File name:

878df3379b86bfd934373a02d859875b58002adc07ee13805f7f8a062aa40c00.exe

Full analysis: https://app.any.run/tasks/30be4e67-36b8-4aeb-b12e-b5661bab07ce
Verdict: Malicious activity
Analysis date: October 03, 2025, 16:38:09
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
urelas
bootkit
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed, 3 sections
MD5:

F1F9742B2C6A5BC0E456C2EC0289F417

SHA1:

51A96BD78982684F4D2DA0B20CE32F6CFB667134

SHA256:

878DF3379B86BFD934373A02D859875B58002ADC07EE13805F7F8A062AA40C00

SSDEEP:

12288:AdDbRSXmj/YqYgJYTRItVm3FwO7kYNqHk4CJj31j+f:AFbRq8JYTRI+3mOkYNqH9q1j+f

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • URELAS has been detected

      • 878df3379b86bfd934373a02d859875b58002adc07ee13805f7f8a062aa40c00.exe (PID: 5196)
      • gucum.exe (PID: 5484)
      • cmd.exe (PID: 5292)
      • fupui.exe (PID: 9120)
    • URELAS mutex has been found

      • gucum.exe (PID: 5484)
    • URELAS has been detected (YARA)

      • gucum.exe (PID: 5484)
      • fupui.exe (PID: 9120)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 878df3379b86bfd934373a02d859875b58002adc07ee13805f7f8a062aa40c00.exe (PID: 5196)
      • gucum.exe (PID: 5484)
      • fupui.exe (PID: 9120)
    • Reads security settings of Internet Explorer

      • 878df3379b86bfd934373a02d859875b58002adc07ee13805f7f8a062aa40c00.exe (PID: 5196)
      • gucum.exe (PID: 5484)
    • Starts CMD.EXE for commands execution

      • 878df3379b86bfd934373a02d859875b58002adc07ee13805f7f8a062aa40c00.exe (PID: 5196)
    • Starts itself from another location

      • 878df3379b86bfd934373a02d859875b58002adc07ee13805f7f8a062aa40c00.exe (PID: 5196)
    • Executing commands from a ".bat" file

      • 878df3379b86bfd934373a02d859875b58002adc07ee13805f7f8a062aa40c00.exe (PID: 5196)
    • Connects to unusual port

      • gucum.exe (PID: 5484)
    • There is functionality for taking screenshot (YARA)

      • gucum.exe (PID: 5484)
      • fupui.exe (PID: 9120)
  • INFO

    • Create files in a temporary directory

      • 878df3379b86bfd934373a02d859875b58002adc07ee13805f7f8a062aa40c00.exe (PID: 5196)
      • gucum.exe (PID: 5484)
      • fupui.exe (PID: 9120)
    • Reads the computer name

      • 878df3379b86bfd934373a02d859875b58002adc07ee13805f7f8a062aa40c00.exe (PID: 5196)
      • gucum.exe (PID: 5484)
    • Checks supported languages

      • 878df3379b86bfd934373a02d859875b58002adc07ee13805f7f8a062aa40c00.exe (PID: 5196)
      • gucum.exe (PID: 5484)
      • fupui.exe (PID: 9120)
    • Process checks computer location settings

      • 878df3379b86bfd934373a02d859875b58002adc07ee13805f7f8a062aa40c00.exe (PID: 5196)
      • gucum.exe (PID: 5484)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 8468)
      • BackgroundTransferHost.exe (PID: 8832)
      • BackgroundTransferHost.exe (PID: 9052)
      • BackgroundTransferHost.exe (PID: 4356)
      • BackgroundTransferHost.exe (PID: 8668)
    • Checks proxy server information

      • BackgroundTransferHost.exe (PID: 8668)
      • slui.exe (PID: 8916)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 8668)
    • Reads the software policy settings

      • slui.exe (PID: 8916)
      • BackgroundTransferHost.exe (PID: 8668)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2013:08:20 15:35:35+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 171008
InitializedDataSize: 312832
UninitializedDataSize: -
EntryPoint: 0x1759a
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
177
Monitored processes
11
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
4356"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
5196"C:\Users\admin\Desktop\878df3379b86bfd934373a02d859875b58002adc07ee13805f7f8a062aa40c00.exe" C:\Users\admin\Desktop\878df3379b86bfd934373a02d859875b58002adc07ee13805f7f8a062aa40c00.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\878df3379b86bfd934373a02d859875b58002adc07ee13805f7f8a062aa40c00.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5292C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\_uinsey.bat" "C:\Windows\SysWOW64\cmd.exe
878df3379b86bfd934373a02d859875b58002adc07ee13805f7f8a062aa40c00.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
5484"C:\Users\admin\AppData\Local\Temp\gucum.exe" C:\Users\admin\AppData\Local\Temp\gucum.exe
878df3379b86bfd934373a02d859875b58002adc07ee13805f7f8a062aa40c00.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\gucum.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6156\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
8468"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
8668"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
8832"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
8916C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
9052"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
Total events
8 792
Read events
8 777
Write events
15
Delete events
0

Modification events

(PID) Process:(8468) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(8468) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(8468) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(8668) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(8668) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(8668) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(8832) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(8832) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(8832) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(9052) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
Executable files
3
Suspicious files
4
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
8668BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\cb779718-4673-48be-8f5f-5198ea96df0c.down_data
MD5:
SHA256:
5196878df3379b86bfd934373a02d859875b58002adc07ee13805f7f8a062aa40c00.exeC:\Users\admin\AppData\Local\Temp\gucum.exeexecutable
MD5:6DD837F28E46D324C2385255EF96F308
SHA256:B9017AD3ACB13AAA8CBA5776E0D32DFAEFC9F3E574EA8C6722A2BDBFD14ABD20
5196878df3379b86bfd934373a02d859875b58002adc07ee13805f7f8a062aa40c00.exeC:\Users\admin\AppData\Local\Temp\_uinsey.battext
MD5:1208E7329C7EE117117E73953C7AB766
SHA256:8B21AAB030A6071D08B671B64D560F1434ADFB3F622A6CF3878131B41D1BFE9A
5196878df3379b86bfd934373a02d859875b58002adc07ee13805f7f8a062aa40c00.exeC:\Users\admin\AppData\Local\Temp\golfinfo.inibinary
MD5:565590B72D76045140B3D84076FF9DFD
SHA256:0E5818D05A22150BD9447EA20F705EDA0B713F7679031849DCD223613F9C4F40
8668BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\11d99619-2c91-4045-93cc-4da15ec0b4f4.up_meta_securebinary
MD5:2A9A96D1F665D904C4A27D3A2CF491F6
SHA256:ED6D94BA068AAFA50A863A418DAA191FD5A6C9E8F28EC87C945B1DE81F3A47C7
8668BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\cb779718-4673-48be-8f5f-5198ea96df0c.1b80d9cd-afa7-451c-ab90-fd469934d9ff.down_metabinary
MD5:7599EDBBAC287F580E8FD1F54614CA2D
SHA256:84CAE0386C5819BEFC6AF466EA0E1F8782185390DC09A2356824AAD58FB596A6
5484gucum.exeC:\Users\admin\AppData\Local\Temp\fupui.exeexecutable
MD5:D4743802046145C68FF8EE35917F84D4
SHA256:DFBD24507435A4BEA392F5C480F82E06CD340C64E2DEF9710A92DD23F61F25D8
8668BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\11d99619-2c91-4045-93cc-4da15ec0b4f4.1b80d9cd-afa7-451c-ab90-fd469934d9ff.down_metabinary
MD5:7599EDBBAC287F580E8FD1F54614CA2D
SHA256:84CAE0386C5819BEFC6AF466EA0E1F8782185390DC09A2356824AAD58FB596A6
9120fupui.exeC:\Users\admin\AppData\Local\Temp\gucum.exeexecutable
MD5:8DEFFCF62C3BDCD112A5031940FF552D
SHA256:51C9B682D41E169C4B9FDE1493651EFAED5A0A90524402B051962B8406647975
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
27
TCP/UDP connections
49
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
POST
204
95.100.100.120:443
https://www.bing.com/web/xlsc.aspx?t=5&dl=1&wsbc=1
unknown
unknown
GET
200
95.100.100.120:443
https://www.bing.com/DSB/search?dsbmr=1&format=dsbjson&client=windowsminiserp&dsbschemaversion=1.1&dsbminiserp=1&q=q&cc=US&setlang=en-us&clientDateTime=10%2F3%2F2025%2C%204%3A38%3A24%20PM
unknown
binary
63.9 Kb
unknown
POST
200
40.126.32.134:443
https://login.live.com/RST2.srf
US
xml
11.2 Kb
unknown
POST
200
40.126.32.134:443
https://login.live.com/RST2.srf
US
xml
11.1 Kb
unknown
GET
200
95.100.100.120:443
https://www.bing.com/th?id=ODSWG.8229b0e5-fa8c-4e4a-af74-69717698b903&pid=dsb
unknown
image
4.62 Kb
unknown
GET
200
95.100.100.113:443
https://www.bing.com/th?id=ODSWG.31bcf3d1-4df8-4c6a-9b3a-447ced8d6c39&pid=dsb
unknown
image
4.64 Kb
unknown
POST
200
20.190.160.132:443
https://login.live.com/RST2.srf
US
xml
11.0 Kb
unknown
POST
200
20.190.160.3:443
https://login.live.com/RST2.srf
US
xml
11.3 Kb
unknown
POST
200
20.190.160.67:443
https://login.live.com/RST2.srf
US
xml
11.3 Kb
unknown
POST
200
40.126.32.136:443
https://login.live.com/RST2.srf
US
xml
11.3 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5948
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5224
SearchApp.exe
95.100.100.130:443
www.bing.com
Akamai International B.V.
PT
whitelisted
4440
svchost.exe
40.126.32.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5484
gucum.exe
218.54.31.226:11300
SK Broadband Co Ltd
KR
malicious
6168
backgroundTaskHost.exe
95.100.100.130:443
www.bing.com
Akamai International B.V.
PT
whitelisted
3464
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.238
whitelisted
www.bing.com
  • 95.100.100.130
  • 95.100.100.115
  • 95.100.100.113
  • 95.100.100.122
  • 95.100.100.129
  • 95.100.100.120
  • 95.100.100.107
  • 95.100.100.112
  • 95.100.100.105
whitelisted
login.live.com
  • 40.126.32.68
  • 20.190.160.3
  • 40.126.32.134
  • 20.190.160.65
  • 40.126.32.72
  • 20.190.160.132
  • 40.126.32.136
  • 20.190.160.67
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
slscr.update.microsoft.com
  • 20.165.94.63
whitelisted
www.microsoft.com
  • 72.247.166.29
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted

Threats

No threats detected
No debug info