File name:

Windows.Manager.v2.0.2.0.exe

Full analysis: https://app.any.run/tasks/e8143864-5bdf-4178-94a2-df48218a1c71
Verdict: Malicious activity
Analysis date: July 25, 2024, 11:39:42
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

C009E6D77AF3D5D62B0F463D6F646FFA

SHA1:

D82957367A9FAA45BC3C830D3E1767BDF59F45FB

SHA256:

83553D2F129710BE83E1824C6D9AAED277C25226DE2CAABB353B21DE550ADDB2

SSDEEP:

98304:WQX2ieTw+Cy0+UmTh0SnirimsJgnm1Cqsweg5ze4ggZ4O/0j6K1lsuqJvoDFtHsQ:6gUACgHVl+2vHXl9jpuadb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Modifies hosts file to block updates

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
    • Drops the executable file immediately after the start

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
    • Executable content was dropped or overwritten

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
    • Uses NETSH.EXE to delete a firewall rule or allowed programs

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
    • The process creates files with name similar to system file names

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
    • Creates a software uninstall entry

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
    • Reads security settings of Internet Explorer

      • WindowsManager.exe (PID: 8188)
      • LiveUpdate.exe (PID: 7480)
    • Reads the date of Windows installation

      • WindowsManager.exe (PID: 8188)
  • INFO

    • Reads the computer name

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
      • TextInputHost.exe (PID: 6600)
      • WindowsManager.exe (PID: 8188)
      • LiveUpdate.exe (PID: 7480)
      • DiskAnalyzer.exe (PID: 6324)
    • Checks supported languages

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
      • TextInputHost.exe (PID: 6600)
      • LiveUpdate.exe (PID: 7480)
      • DiskAnalyzer.exe (PID: 6324)
      • WindowsManager.exe (PID: 8188)
    • Create files in a temporary directory

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
    • Creates files in the program directory

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
      • DiskAnalyzer.exe (PID: 6324)
    • Application launched itself

      • firefox.exe (PID: 4516)
      • firefox.exe (PID: 4632)
    • Manual execution by a user

      • firefox.exe (PID: 4516)
    • Reads Microsoft Office registry keys

      • firefox.exe (PID: 4632)
    • Creates files or folders in the user directory

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
    • Reads the machine GUID from the registry

      • WindowsManager.exe (PID: 8188)
      • LiveUpdate.exe (PID: 7480)
      • DiskAnalyzer.exe (PID: 6324)
    • Disables trace logs

      • WindowsManager.exe (PID: 8188)
      • LiveUpdate.exe (PID: 7480)
    • Process checks computer location settings

      • WindowsManager.exe (PID: 8188)
    • Checks proxy server information

      • WindowsManager.exe (PID: 8188)
      • LiveUpdate.exe (PID: 7480)
    • Reads Environment values

      • LiveUpdate.exe (PID: 7480)
      • WindowsManager.exe (PID: 8188)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:30 16:56:02+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 412160
UninitializedDataSize: 16384
EntryPoint: 0x3665
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.0.2.0
ProductVersionNumber: 2.0.2.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: -
CompanyName: YamicSoft
FileDescription: Windows Manager v2.0.2.0
FileVersion: 2.0.2.0.0
LegalCopyright: © YamicSoft
ProductName: Windows Manager v2.0.2.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
156
Monitored processes
24
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start windows.manager.v2.0.2.0.exe slui.exe no specs firefox.exe no specs firefox.exe netsh.exe no specs conhost.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs textinputhost.exe no specs firefox.exe no specs netsh.exe no specs conhost.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs netsh.exe no specs conhost.exe no specs firefox.exe no specs windowsmanager.exe no specs liveupdate.exe diskanalyzer.exe no specs windows.manager.v2.0.2.0.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
540"C:\Users\admin\Downloads\Windows.Manager.v2.0.2.0.exe" C:\Users\admin\Downloads\Windows.Manager.v2.0.2.0.exe
explorer.exe
User:
admin
Company:
YamicSoft
Integrity Level:
HIGH
Description:
Windows Manager v2.0.2.0
Exit code:
0
Version:
2.0.2.0.0
Modules
Images
c:\users\admin\downloads\windows.manager.v2.0.2.0.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1000\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenetsh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1272"C:\Users\admin\Downloads\Windows.Manager.v2.0.2.0.exe" C:\Users\admin\Downloads\Windows.Manager.v2.0.2.0.exeexplorer.exe
User:
admin
Company:
YamicSoft
Integrity Level:
MEDIUM
Description:
Windows Manager v2.0.2.0
Exit code:
3221226540
Version:
2.0.2.0.0
Modules
Images
c:\users\admin\downloads\windows.manager.v2.0.2.0.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1552"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2284 -parentBuildID 20240213221259 -prefsHandle 1812 -prefMapHandle 2232 -prefsLen 30537 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {14b9395f-d462-4ce8-8d01-d0c9acfc46d8} 4632 "\\.\pipe\gecko-crash-server-pipe.4632" 1ebaa480b10 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1728netsh.exe advfirewall firewall delete rule name="Block WindowsManager"C:\Windows\SysWOW64\netsh.exeWindows.Manager.v2.0.2.0.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2196"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1896 -parentBuildID 20240213221259 -prefsHandle 1820 -prefMapHandle 1808 -prefsLen 30537 -prefMapSize 244343 -appDir "C:\Program Files\Mozilla Firefox\browser" - {759b3c26-af48-47a6-bc86-04da6a8b5a74} 4632 "\\.\pipe\gecko-crash-server-pipe.4632" 1ebb70e3f10 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
4016"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5768 -childID 5 -isForBrowser -prefsHandle 5776 -prefMapHandle 5780 -prefsLen 31154 -prefMapSize 244343 -jsInitHandle 1396 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {2fcecf57-9b01-422c-bd97-034e1daa990c} 4632 "\\.\pipe\gecko-crash-server-pipe.4632" 1ebc1bfe690 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
4020"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5592 -childID 4 -isForBrowser -prefsHandle 5428 -prefMapHandle 5548 -prefsLen 31154 -prefMapSize 244343 -jsInitHandle 1396 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {f4812952-06b6-44c4-8d8d-2fcff65c513c} 4632 "\\.\pipe\gecko-crash-server-pipe.4632" 1ebc1bfe4d0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
4516"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
4632"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
Total events
29 532
Read events
29 432
Write events
89
Delete events
11

Modification events

(PID) Process:(4516) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
4DBA47C800000000
(PID) Process:(4632) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
626648C800000000
(PID) Process:(4632) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Progress
Value:
0
(PID) Process:(540) Windows.Manager.v2.0.2.0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Windows Manager
Operation:writeName:DisplayName
Value:
Windows Manager
(PID) Process:(540) Windows.Manager.v2.0.2.0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Windows Manager
Operation:writeName:Publisher
Value:
YamicSoft
(PID) Process:(540) Windows.Manager.v2.0.2.0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Windows Manager
Operation:writeName:UninstallString
Value:
C:\Program Files\YamicSoft\Windows Manager\Uninstall.exe
(PID) Process:(540) Windows.Manager.v2.0.2.0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Windows Manager
Operation:writeName:DisplayIcon
Value:
C:\Program Files\YamicSoft\Windows Manager\WindowsManager.exe
(PID) Process:(540) Windows.Manager.v2.0.2.0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Windows Manager
Operation:writeName:DisplayVersion
Value:
2.0.2.0
(PID) Process:(4632) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Progress
Value:
1
(PID) Process:(540) Windows.Manager.v2.0.2.0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Windows Manager
Operation:writeName:EstimatedSize
Value:
77322
Executable files
64
Suspicious files
41
Text files
44
Unknown types
4

Dropped files

PID
Process
Filename
Type
540Windows.Manager.v2.0.2.0.exeC:\Program Files\YamicSoft\Windows Manager\1-ClickCleaner.exeexecutable
MD5:EE03E06591D36240524EFD8597E56090
SHA256:7EAEFC02B29239075878D4D2A60A0F9114B2F22A39E9C3D3975192274FC729CB
540Windows.Manager.v2.0.2.0.exeC:\Users\admin\AppData\Local\Temp\nsr1A6B.tmp\modern-header.bmpimage
MD5:CBC96B5DE5A30349EF4CD923826A61B4
SHA256:322470E6BAD05A10BDB493C3E4E9F136C4E5C6CF524524801C9A6F4BC98B8CBB
540Windows.Manager.v2.0.2.0.exeC:\Users\admin\AppData\Local\Temp\nsr1A6B.tmp\4.bmpimage
MD5:7B91A8BD71A1534BED881C524474AA66
SHA256:3392CF7BA5655BC4624D133947E13683D4447FAFB1EA6926F070FC3FD3C499B1
540Windows.Manager.v2.0.2.0.exeC:\Program Files\YamicSoft\Windows Manager\CMMultipleFiles.exeexecutable
MD5:84A8763EC68FE9C3E21E2FDA328F1BD3
SHA256:70E21082846DCED2C12DF22EAF747115D946E6FAD8824A9A3DB99ECDC173D2F1
540Windows.Manager.v2.0.2.0.exeC:\Program Files\YamicSoft\Windows Manager\CheckBoxComboBox.dllexecutable
MD5:F6EE7D64F7E8DADB0B9A9D00D0FF223B
SHA256:1548A1F06025153F4C416E12D7C0A2640D53AE5571CA1F6335D05C1D6F4F7960
540Windows.Manager.v2.0.2.0.exeC:\Users\admin\AppData\Local\Temp\nsr1A6B.tmp\System.dllexecutable
MD5:192639861E3DC2DC5C08BB8F8C7260D5
SHA256:23D618A0293C78CE00F7C6E6DD8B8923621DA7DD1F63A070163EF4C0EC3033D6
540Windows.Manager.v2.0.2.0.exeC:\Program Files\YamicSoft\Windows Manager\DevComponents.TreeGX.dllexecutable
MD5:B082423ED7DAA36174DC6EDFB3D7D9FB
SHA256:01D1EC727F3810998E395C20823951BC3704AC917C1024E6116F839E220AC425
540Windows.Manager.v2.0.2.0.exeC:\Program Files\YamicSoft\Windows Manager\DevComponents.DotNetBar2.dllexecutable
MD5:72590D0708FD59767936008C2BAF5A06
SHA256:023142BB888FE4811CD428AAA4649EF2F83EFD62B8231E6DDA2273B4D66C98E9
540Windows.Manager.v2.0.2.0.exeC:\Users\admin\AppData\Local\Temp\nsr1A6B.tmp\1.bmpimage
MD5:DEC435FEBCB6AFA7D48712C6B7B7F797
SHA256:CF0BF3E2326C6D6C60C0EB72F23D2F57E02C50B1C08012EC0F3490AD7992F85A
540Windows.Manager.v2.0.2.0.exeC:\Program Files\YamicSoft\Windows Manager\ContextMenuManager.exeexecutable
MD5:19231D20CDF37C6453FA598B13687F64
SHA256:2AF5786E2106762E0F14B0159F7238A20CEBA6BC6F6F7995121E2D4B788DD756
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
76
DNS requests
97
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4632
firefox.exe
GET
404
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
4632
firefox.exe
GET
404
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
4632
firefox.exe
GET
404
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
4632
firefox.exe
GET
404
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
4632
firefox.exe
GET
404
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
4632
firefox.exe
GET
404
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6012
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
104.126.37.155:443
www.bing.com
Akamai International B.V.
DE
unknown
4204
svchost.exe
4.209.33.156:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3952
svchost.exe
239.255.255.250:1900
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
1952
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4632
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
whitelisted
google.com
  • 216.58.206.46
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.117.188.166
whitelisted
spocs.getpocket.com
  • 34.117.188.166
whitelisted
prod.ads.prod.webservices.mozgcp.net
  • 34.117.188.166
unknown
content-signature-2.cdn.mozilla.net
  • 34.160.144.191
whitelisted
prod.content-signature-chains.prod.webservices.mozgcp.net
  • 34.160.144.191
  • 2600:1901:0:92a9::
whitelisted

Threats

No threats detected
No debug info