File name:

RegCureProSetup_bing.exe

Full analysis: https://app.any.run/tasks/a7c98786-45a0-4777-91b6-d07a85fc475a
Verdict: Malicious activity
Analysis date: June 07, 2025, 22:06:39
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

0ABE2DD446325DD95D5D4491D8A8C0F5

SHA1:

520BAAC0A3F1F3B5D3E8571EF31913305A8F9A0C

SHA256:

88C728A821E25C4579DF2235CB3F31E1768442F465C285DFA5C20A2359473C3B

SSDEEP:

98304:pI+9di1aFKH1tDUXHMAaCzyV4Roi6O03uWMc+jFbIdMoOpaE31mWO/DRG8UwKTHm:quY2xx0JPBeG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • RegCureProSetup_bing.exe (PID: 6632)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • RegCureProSetup_bing.exe (PID: 5960)
    • The process creates files with name similar to system file names

      • RegCureProSetup_bing.exe (PID: 5960)
    • Reads security settings of Internet Explorer

      • RegCureProSetup_bing.exe (PID: 5960)
      • RegCurePro.exe (PID: 7508)
      • RegCurePro.exe (PID: 5260)
    • Executable content was dropped or overwritten

      • RegCureProSetup_bing.exe (PID: 5960)
    • There is functionality for taking screenshot (YARA)

      • RegCureProSetup_bing.exe (PID: 5960)
      • RegCurePro.exe (PID: 5260)
    • Creates a software uninstall entry

      • RegCureProSetup_bing.exe (PID: 5960)
    • Searches for installed software

      • RegCurePro.exe (PID: 5260)
    • Reads Microsoft Outlook installation path

      • RegCurePro.exe (PID: 5260)
    • Reads Internet Explorer settings

      • RegCurePro.exe (PID: 5260)
    • Executes as Windows Service

      • VSSVC.exe (PID: 668)
    • Adds/modifies Windows certificates

      • RegCurePro.exe (PID: 5260)
  • INFO

    • Create files in a temporary directory

      • RegCureProSetup_bing.exe (PID: 5960)
    • Checks supported languages

      • RegCureProSetup_bing.exe (PID: 5960)
      • RegCurePro.exe (PID: 3996)
      • Pareto_Update3.exe (PID: 1760)
      • RegCurePro.exe (PID: 2568)
      • RegCurePro.exe (PID: 1812)
      • RegCurePro.exe (PID: 7508)
      • RegCurePro.exe (PID: 5260)
    • Reads the computer name

      • RegCureProSetup_bing.exe (PID: 5960)
      • RegCurePro.exe (PID: 3996)
      • Pareto_Update3.exe (PID: 1760)
      • RegCurePro.exe (PID: 2568)
      • RegCurePro.exe (PID: 1812)
      • RegCurePro.exe (PID: 7508)
      • RegCurePro.exe (PID: 5260)
    • The sample compiled with english language support

      • RegCureProSetup_bing.exe (PID: 5960)
    • Creates files in the program directory

      • RegCureProSetup_bing.exe (PID: 5960)
      • RegCurePro.exe (PID: 3996)
      • RegCurePro.exe (PID: 7508)
      • RegCurePro.exe (PID: 5260)
    • Creates files or folders in the user directory

      • RegCureProSetup_bing.exe (PID: 5960)
      • RegCurePro.exe (PID: 5260)
    • Checks proxy server information

      • RegCurePro.exe (PID: 7508)
      • RegCurePro.exe (PID: 5260)
    • Reads CPU info

      • RegCurePro.exe (PID: 5260)
    • Reads the machine GUID from the registry

      • RegCurePro.exe (PID: 5260)
    • Reads the software policy settings

      • RegCurePro.exe (PID: 5260)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:02:24 19:19:59+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 28672
InitializedDataSize: 445952
UninitializedDataSize: 16896
EntryPoint: 0x39e3
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 3.1.6.0
ProductVersionNumber: 3.1.6.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: ASCII
CompanyName: ParetoLogic, Inc.
FileDescription: RegCure Pro Installer
FileVersion: 3.1.6.0
LegalCopyright: Copyright © 2013 ParetoLogic, Inc.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
11
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start regcureprosetup_bing.exe regcurepro.exe no specs pareto_update3.exe no specs regcurepro.exe no specs regcurepro.exe no specs regcurepro.exe no specs regcurepro.exe SPPSurrogate no specs vssvc.exe no specs slui.exe no specs regcureprosetup_bing.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
668C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1760"C:\Program Files (x86)\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe" -AddTaskC:\Program Files (x86)\Common Files\ParetoLogic\UUS3\Pareto_Update3.exeRegCureProSetup_bing.exe
User:
admin
Integrity Level:
HIGH
Description:
Update Application
Exit code:
0
Version:
3.0.3.0
Modules
Images
c:\program files (x86)\common files\paretologic\uus3\pareto_update3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
1812"C:\Program Files (x86)\ParetoLogic\RegCure Pro\RegCurePro.exe" -installC:\Program Files (x86)\ParetoLogic\RegCure Pro\RegCurePro.exeRegCureProSetup_bing.exe
User:
admin
Company:
ParetoLogic, Inc.
Integrity Level:
HIGH
Description:
RegCure Pro
Exit code:
0
Version:
3.1.6.0
Modules
Images
c:\program files (x86)\paretologic\regcure pro\regcurepro.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\rpcrt4.dll
2568"C:\Program Files (x86)\ParetoLogic\RegCure Pro\RegCurePro.exe" -launchonlogonC:\Program Files (x86)\ParetoLogic\RegCure Pro\RegCurePro.exeRegCureProSetup_bing.exe
User:
admin
Company:
ParetoLogic, Inc.
Integrity Level:
HIGH
Description:
RegCure Pro
Exit code:
0
Version:
3.1.6.0
Modules
Images
c:\program files (x86)\paretologic\regcure pro\regcurepro.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\rpcrt4.dll
3996"C:\Program Files (x86)\ParetoLogic\RegCure Pro\RegCurePro.exe" -addtaskC:\Program Files (x86)\ParetoLogic\RegCure Pro\RegCurePro.exeRegCureProSetup_bing.exe
User:
admin
Company:
ParetoLogic, Inc.
Integrity Level:
HIGH
Description:
RegCure Pro
Exit code:
0
Version:
3.1.6.0
Modules
Images
c:\program files (x86)\paretologic\regcure pro\regcurepro.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\rpcrt4.dll
5260"C:\Program Files (x86)\ParetoLogic\RegCure Pro\RegCurePro.exe" -scanC:\Program Files (x86)\ParetoLogic\RegCure Pro\RegCurePro.exe
RegCureProSetup_bing.exe
User:
admin
Company:
ParetoLogic, Inc.
Integrity Level:
HIGH
Description:
RegCure Pro
Version:
3.1.6.0
Modules
Images
c:\program files (x86)\paretologic\regcure pro\regcurepro.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\rpcrt4.dll
5960"C:\Users\admin\AppData\Local\Temp\RegCureProSetup_bing.exe" C:\Users\admin\AppData\Local\Temp\RegCureProSetup_bing.exe
explorer.exe
User:
admin
Company:
ParetoLogic, Inc.
Integrity Level:
HIGH
Description:
RegCure Pro Installer
Exit code:
0
Version:
3.1.6.0
Modules
Images
c:\users\admin\appdata\local\temp\regcureprosetup_bing.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6632"C:\Users\admin\AppData\Local\Temp\RegCureProSetup_bing.exe" C:\Users\admin\AppData\Local\Temp\RegCureProSetup_bing.exeexplorer.exe
User:
admin
Company:
ParetoLogic, Inc.
Integrity Level:
MEDIUM
Description:
RegCure Pro Installer
Exit code:
3221226540
Version:
3.1.6.0
Modules
Images
c:\users\admin\appdata\local\temp\regcureprosetup_bing.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6644C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7508"C:\Program Files (x86)\ParetoLogic\RegCure Pro\RegCurePro.exe" -reportC:\Program Files (x86)\ParetoLogic\RegCure Pro\RegCurePro.exeRegCureProSetup_bing.exe
User:
admin
Company:
ParetoLogic, Inc.
Integrity Level:
HIGH
Description:
RegCure Pro
Exit code:
0
Version:
3.1.6.0
Modules
Images
c:\program files (x86)\paretologic\regcure pro\regcurepro.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\rpcrt4.dll
Total events
20 720
Read events
20 022
Write events
695
Delete events
3

Modification events

(PID) Process:(5960) RegCureProSetup_bing.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ParetoLogic\RegCure Pro
Operation:writeName:Updates
Value:
0
(PID) Process:(5960) RegCureProSetup_bing.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ParetoLogic\RegCure Pro
Operation:writeName:Desktop
Value:
0
(PID) Process:(5960) RegCureProSetup_bing.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ParetoLogic\RegCure Pro
Operation:writeName:Login
Value:
0
(PID) Process:(5960) RegCureProSetup_bing.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ParetoLogic\RegCure Pro
Operation:writeName:Quick
Value:
0
(PID) Process:(5960) RegCureProSetup_bing.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ParetoLogic\RegCure Pro
Operation:writeName:Silent
Value:
0
(PID) Process:(5960) RegCureProSetup_bing.exeKey:HKEY_CURRENT_USER\SOFTWARE\ParetoLogic\RegCure Pro
Operation:writeName:ScanOnStartup
Value:
1
(PID) Process:(5960) RegCureProSetup_bing.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ParetoLogic\UUS3
Operation:writeName:Version
Value:
3.0.3
(PID) Process:(5960) RegCureProSetup_bing.exeKey:HKEY_CURRENT_USER\SOFTWARE\ParetoLogic\UUS3\Settings
Operation:writeName:CloseUpdateWindow
Value:
00000000
(PID) Process:(5960) RegCureProSetup_bing.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\uus3url-pl
Operation:writeName:URL Protocol
Value:
(PID) Process:(5960) RegCureProSetup_bing.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\ParetoLogic\UUS3
Operation:writeName:Installed
Value:
1
Executable files
25
Suspicious files
37
Text files
266
Unknown types
0

Dropped files

PID
Process
Filename
Type
5960RegCureProSetup_bing.exeC:\Users\admin\AppData\Local\Temp\nslF701.tmp\button.bmpimage
MD5:852BA1F1EB2BA4246F5B16A9C96F2D71
SHA256:04313D78272CE38B87CEACA8951BC4F4B34AFD8E8762B3F662C7BE8B3C00A621
5960RegCureProSetup_bing.exeC:\Users\admin\AppData\Local\Temp\nslF701.tmp\nsDialogs.dllexecutable
MD5:F7B92B78F1A00A872C8A38F40AFA7D65
SHA256:2BEE549B2816BA29F81C47778D9E299C3A364B81769E43D5255310C2BD146D6E
5960RegCureProSetup_bing.exeC:\Users\admin\AppData\Local\Temp\nslF701.tmp\SkinnedControls.dllexecutable
MD5:364BB3C9218429DD1315AD1DB47E152D
SHA256:5F7998711EA856730139C4DAC403F11B947ED94A464DC6D2D4B22F928C3A8536
5960RegCureProSetup_bing.exeC:\Users\admin\AppData\Local\Temp\nslF701.tmp\GraphicalInstaller.dllexecutable
MD5:C6A2332AF1DB39F76B37AD024003D9E7
SHA256:DD8CB56054CF916266937C5410F94F79009443FD090D9E8D0F2FDA03D5868BDA
5960RegCureProSetup_bing.exeC:\Users\admin\AppData\Local\Temp\nslF701.tmp\KillProcDLL.dllexecutable
MD5:83142EAC84475F4CA889C73F10D9C179
SHA256:AE2F1658656E554F37E6EAC896475A3862841A18FFC6FAD2754E2D3525770729
5960RegCureProSetup_bing.exeC:\ProgramData\ParetoLogic\RegCure Pro\dc_db.dbbinary
MD5:EDDEA8E6F76C94A9F0F82811141B986B
SHA256:DF2271608AE9246F135278F4FB2FB90E9C629A3BF6627B53550E193CA67D0354
5960RegCureProSetup_bing.exeC:\Users\admin\AppData\Local\Temp\nslF701.tmp\background.oleimage
MD5:E8D6EDB75D9183AF2EB076D8A203D8B8
SHA256:0E5AA56DD09707789400982B8085E38E79AE1714619BE5FE692E6485AAED2753
5960RegCureProSetup_bing.exeC:\Users\admin\AppData\Local\Temp\nslF701.tmp\Math.dllexecutable
MD5:7FC4A4937D364D42D4D06FF3554A464D
SHA256:4E540D1D8CA1C7564753232D18A884B0597FD7E5DF88F8B5D370824D858954B7
5960RegCureProSetup_bing.exeC:\Users\admin\AppData\Local\Temp\nslF701.tmp\splash.bmpimage
MD5:959C1D8648A28875F6DA0FF99FB9DE4D
SHA256:4EDF0BAB5323FE66CCDDB33D084E13506A53FC21E1151AC069D1F9B4B7B798D9
5960RegCureProSetup_bing.exeC:\Users\admin\AppData\Local\Temp\nslF701.tmp\AdvSplash.dllexecutable
MD5:41BE2441EE7C684EAA76A62D4223B4C7
SHA256:0990902460EC38BCD605B518BFFA081942C6F4C5FE1828A61BA3965BBF15D8BD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
22
TCP/UDP connections
38
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4628
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.16.241.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5260
RegCurePro.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4628
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5260
RegCurePro.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl
unknown
whitelisted
5260
RegCurePro.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
5260
RegCurePro.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_2010-07-06.crl
unknown
whitelisted
5260
RegCurePro.exe
GET
200
184.30.131.114:80
http://crl.verisign.com/pca3.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6544
svchost.exe
20.190.160.17:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.241.12:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
4
System
192.168.100.255:138
whitelisted
6544
svchost.exe
20.190.160.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
5496
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2112
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
login.live.com
  • 20.190.160.17
  • 20.190.160.67
  • 20.190.160.3
  • 20.190.160.4
  • 40.126.32.133
  • 20.190.160.64
  • 40.126.32.140
  • 40.126.32.138
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 2.16.241.12
  • 2.16.241.19
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 23.219.150.101
whitelisted
google.com
  • 142.250.186.46
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
survey.paretologic.com
unknown
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted

Threats

No threats detected
No debug info