37138EDF1E}\dotnet_runtime_6.0.33_win_x64.msi
MD5:
SHA256:
4472windowsdesktop-runtime-6.0.33-win-x64.exeC:\Users\admin\AppData\Local\Temp\{72F4BB34-04D7-4F8A-AAF6-5F37138EDF1E}\.ba\1033\thm.wxlxml
MD5:D5070CB3387A0A22B7046AE5AB53F371
SHA256:81A68046B06E09385BE8449373E7CEB9E79F7724C3CF11F0B18A4489A8D4926A
4472windowsdesktop-runtime-6.0.33-win-x64.exeC:\Users\admin\AppData\Local\Temp\{72F4BB34-04D7-4F8A-AAF6-5F37138EDF1E}\.ba\1031\thm.wxlxml
MD5:B45249A2238A5568B377E58D4CE89E9A
SHA256:0C4203A81DCD01D53378036AF78CFFCF9E9A5AF7754DFBDD56584AE74C21CC61
4472windowsdesktop-runtime-6.0.33-win-x64.exeC:\Users\admin\AppData\Local\Temp\{72F4BB34-04D7-4F8A-AAF6-5F37138EDF1E}\windowsdesktop_runtime_6.0.33_win_x64.msi
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
24
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2120
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6868
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4668
msiexec.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
239.255.255.250:1900
whitelisted
2120
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
6868
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4668
msiexec.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
6868
svchost.exe
13.71.55.58:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IN
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 13.71.55.58
whitelisted
google.com
  • 172.217.18.14
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted

Threats

No threats detected
No debug info