File name:

MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe

Full analysis: https://app.any.run/tasks/d6f523e2-8566-47f4-9913-e39471a06ec3
Verdict: Malicious activity
Analysis date: February 11, 2025, 20:41:33
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
advancedinstaller
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

060EF13B53A591137F4CC702803F3707

SHA1:

5CBEE39DE6198C9E4CB84D890DA74CFE8B35BD06

SHA256:

7085EDA03BE0270EE47B9BA2109EE2980B8179685C99589009D6FB47879B064C

SSDEEP:

98304:5ayfnIwx5xsHTovMiZkGYoGUVEE8IQW8Hm/e6lpXp1GQaPD+pDcJzRj6C3JJThX6:gBHmq0L24

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • ADVANCEDINSTALLER mutex has been found

      • MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe (PID: 6392)
    • Executable content was dropped or overwritten

      • MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe (PID: 6392)
    • Reads the Windows owner or organization settings

      • MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe (PID: 6392)
      • msiexec.exe (PID: 6572)
    • Process drops legitimate windows executable

      • MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe (PID: 6392)
    • There is functionality for taking screenshot (YARA)

      • MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe (PID: 6392)
    • Executes as Windows Service

      • VSSVC.exe (PID: 5712)
  • INFO

    • The sample compiled with english language support

      • MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe (PID: 6392)
      • msiexec.exe (PID: 6668)
      • msiexec.exe (PID: 6572)
    • Checks supported languages

      • MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe (PID: 6392)
      • msiexec.exe (PID: 6624)
      • msiexec.exe (PID: 6768)
      • msiexec.exe (PID: 6572)
      • msiexec.exe (PID: 2676)
    • Reads Environment values

      • MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe (PID: 6392)
      • msiexec.exe (PID: 6768)
    • Creates files or folders in the user directory

      • MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe (PID: 6392)
    • Reads the computer name

      • MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe (PID: 6392)
      • msiexec.exe (PID: 6572)
      • msiexec.exe (PID: 6624)
      • msiexec.exe (PID: 6768)
    • Create files in a temporary directory

      • MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe (PID: 6392)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 6668)
      • msiexec.exe (PID: 6572)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 6572)
    • Manages system restore points

      • SrTasks.exe (PID: 5788)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:08:30 14:59:22+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 1588224
InitializedDataSize: 610304
UninitializedDataSize: -
EntryPoint: 0x12c431
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 0.10.0.0
ProductVersionNumber: 0.10.0.0
FileFlagsMask: 0x003f
FileFlags: Debug
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: maxon.net
FileDescription: MAXON Cinema R25.010 fixer [MONTER GROUP©] Installer
FileVersion: 0.1
InternalName: MAXON Cinema R25.010 fixer [MONTER GROUP©]
LegalCopyright: Copyright (C) 2021 maxon.net
OriginalFileName: MAXON Cinema R25.010 fixer [MONTER GROUP©].exe
ProductName: MAXON Cinema R25.010 fixer [MONTER GROUP©]
ProductVersion: 0.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
10
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start maxon cinema 4d r25_010 fixer [monter group©].exe msiexec.exe msiexec.exe no specs msiexec.exe msiexec.exe no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs maxon cinema 4d r25_010 fixer [monter group©].exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2676C:\Windows\syswow64\MsiExec.exe -Embedding D2B5028CB01EF5D518B76BCF8CDDD728C:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
5588\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5712C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5788C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6216"C:\Users\admin\AppData\Local\Temp\MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe" C:\Users\admin\AppData\Local\Temp\MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exeexplorer.exe
User:
admin
Company:
maxon.net
Integrity Level:
MEDIUM
Description:
MAXON Cinema R25.010 fixer [MONTER GROUP©] Installer
Exit code:
3221226540
Version:
0.10
Modules
Images
c:\users\admin\appdata\local\temp\maxon cinema 4d r25_010 fixer [monter group©].exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6392"C:\Users\admin\AppData\Local\Temp\MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe" C:\Users\admin\AppData\Local\Temp\MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe
explorer.exe
User:
admin
Company:
maxon.net
Integrity Level:
HIGH
Description:
MAXON Cinema R25.010 fixer [MONTER GROUP©] Installer
Exit code:
0
Version:
0.10
Modules
Images
c:\users\admin\appdata\local\temp\maxon cinema 4d r25_010 fixer [monter group©].exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6572C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6624C:\Windows\syswow64\MsiExec.exe -Embedding 275C2F005459DD690C3410696517DA59 CC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6668"C:\WINDOWS\system32\msiexec.exe" /i "C:\Users\admin\AppData\Roaming\maxon.net\MAXON Cinema R25.010 fixer [MONTER GROUP©] 0.10\install\61704E9\MAXON Cinema R25.010 fixer [MG©].msi" AI_SETUPEXEPATH="C:\Users\admin\AppData\Local\Temp\MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe" SETUPEXEDIR=C:\Users\admin\AppData\Local\Temp\ EXE_CMD_LINE="/exenoupdates /forcecleanup /wintime 1739305232 " C:\Windows\SysWOW64\msiexec.exe
MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6768C:\Windows\syswow64\MsiExec.exe -Embedding 4EF35FA9197C40E574CE23EE0AD6B647 CC:\Windows\SysWOW64\msiexec.exemsiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
3 294
Read events
3 016
Write events
261
Delete events
17

Modification events

(PID) Process:(6668) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Volatile\00\MACHINE\SOFTWARE\Classes\Interface\{03022430-ABC4-11D0-BDE2-00AA001A1953}\TypeLib
Operation:writeName:Version
Value:
1.1
(PID) Process:(6668) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}\TypeLib
Operation:writeName:Version
Value:
1.1
(PID) Process:(6668) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}\TypeLib
Operation:writeName:Version
Value:
1.1
(PID) Process:(6668) msiexec.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Volatile\00\MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{03022430-ABC4-11D0-BDE2-00AA001A1953}\TypeLib
Operation:writeName:Version
Value:
1.1
(PID) Process:(6572) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
48000000000000000967F95EC57CDB01AC190000C0150000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6572) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
48000000000000000967F95EC57CDB01AC190000C0150000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6572) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
480000000000000012CAFB5EC57CDB01AC190000C0150000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6572) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
48000000000000004491005FC57CDB01AC190000C0150000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6572) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4800000000000000C998C25EC57CDB01AC190000C0150000D50700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6572) msiexec.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
4800000000000000C998C25EC57CDB01AC190000C0150000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
16
Suspicious files
19
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
6572msiexec.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
6392MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exeC:\Users\admin\AppData\Local\Temp\MSI5F5A.tmpexecutable
MD5:07CE413B1AF6342187514871DC112C74
SHA256:0BA7E90FE2A0005E1E0DAD53E2678916650C3B95FF9B666B802D128276C8EC46
6668msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI623B.tmpexecutable
MD5:07CE413B1AF6342187514871DC112C74
SHA256:0BA7E90FE2A0005E1E0DAD53E2678916650C3B95FF9B666B802D128276C8EC46
6392MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exeC:\Users\admin\AppData\Roaming\maxon.net\MAXON Cinema R25.010 fixer [MONTER GROUP©] 0.10\install\61704E9\MAXON Cinema R25.010 fixer [MG©].msiexecutable
MD5:1D083FD4D8DBA5055742F7CF6EFC96FF
SHA256:C23A14772E44D1D0D1B01235542266392FAF4C4540919B9996723D55C203EE07
6392MAXON Cinema 4D R25_010 fixer [MONTER GROUP©].exeC:\Users\admin\AppData\Roaming\maxon.net\MAXON Cinema R25.010 fixer [MONTER GROUP©] 0.10\install\holder0.aiphbinary
MD5:A9E0F2D46A33155A1136A56BB66E6DE3
SHA256:E4DDD8A3CC0E72DF3C008BAAE0F0F5A38C1F80CBD0396C70684422126A480FE8
6572msiexec.exeC:\Windows\Installer\13ae44.msiexecutable
MD5:1D083FD4D8DBA5055742F7CF6EFC96FF
SHA256:C23A14772E44D1D0D1B01235542266392FAF4C4540919B9996723D55C203EE07
6668msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI610F.tmpexecutable
MD5:07CE413B1AF6342187514871DC112C74
SHA256:0BA7E90FE2A0005E1E0DAD53E2678916650C3B95FF9B666B802D128276C8EC46
6668msiexec.exeC:\Users\admin\AppData\Local\Temp\MSI6307.tmpexecutable
MD5:07CE413B1AF6342187514871DC112C74
SHA256:0BA7E90FE2A0005E1E0DAD53E2678916650C3B95FF9B666B802D128276C8EC46
6572msiexec.exeC:\System Volume Information\SPP\OnlineMetadataCache\{9afc15f6-50ad-4834-a766-b7fffe63bd8f}_OnDiskSnapshotPropbinary
MD5:3EB770DCB77F6AB6FC3E2BE04027D141
SHA256:A6316208995FA0D8726590E2D7040A497F972A5B7803E5FECCFE07231AB1118B
6572msiexec.exeC:\Windows\Installer\MSIB355.tmpexecutable
MD5:07CE413B1AF6342187514871DC112C74
SHA256:0BA7E90FE2A0005E1E0DAD53E2678916650C3B95FF9B666B802D128276C8EC46
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
32
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.19.11.105:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6460
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5872
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5872
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.19.11.105:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
5064
SearchApp.exe
2.19.96.120:443
www.bing.com
Akamai International B.V.
DE
whitelisted
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4308
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
20.190.160.5:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.18.14
whitelisted
crl.microsoft.com
  • 2.19.11.105
  • 2.19.11.120
whitelisted
www.microsoft.com
  • 23.219.150.101
  • 23.35.229.160
whitelisted
www.bing.com
  • 2.19.96.120
  • 2.19.96.66
  • 2.19.96.128
  • 2.19.96.90
  • 2.19.96.83
whitelisted
ocsp.digicert.com
  • 2.23.77.188
  • 2.17.190.73
whitelisted
login.live.com
  • 20.190.160.5
  • 20.190.160.130
  • 20.190.160.2
  • 20.190.160.4
  • 20.190.160.128
  • 40.126.32.133
  • 20.190.160.65
  • 40.126.32.74
whitelisted
go.microsoft.com
  • 2.18.97.227
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted

Threats

No threats detected
No debug info