File name:

Windows.Manager.v2.0.2.0.exe

Full analysis: https://app.any.run/tasks/e8143864-5bdf-4178-94a2-df48218a1c71
Verdict: Malicious activity
Analysis date: July 25, 2024, 11:39:42
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

C009E6D77AF3D5D62B0F463D6F646FFA

SHA1:

D82957367A9FAA45BC3C830D3E1767BDF59F45FB

SHA256:

83553D2F129710BE83E1824C6D9AAED277C25226DE2CAABB353B21DE550ADDB2

SSDEEP:

98304:WQX2ieTw+Cy0+UmTh0SnirimsJgnm1Cqsweg5ze4ggZ4O/0j6K1lsuqJvoDFtHsQ:6gUACgHVl+2vHXl9jpuadb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
    • Modifies hosts file to block updates

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
    • The process creates files with name similar to system file names

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
    • Uses NETSH.EXE to delete a firewall rule or allowed programs

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
    • Creates a software uninstall entry

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
    • Executable content was dropped or overwritten

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
    • Reads the date of Windows installation

      • WindowsManager.exe (PID: 8188)
    • Reads security settings of Internet Explorer

      • WindowsManager.exe (PID: 8188)
      • LiveUpdate.exe (PID: 7480)
  • INFO

    • Reads the computer name

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
      • TextInputHost.exe (PID: 6600)
      • WindowsManager.exe (PID: 8188)
      • LiveUpdate.exe (PID: 7480)
      • DiskAnalyzer.exe (PID: 6324)
    • Create files in a temporary directory

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
    • Checks supported languages

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
      • TextInputHost.exe (PID: 6600)
      • WindowsManager.exe (PID: 8188)
      • LiveUpdate.exe (PID: 7480)
      • DiskAnalyzer.exe (PID: 6324)
    • Creates files in the program directory

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
      • DiskAnalyzer.exe (PID: 6324)
    • Manual execution by a user

      • firefox.exe (PID: 4516)
    • Reads Microsoft Office registry keys

      • firefox.exe (PID: 4632)
    • Application launched itself

      • firefox.exe (PID: 4632)
      • firefox.exe (PID: 4516)
    • Creates files or folders in the user directory

      • Windows.Manager.v2.0.2.0.exe (PID: 540)
    • Reads Environment values

      • WindowsManager.exe (PID: 8188)
      • LiveUpdate.exe (PID: 7480)
    • Disables trace logs

      • WindowsManager.exe (PID: 8188)
      • LiveUpdate.exe (PID: 7480)
    • Checks proxy server information

      • WindowsManager.exe (PID: 8188)
      • LiveUpdate.exe (PID: 7480)
    • Process checks computer location settings

      • WindowsManager.exe (PID: 8188)
    • Reads the machine GUID from the registry

      • LiveUpdate.exe (PID: 7480)
      • DiskAnalyzer.exe (PID: 6324)
      • WindowsManager.exe (PID: 8188)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:30 16:56:02+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 412160
UninitializedDataSize: 16384
EntryPoint: 0x3665
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.0.2.0
ProductVersionNumber: 2.0.2.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: -
CompanyName: YamicSoft
FileDescription: Windows Manager v2.0.2.0
FileVersion: 2.0.2.0.0
LegalCopyright: © YamicSoft
ProductName: Windows Manager v2.0.2.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
156
Monitored processes
24
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start windows.manager.v2.0.2.0.exe slui.exe no specs firefox.exe no specs firefox.exe netsh.exe no specs conhost.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs textinputhost.exe no specs firefox.exe no specs netsh.exe no specs conhost.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs netsh.exe no specs conhost.exe no specs firefox.exe no specs windowsmanager.exe no specs liveupdate.exe diskanalyzer.exe no specs windows.manager.v2.0.2.0.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
540"C:\Users\admin\Downloads\Windows.Manager.v2.0.2.0.exe" C:\Users\admin\Downloads\Windows.Manager.v2.0.2.0.exe
explorer.exe
User:
admin
Company:
YamicSoft
Integrity Level:
HIGH
Description:
Windows Manager v2.0.2.0
Exit code:
0
Version:
2.0.2.0.0
Modules
Images
c:\users\admin\downloads\windows.manager.v2.0.2.0.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1000\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenetsh.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1272"C:\Users\admin\Downloads\Windows.Manager.v2.0.2.0.exe" C:\Users\admin\Downloads\Windows.Manager.v2.0.2.0.exeexplorer.exe
User:
admin
Company:
YamicSoft
Integrity Level:
MEDIUM
Description:
Windows Manager v2.0.2.0
Exit code:
3221226540
Version:
2.0.2.0.0
Modules
Images
c:\users\admin\downloads\windows.manager.v2.0.2.0.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1552"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2284 -parentBuildID 20240213221259 -prefsHandle 1812 -prefMapHandle 2232 -prefsLen 30537 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {14b9395f-d462-4ce8-8d01-d0c9acfc46d8} 4632 "\\.\pipe\gecko-crash-server-pipe.4632" 1ebaa480b10 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1728netsh.exe advfirewall firewall delete rule name="Block WindowsManager"C:\Windows\SysWOW64\netsh.exeWindows.Manager.v2.0.2.0.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2196"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=1896 -parentBuildID 20240213221259 -prefsHandle 1820 -prefMapHandle 1808 -prefsLen 30537 -prefMapSize 244343 -appDir "C:\Program Files\Mozilla Firefox\browser" - {759b3c26-af48-47a6-bc86-04da6a8b5a74} 4632 "\\.\pipe\gecko-crash-server-pipe.4632" 1ebb70e3f10 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
4016"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5768 -childID 5 -isForBrowser -prefsHandle 5776 -prefMapHandle 5780 -prefsLen 31154 -prefMapSize 244343 -jsInitHandle 1396 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {2fcecf57-9b01-422c-bd97-034e1daa990c} 4632 "\\.\pipe\gecko-crash-server-pipe.4632" 1ebc1bfe690 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
4020"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5592 -childID 4 -isForBrowser -prefsHandle 5428 -prefMapHandle 5548 -prefsLen 31154 -prefMapSize 244343 -jsInitHandle 1396 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {f4812952-06b6-44c4-8d8d-2fcff65c513c} 4632 "\\.\pipe\gecko-crash-server-pipe.4632" 1ebc1bfe4d0 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
4516"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
4632"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
Total events
29 532
Read events
29 432
Write events
89
Delete events
11

Modification events

(PID) Process:(4516) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
4DBA47C800000000
(PID) Process:(4632) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
626648C800000000
(PID) Process:(4632) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Progress
Value:
0
(PID) Process:(540) Windows.Manager.v2.0.2.0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Windows Manager
Operation:writeName:DisplayName
Value:
Windows Manager
(PID) Process:(540) Windows.Manager.v2.0.2.0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Windows Manager
Operation:writeName:Publisher
Value:
YamicSoft
(PID) Process:(540) Windows.Manager.v2.0.2.0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Windows Manager
Operation:writeName:UninstallString
Value:
C:\Program Files\YamicSoft\Windows Manager\Uninstall.exe
(PID) Process:(540) Windows.Manager.v2.0.2.0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Windows Manager
Operation:writeName:DisplayIcon
Value:
C:\Program Files\YamicSoft\Windows Manager\WindowsManager.exe
(PID) Process:(540) Windows.Manager.v2.0.2.0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Windows Manager
Operation:writeName:DisplayVersion
Value:
2.0.2.0
(PID) Process:(4632) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Progress
Value:
1
(PID) Process:(540) Windows.Manager.v2.0.2.0.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Windows Manager
Operation:writeName:EstimatedSize
Value:
77322
Executable files
64
Suspicious files
41
Text files
44
Unknown types
4

Dropped files

PID
Process
Filename
Type
540Windows.Manager.v2.0.2.0.exeC:\Users\admin\AppData\Local\Temp\nsr1A6B.tmp\LangDLL.dllexecutable
MD5:549EE11198143574F4D9953198A09FE8
SHA256:131AA0DF90C08DCE2EECEE46CCE8759E9AFFF04BF15B7B0002C2A53AE5E92C36
540Windows.Manager.v2.0.2.0.exeC:\Users\admin\AppData\Local\Temp\nsr1A6B.tmp\modern-header.bmpimage
MD5:CBC96B5DE5A30349EF4CD923826A61B4
SHA256:322470E6BAD05A10BDB493C3E4E9F136C4E5C6CF524524801C9A6F4BC98B8CBB
540Windows.Manager.v2.0.2.0.exeC:\Users\admin\AppData\Local\Temp\nsr1A6B.tmp\2.bmpimage
MD5:03E71E2F27CB3C60F2515B378D5934A7
SHA256:242603B8262926CB598FF0F8094775CF6A4EC4FA5DC8191B9CF226888AF9F96E
540Windows.Manager.v2.0.2.0.exeC:\Users\admin\AppData\Local\Temp\nsr1A6B.tmp\nsDialogs.dllexecutable
MD5:B7D61F3F56ABF7B7FF0D4E7DA3AD783D
SHA256:89A82C4849C21DFE765052681E1FAD02D2D7B13C8B5075880C52423DCA72A912
540Windows.Manager.v2.0.2.0.exeC:\Users\admin\AppData\Local\Temp\nsr1A6B.tmp\4.bmpimage
MD5:7B91A8BD71A1534BED881C524474AA66
SHA256:3392CF7BA5655BC4624D133947E13683D4447FAFB1EA6926F070FC3FD3C499B1
540Windows.Manager.v2.0.2.0.exeC:\Users\admin\AppData\Local\Temp\nsr1A6B.tmp\System.dllexecutable
MD5:192639861E3DC2DC5C08BB8F8C7260D5
SHA256:23D618A0293C78CE00F7C6E6DD8B8923621DA7DD1F63A070163EF4C0EC3033D6
540Windows.Manager.v2.0.2.0.exeC:\Users\admin\AppData\Local\Temp\nsr1A6B.tmp\3.bmpimage
MD5:FC176015020E80F8266906905D30536D
SHA256:475853E54B9B40AB85E3D7FEED1C3EE9CC4E34444E2068B63627A9235E5B6333
540Windows.Manager.v2.0.2.0.exeC:\Program Files\YamicSoft\Windows Manager\DeviceManager.exeexecutable
MD5:0CA318930E8CD58A741DADA3EBB02805
SHA256:7DF4803391020A07FB120F69DD4739D80F1F2D5B9C16B2B1A0DC30AD0FD8CA00
540Windows.Manager.v2.0.2.0.exeC:\Program Files\YamicSoft\Windows Manager\EventViewer.exeexecutable
MD5:E99386EF4834C7504AABD141405E21FE
SHA256:7065F0F455711D0CC95856B0ED007AD886C62F7E217B33A942223929CD1A4CF5
540Windows.Manager.v2.0.2.0.exeC:\Program Files\YamicSoft\Windows Manager\DuplicateFilesFinder.exeexecutable
MD5:798676E54240744840DB52F792CF5E1A
SHA256:6C06DFF7836FAEF8CA976CCAEEC158FBBD07EE86D5ACA743345DC32E07F71E45
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
76
DNS requests
97
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4632
firefox.exe
GET
404
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
4632
firefox.exe
GET
404
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
4632
firefox.exe
GET
404
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
4632
firefox.exe
GET
404
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
4632
firefox.exe
GET
404
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
4632
firefox.exe
GET
404
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6012
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
104.126.37.155:443
www.bing.com
Akamai International B.V.
DE
unknown
4204
svchost.exe
4.209.33.156:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3952
svchost.exe
239.255.255.250:1900
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
1952
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4632
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
whitelisted
google.com
  • 216.58.206.46
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
contile.services.mozilla.com
  • 34.117.188.166
whitelisted
spocs.getpocket.com
  • 34.117.188.166
whitelisted
prod.ads.prod.webservices.mozgcp.net
  • 34.117.188.166
unknown
content-signature-2.cdn.mozilla.net
  • 34.160.144.191
whitelisted
prod.content-signature-chains.prod.webservices.mozgcp.net
  • 34.160.144.191
  • 2600:1901:0:92a9::
whitelisted

Threats

No threats detected
No debug info