File name:

action-replay-dsi-code-manager-pc-software (1).zip

Full analysis: https://app.any.run/tasks/b4599fad-7efe-4dcb-964e-7717497309e1
Verdict: Malicious activity
Analysis date: December 07, 2024, 18:23:43
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

7D6E49CBDEFAB832965156E58C018D22

SHA1:

432CB1D972513700ADA90DA529C5733A90C97D14

SHA256:

79C64ACB0F4841A0D59173BFBA6205C8BA33C1086F08EC587AFBC22EBDBD564F

SSDEEP:

98304:Gd39U5Pxy07UZ8xOn+ZImKfiWbX8ct7BkKPPnJcrH/Owz2CJRGrO2+Xgk6XFWrM3:Nrkfud27jQrjyhNqDQO6agCMf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6536)
    • Executing a file with an untrusted certificate

      • WindowsInstaller-KB893803-v2-x86.exe (PID: 6364)
      • update.exe (PID: 6304)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 6536)
      • ActionReplayDsiCodeManagerSetup.tmp (PID: 6944)
    • Executable content was dropped or overwritten

      • ActionReplayDsiCodeManagerSetup.exe (PID: 6924)
      • ActionReplayDsiCodeManagerSetup.exe (PID: 7028)
      • ActionReplayDsiCodeManagerSetup.tmp (PID: 7084)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 6364)
      • dpinst64.exe (PID: 712)
      • TiWorker.exe (PID: 4188)
      • drvinst.exe (PID: 628)
    • Process drops legitimate windows executable

      • ActionReplayDsiCodeManagerSetup.tmp (PID: 7084)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 6364)
      • msiexec.exe (PID: 4504)
      • TiWorker.exe (PID: 4188)
      • dpinst64.exe (PID: 712)
    • The process drops C-runtime libraries

      • ActionReplayDsiCodeManagerSetup.tmp (PID: 7084)
    • Drops a system driver (possible attempt to evade defenses)

      • ActionReplayDsiCodeManagerSetup.tmp (PID: 7084)
      • dpinst64.exe (PID: 712)
      • drvinst.exe (PID: 628)
    • Executes as Windows Service

      • VSSVC.exe (PID: 5972)
    • Start notepad (likely ransomware note)

      • ActionReplayDsiCodeManagerSetup.tmp (PID: 6944)
  • INFO

    • Create files in a temporary directory

      • ActionReplayDsiCodeManagerSetup.exe (PID: 6924)
    • Checks supported languages

      • ActionReplayDsiCodeManagerSetup.exe (PID: 6924)
      • ActionReplayDsiCodeManagerSetup.tmp (PID: 6944)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6536)
      • msiexec.exe (PID: 4504)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 6536)
    • Reads the computer name

      • ActionReplayDsiCodeManagerSetup.tmp (PID: 6944)
    • Process checks computer location settings

      • ActionReplayDsiCodeManagerSetup.tmp (PID: 6944)
    • Manages system restore points

      • SrTasks.exe (PID: 1480)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2014:03:24 13:41:12
ZipCRC: 0xa5fc7fa4
ZipCompressedSize: 12217246
ZipUncompressedSize: 12300838
ZipFileName: ActionReplayDsiCodeManagerSetup.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
19
Malicious processes
6
Suspicious processes
3

Behavior graph

Click at the process to see the details
start winrar.exe actionreplaydsicodemanagersetup.exe actionreplaydsicodemanagersetup.tmp no specs actionreplaydsicodemanagersetup.exe actionreplaydsicodemanagersetup.tmp windowsinstaller-kb893803-v2-x86.exe update.exe no specs msiexec.exe no specs msiexec.exe vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs tiworker.exe dpinst64.exe drvinst.exe no specs rundll32.exe no specs drvinst.exe notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
628DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{626ad08f-a174-ce44-bb71-888b42c94d64}\dsiarhwprog_x64.inf" "9" "4bbefcc3b" "00000000000001FC" "WinSta0\Default" "0000000000000200" "208" "c:\program files (x86)\datel\action replay dsi code manager\driver"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
712"C:\Program Files (x86)\Datel\Action Replay DSi Code Manager\Driver\dpinst64.exe"C:\Program Files (x86)\Datel\Action Replay DSi Code Manager\driver\dpinst64.exe
ActionReplayDsiCodeManagerSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
512
Version:
2.1
Modules
Images
c:\program files (x86)\datel\action replay dsi code manager\driver\dpinst64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1480C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11C:\Windows\System32\SrTasks.exemsiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Windows System Protection background tasks.
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\srtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1520\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSrTasks.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4188C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exe -EmbeddingC:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Modules Installer Worker
Version:
10.0.19041.3989 (WinBuild.160101.0800)
Modules
Images
c:\windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\tiworker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
4504C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5972C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6224"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Documents\Datel\Action Replay DSi Code Manager\Readme.txtC:\Windows\SysWOW64\notepad.exeActionReplayDsiCodeManagerSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\gdi32.dll
c:\windows\syswow64\win32u.dll
6284"msiexec.exe" /quiet /passive /norestart /package "C:\Program Files (x86)\Datel\Action Replay DSi Code Manager\msxml.msi"C:\Windows\System32\msiexec.exeActionReplayDsiCodeManagerSetup.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6304c:\3abeddf3ca7b60732b2196\UPDATE\update.exe /quiet /norestartC:\3abeddf3ca7b60732b2196\update\update.exeWindowsInstaller-KB893803-v2-x86.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Service Pack Setup
Exit code:
1603
Version:
6.1.0022.4 (SRV03_QFE.031113-0918)
Modules
Images
c:\3abeddf3ca7b60732b2196\update\update.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
20 790
Read events
20 373
Write events
376
Delete events
41

Modification events

(PID) Process:(6536) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6536) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6536) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6536) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\action-replay-dsi-code-manager-pc-software (1).zip
(PID) Process:(6536) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6536) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6536) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6536) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7084) ActionReplayDsiCodeManagerSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Action Replay DSi Code Manager_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.3 (u)
(PID) Process:(7084) ActionReplayDsiCodeManagerSetup.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Action Replay DSi Code Manager_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files (x86)\Datel\Action Replay DSi Code Manager
Executable files
55
Suspicious files
55
Text files
33
Unknown types
6

Dropped files

PID
Process
Filename
Type
7084ActionReplayDsiCodeManagerSetup.tmpC:\Users\admin\Documents\Datel\Action Replay DSi Code Manager\local_codelists\is-R47CV.tmp
MD5:
SHA256:
7084ActionReplayDsiCodeManagerSetup.tmpC:\Users\admin\Documents\Datel\Action Replay DSi Code Manager\local_codelists\Default Codelist EU.xml
MD5:
SHA256:
7028ActionReplayDsiCodeManagerSetup.exeC:\Users\admin\AppData\Local\Temp\is-00QUN.tmp\ActionReplayDsiCodeManagerSetup.tmpexecutable
MD5:05D1574E130DAB0179C29DB99CE920A9
SHA256:6C8EA99189DB9141ADAAD1FF75945B8861C34FA764EB5342AEA582C9220C6961
7084ActionReplayDsiCodeManagerSetup.tmpC:\Users\admin\AppData\Local\Temp\is-G2GFV.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
6536WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6536.14654\ActionReplayDsiCodeManagerSetup.exeexecutable
MD5:520F49FE9BA11CA5DA356FB997DA5869
SHA256:F98E072E2FC34B8F2C79A529A867E56D26A59ED7024314611DB19DCF17ED78F5
7084ActionReplayDsiCodeManagerSetup.tmpC:\Program Files (x86)\Datel\Action Replay DSi Code Manager\ActionReplayCodeManager.exeexecutable
MD5:2E9034F2810F2EE22C95771949AF9345
SHA256:2C12D2F8AE741950F967E3AF836A9554D518B167E6B4AAB26F6AC4F5C4758738
7084ActionReplayDsiCodeManagerSetup.tmpC:\Program Files (x86)\Datel\Action Replay DSi Code Manager\is-IB78E.tmpexecutable
MD5:2E9034F2810F2EE22C95771949AF9345
SHA256:2C12D2F8AE741950F967E3AF836A9554D518B167E6B4AAB26F6AC4F5C4758738
7084ActionReplayDsiCodeManagerSetup.tmpC:\Users\admin\AppData\Local\Temp\is-G2GFV.tmp\_isetup\_setup64.tmpexecutable
MD5:C8871EFD8AF2CF4D9D42D1FF8FADBF89
SHA256:E4FC574A01B272C2D0AED0EC813F6D75212E2A15A5F5C417129DD65D69768F40
7084ActionReplayDsiCodeManagerSetup.tmpC:\Users\admin\Documents\Datel\Action Replay DSi Code Manager\local_codelists\Default Codelist US.xmlxml
MD5:5C228392C056BAA49850C1119F0836CA
SHA256:607EFB4098248DB49BA2E2EB4F562F45082B50E790E6C16534A892E74617406D
6924ActionReplayDsiCodeManagerSetup.exeC:\Users\admin\AppData\Local\Temp\is-HLLRK.tmp\ActionReplayDsiCodeManagerSetup.tmpexecutable
MD5:05D1574E130DAB0179C29DB99CE920A9
SHA256:6C8EA99189DB9141ADAAD1FF75945B8861C34FA764EB5342AEA582C9220C6961
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
35
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.194:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.194:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3772
SIHClient.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3772
SIHClient.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4504
msiexec.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/CodeSignPCA.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.48.23.194:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.194:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
23.37.237.227:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
23.37.237.227:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
2.16.204.145:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
40.126.31.69:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.48.23.194
  • 23.48.23.164
  • 23.48.23.166
  • 23.48.23.145
  • 23.48.23.167
  • 23.48.23.143
  • 23.48.23.177
  • 23.48.23.176
  • 23.48.23.173
whitelisted
google.com
  • 142.250.185.78
whitelisted
www.microsoft.com
  • 23.37.237.227
whitelisted
www.bing.com
  • 2.16.204.145
  • 2.16.204.158
  • 2.16.204.152
  • 2.16.204.150
  • 2.16.204.157
  • 2.16.204.142
  • 2.16.204.149
  • 2.16.204.146
  • 2.16.204.155
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.31.69
  • 20.190.159.2
  • 20.190.159.71
  • 20.190.159.68
  • 20.190.159.75
  • 20.190.159.23
  • 20.190.159.64
  • 40.126.31.73
whitelisted
go.microsoft.com
  • 23.218.210.69
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted

Threats

No threats detected
No debug info