File name:

Gw2.exe

Full analysis: https://app.any.run/tasks/0bbc9b1f-0dfc-4fc5-ac7d-1f11ca396b05
Verdict: Malicious activity
Analysis date: May 09, 2025, 15:48:42
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
ip-check
meshagent
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 7 sections
MD5:

D071F3F9506BA1F12D5078F5992EC02E

SHA1:

CF211E4DDD08EC336E5EA90F65CC899848E06621

SHA256:

74575E17A65BD5DF2E95847917B7583F1C569D8643551099366EECBAD78BE472

SSDEEP:

98304:W6Y8sn56TzzSnEBABGwR5toVGx137dGG3WiLE4ROBvz78kFwOj+klDnxhLypN7qd:Wd3sdv83pOeiGm+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Connects to unusual port

      • Gw2.exe (PID: 3784)
    • Reads security settings of Internet Explorer

      • GameBar.exe (PID: 4812)
    • There is functionality for capture public ip (YARA)

      • Gw2.exe (PID: 3784)
    • The process creates files with name similar to system file names

      • Gw2.exe (PID: 3784)
    • MeshAgent potential remote access (YARA)

      • Gw2.exe (PID: 3784)
    • Process drops legitimate windows executable

      • Gw2.exe (PID: 3784)
    • Executable content was dropped or overwritten

      • Gw2.exe (PID: 3784)
  • INFO

    • Reads the computer name

      • Gw2.exe (PID: 3784)
      • GameBar.exe (PID: 4812)
      • CefHost.exe (PID: 4212)
      • CefHost.exe (PID: 1512)
    • Checks supported languages

      • Gw2.exe (PID: 3784)
      • GameBar.exe (PID: 4812)
      • CefHost.exe (PID: 4212)
      • CefHost.exe (PID: 1168)
      • CefHost.exe (PID: 1512)
      • CefHost.exe (PID: 3268)
      • CefHost.exe (PID: 4740)
    • Creates files or folders in the user directory

      • Gw2.exe (PID: 3784)
    • The sample compiled with english language support

      • Gw2.exe (PID: 3784)
    • Checks proxy server information

      • slui.exe (PID: 6516)
      • Gw2.exe (PID: 3784)
    • Reads the software policy settings

      • slui.exe (PID: 6516)
      • Gw2.exe (PID: 3784)
    • Create files in a temporary directory

      • Gw2.exe (PID: 3784)
      • CefHost.exe (PID: 1512)
    • Process checks computer location settings

      • CefHost.exe (PID: 3268)
      • Gw2.exe (PID: 3784)
      • CefHost.exe (PID: 4740)
    • Reads the machine GUID from the registry

      • Gw2.exe (PID: 3784)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:05:08 19:40:19+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.43
CodeSize: 26095104
InitializedDataSize: 19968000
UninitializedDataSize: -
EntryPoint: 0xe32198
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.1
ProductVersionNumber: 1.0.0.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: ArenaNet
FileVersion: 1, 0, 0, 1
FileDescription: Guild Wars 2 Game Client
LegalCopyright: © 2012-2025 ArenaNet, LLC
ProductName: Guild Wars 2
ProductVersion: 1, 0, 0, 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
127
Monitored processes
9
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #MESHAGENT gw2.exe gamebarpresencewriter.exe no specs gamebar.exe no specs slui.exe cefhost.exe no specs cefhost.exe no specs cefhost.exe cefhost.exe no specs cefhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
904"C:\Windows\System32\GameBarPresenceWriter.exe" -ServerName:Windows.Gaming.GameBar.Internal.PresenceWriterServerC:\Windows\System32\GameBarPresenceWriter.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Gamebar Presence Writer
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\gamebarpresencewriter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
1168"C:\Users\admin\Desktop\bin64\cef\CefHost.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=utility --no-sandbox --locales-dir-path="C:\Users\admin\Desktop\bin64\cef" --log-severity=warning --lang=en-US --user-data-dir="C:\Users\admin\AppData\Local\Temp\gw2cache-{0464A8C1-5BE0-2DCE-C2A8-6404E05BCE2D}\user" --log-file="C:\Users\admin\Desktop\debug.log" --mojo-platform-channel-handle=4024 --field-trial-handle=4308,i,11712388068476396692,7466318370090425523,131072 --disable-features=CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8C:\Users\admin\Desktop\bin64\cef\CefHost.exeGw2.exe
User:
admin
Company:
ArenaNet LLC
Integrity Level:
MEDIUM
Description:
Chromium Embedded Framework Host for Guild Wars 2
Version:
1.0.0.2
Modules
Images
c:\users\admin\desktop\bin64\cef\cefhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
1512"C:\Users\admin\Desktop\bin64\cef\CefHost.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-sandbox --locales-dir-path="C:\Users\admin\Desktop\bin64\cef" --log-severity=warning --lang=en-US --user-data-dir="C:\Users\admin\AppData\Local\Temp\gw2cache-{0464A8C1-5BE0-2DCE-C2A8-6404E05BCE2D}\user" --log-file="C:\Users\admin\Desktop\debug.log" --mojo-platform-channel-handle=5852 --field-trial-handle=4308,i,11712388068476396692,7466318370090425523,131072 --disable-features=CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8C:\Users\admin\Desktop\bin64\cef\CefHost.exe
Gw2.exe
User:
admin
Company:
ArenaNet LLC
Integrity Level:
MEDIUM
Description:
Chromium Embedded Framework Host for Guild Wars 2
Version:
1.0.0.2
Modules
Images
c:\users\admin\desktop\bin64\cef\cefhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
3268"C:\Users\admin\Desktop\bin64\cef\CefHost.exe" --type=renderer --locales-dir-path="C:\Users\admin\Desktop\bin64\cef" --log-severity=warning --user-data-dir="C:\Users\admin\AppData\Local\Temp\gw2cache-{0464A8C1-5BE0-2DCE-C2A8-6404E05BCE2D}\user" --no-sandbox --log-file="C:\Users\admin\Desktop\debug.log" --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3924 --field-trial-handle=4308,i,11712388068476396692,7466318370090425523,131072 --disable-features=CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:1C:\Users\admin\Desktop\bin64\cef\CefHost.exeGw2.exe
User:
admin
Company:
ArenaNet LLC
Integrity Level:
MEDIUM
Description:
Chromium Embedded Framework Host for Guild Wars 2
Version:
1.0.0.2
Modules
Images
c:\users\admin\desktop\bin64\cef\cefhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
3784"C:\Users\admin\Desktop\Gw2.exe" C:\Users\admin\Desktop\Gw2.exe
explorer.exe
User:
admin
Company:
ArenaNet
Integrity Level:
MEDIUM
Description:
Guild Wars 2 Game Client
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\gw2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4212"C:\Users\admin\Desktop\bin64\cef\CefHost.exe" --type=gpu-process --no-sandbox --locales-dir-path="C:\Users\admin\Desktop\bin64\cef" --log-severity=warning --lang=en-US --user-data-dir="C:\Users\admin\AppData\Local\Temp\gw2cache-{0464A8C1-5BE0-2DCE-C2A8-6404E05BCE2D}\user" --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --log-file="C:\Users\admin\Desktop\debug.log" --mojo-platform-channel-handle=4392 --field-trial-handle=4308,i,11712388068476396692,7466318370090425523,131072 --disable-features=CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:2C:\Users\admin\Desktop\bin64\cef\CefHost.exeGw2.exe
User:
admin
Company:
ArenaNet LLC
Integrity Level:
MEDIUM
Description:
Chromium Embedded Framework Host for Guild Wars 2
Version:
1.0.0.2
Modules
Images
c:\users\admin\desktop\bin64\cef\cefhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4740"C:\Users\admin\Desktop\bin64\cef\CefHost.exe" --type=renderer --locales-dir-path="C:\Users\admin\Desktop\bin64\cef" --log-severity=warning --user-data-dir="C:\Users\admin\AppData\Local\Temp\gw2cache-{0464A8C1-5BE0-2DCE-C2A8-6404E05BCE2D}\user" --no-sandbox --log-file="C:\Users\admin\Desktop\debug.log" --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=3932 --field-trial-handle=4308,i,11712388068476396692,7466318370090425523,131072 --disable-features=CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:1C:\Users\admin\Desktop\bin64\cef\CefHost.exeGw2.exe
User:
admin
Company:
ArenaNet LLC
Integrity Level:
MEDIUM
Description:
Chromium Embedded Framework Host for Guild Wars 2
Version:
1.0.0.2
Modules
Images
c:\users\admin\desktop\bin64\cef\cefhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4812"C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exe" -ServerName:App.AppXbdkk0yrkwpcgeaem8zk81k8py1eaahny.mcaC:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_2.34.28001.0_x64__8wekyb3d8bbwe\GameBar.exesvchost.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\program files\windowsapps\microsoft.xboxgamingoverlay_2.34.28001.0_x64__8wekyb3d8bbwe\gamebar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\vccorlib140_app.dll
c:\windows\system32\oleaut32.dll
c:\program files\windowsapps\microsoft.vclibs.140.00_14.0.27323.0_x64__8wekyb3d8bbwe\msvcp140_app.dll
6516C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
8 398
Read events
8 391
Write events
7
Delete events
0

Modification events

(PID) Process:(4812) GameBar.exeKey:\REGISTRY\A\{307d0908-713b-1c65-0e87-8b601e55c4f6}\LocalState
Operation:writeName:InstalledVersionMajor
Value:
0200B4EEDDE7F9C0DB01
(PID) Process:(4812) GameBar.exeKey:\REGISTRY\A\{307d0908-713b-1c65-0e87-8b601e55c4f6}\LocalState
Operation:writeName:InstalledVersionMinor
Value:
2200953DDEE7F9C0DB01
(PID) Process:(4812) GameBar.exeKey:\REGISTRY\A\{307d0908-713b-1c65-0e87-8b601e55c4f6}\LocalState
Operation:writeName:InstalledVersionBuild
Value:
616D953DDEE7F9C0DB01
(PID) Process:(4812) GameBar.exeKey:\REGISTRY\A\{307d0908-713b-1c65-0e87-8b601e55c4f6}\LocalState
Operation:writeName:InstalledVersionRevision
Value:
0000953DDEE7F9C0DB01
(PID) Process:(4812) GameBar.exeKey:\REGISTRY\A\{307d0908-713b-1c65-0e87-8b601e55c4f6}\LocalState
Operation:writeName:PreviousAppTerminationFromSuspended
Value:
00953DDEE7F9C0DB01
(PID) Process:(4812) GameBar.exeKey:\REGISTRY\A\{307d0908-713b-1c65-0e87-8b601e55c4f6}\LocalState
Operation:writeName:CurrentDisplayMonitor
Value:
670061006D0065000000C6A9E1E7F9C0DB01
(PID) Process:(4812) GameBar.exeKey:\REGISTRY\A\{307d0908-713b-1c65-0e87-8b601e55c4f6}\LocalState
Operation:writeName:StartupTipIndex
Value:
0100000000000000146CF0E7F9C0DB01
Executable files
7
Suspicious files
40
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
3784Gw2.exeC:\Users\admin\Desktop\Gw2.tmp
MD5:
SHA256:
3784Gw2.exeC:\Users\admin\Desktop\Gw2.dat
MD5:
SHA256:
3784Gw2.exeC:\Users\admin\Desktop\bin64\cef\libcef.dll
MD5:
SHA256:
3784Gw2.exeC:\Users\admin\Desktop\bin64\cef\icudtl.dat
MD5:
SHA256:
3784Gw2.exeC:\Users\admin\Desktop\bin64\cef\resources.pak
MD5:
SHA256:
3784Gw2.exeC:\Users\admin\AppData\Roaming\Guild Wars 2\Local.datbinary
MD5:289B6814D278BBE646FB178561080F85
SHA256:5E1F47307D31C5B4EAE48CEF2D35F69112F2634532552DD4A4ADBFD94F32E198
3784Gw2.exeC:\Users\admin\Desktop\THIRDPARTYSOFTWAREREADME.txttext
MD5:3DEC45B73B7607D43A6AD0202BEA1839
SHA256:5B0F595845CEB29464BA90C5B690D6778BC2459BBF7D3650CEDE680817F41B86
3784Gw2.exeC:\Users\admin\Desktop\bin64\cef\CefHost.exeexecutable
MD5:B67DA5E1A2DCF07F14FB67F6CAE05AE5
SHA256:02043EEB2373A4B4631DA31C89A3E5EDF7F96514FDE271DB1485E7618D75CF6C
3784Gw2.exeC:\Users\admin\Desktop\bin64\cef\chrome_elf.dllexecutable
MD5:C1E27CA059CAC0F223960341515C4F72
SHA256:B891991659D3AFBB6B6FCC12F76D23A1011E6E4F66F9CB6C579A659706A8C3FD
3784Gw2.exeC:\Users\admin\Desktop\bin64\cef\chrome_200_percent.pakbinary
MD5:4DD3BE4AD499D1A60DDEDF1926D7364B
SHA256:8910DC19346C452AC21CE4E4435DB5EE9541FF4D86AFCE62D26AC5872067FF38
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3 394
TCP/UDP connections
64
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3784
Gw2.exe
GET
200
18.66.137.226:80
http://assetcdn.101.ArenaNetworks.com/program/101/1/0/3626096/compressed
unknown
unknown
3784
Gw2.exe
GET
200
18.66.137.226:80
http://assetcdn.101.ArenaNetworks.com/program/101/1/0/3625804/compressed
unknown
unknown
2104
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3784
Gw2.exe
GET
200
18.66.137.226:80
http://assetcdn.101.ArenaNetworks.com/latest64/101
unknown
unknown
2104
svchost.exe
GET
200
2.19.11.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
3784
Gw2.exe
GET
200
18.66.137.226:80
http://assetcdn.101.ArenaNetworks.com/program/101/1/0/3625807/compressed
unknown
unknown
3784
Gw2.exe
GET
200
18.66.137.226:80
http://assetcdn.101.ArenaNetworks.com/program/101/1/0/3625805/compressed
unknown
unknown
3784
Gw2.exe
GET
200
18.66.137.226:80
http://assetcdn.101.ArenaNetworks.com/program/101/1/0/3625806/compressed
unknown
unknown
3784
Gw2.exe
GET
200
18.66.137.226:80
http://assetcdn.101.ArenaNetworks.com/program/101/1/0/3625809/compressed
unknown
unknown
3784
Gw2.exe
GET
200
18.66.137.226:80
http://assetcdn.101.ArenaNetworks.com/program/101/1/0/3625811/compressed
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2104
svchost.exe
2.19.11.120:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
2104
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
3784
Gw2.exe
18.66.137.226:80
assetcdn.101.ArenaNetworks.com
AMAZON-02
US
unknown
3784
Gw2.exe
18.184.118.144:6112
cligate.101.ncplatform.net
AMAZON-02
DE
unknown
3100
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6516
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1512
CefHost.exe
99.86.4.78:443
a.cdn.ua.ncsoft.com
AMAZON-02
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
google.com
  • 142.250.184.238
whitelisted
crl.microsoft.com
  • 2.19.11.120
  • 2.19.11.105
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
assetcdn.101.ArenaNetworks.com
  • 18.66.137.226
  • 18.66.137.82
  • 18.66.137.100
  • 18.66.137.106
unknown
cligate.101.ncplatform.net
  • 18.184.132.250
  • 18.196.209.108
  • 18.185.197.21
  • 3.121.82.222
  • 3.64.34.254
  • 18.184.118.144
unknown
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted
a.cdn.ua.ncsoft.com
  • 99.86.4.78
  • 99.86.4.82
  • 99.86.4.55
  • 99.86.4.90
whitelisted
gemstore-live.ncplatform.net
  • 52.57.89.168
  • 18.185.44.231
unknown
cms-live.ncplatform.net
  • 52.57.89.168
  • 18.185.44.231
unknown

Threats

No threats detected
No debug info