URL:

http://www.avantronics.com/software-driver/DG40S-Driver-BlueSoleil_A9.2.496.11.zip

Full analysis: https://app.any.run/tasks/796fd730-4db4-4bb4-8277-15f1a4f39717
Verdict: Malicious activity
Analysis date: March 09, 2020, 19:31:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
opendir
Indicators:
MD5:

203B7A565048F0D28BF1104F131F2350

SHA1:

715DE3237F846132BBF0DCF25B1D87E48480BB40

SHA256:

98B8A1A96C61FDE3295D9BAF27633E75B5E544B0113D4704CC8A3A038250F490

SSDEEP:

3:N1KJS4OHMwKZcOzJ7InJQTzIPKV:Cc46MwG1MneTzEO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • setup.exe (PID: 4092)
      • setup.exe (PID: 3260)
      • setup.exe (PID: 2412)
      • vcredist_x86.exe (PID: 3196)
      • install.exe (PID: 1296)
      • BlueSoleilCS.exe (PID: 2284)
      • BsHelpCS.exe (PID: 3996)
    • Loads dropped or rewritten executable

      • install.exe (PID: 1296)
      • regsvr32.exe (PID: 1412)
      • regsvr32.exe (PID: 2660)
      • regsvr32.exe (PID: 1492)
      • BlueSoleilCS.exe (PID: 2284)
      • regsvr32.exe (PID: 924)
    • Registers / Runs the DLL via REGSVR32.EXE

      • MsiExec.exe (PID: 3916)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • vcredist_x86.exe (PID: 3196)
      • WinRAR.exe (PID: 2748)
      • MSIEXEC.EXE (PID: 2160)
      • msiexec.exe (PID: 1348)
      • DrvInst.exe (PID: 2560)
      • MsiExec.exe (PID: 3916)
      • DrvInst.exe (PID: 3224)
      • DrvInst.exe (PID: 2860)
      • DrvInst.exe (PID: 1932)
      • DrvInst.exe (PID: 2864)
      • DrvInst.exe (PID: 3028)
      • DrvInst.exe (PID: 1508)
      • DrvInst.exe (PID: 912)
    • Creates or modifies windows services

      • setup.exe (PID: 2412)
      • DrvInst.exe (PID: 2696)
    • Creates files in the Windows directory

      • setup.exe (PID: 2412)
      • MsiExec.exe (PID: 3360)
      • MsiExec.exe (PID: 3916)
      • msiexec.exe (PID: 1348)
      • DrvInst.exe (PID: 3224)
      • DrvInst.exe (PID: 2560)
      • DrvInst.exe (PID: 1692)
      • DrvInst.exe (PID: 2860)
      • DrvInst.exe (PID: 3028)
      • DrvInst.exe (PID: 340)
      • DrvInst.exe (PID: 1932)
      • DrvInst.exe (PID: 2864)
      • DrvInst.exe (PID: 2696)
      • DrvInst.exe (PID: 1508)
      • DrvInst.exe (PID: 2672)
      • DrvInst.exe (PID: 3744)
      • DrvInst.exe (PID: 2984)
      • DrvInst.exe (PID: 912)
    • Starts Microsoft Installer

      • setup.exe (PID: 4092)
    • Executed as Windows Service

      • vssvc.exe (PID: 816)
    • Creates files in the driver directory

      • msiexec.exe (PID: 1348)
      • DrvInst.exe (PID: 3224)
      • DrvInst.exe (PID: 2560)
      • DrvInst.exe (PID: 2860)
      • DrvInst.exe (PID: 1692)
      • DrvInst.exe (PID: 340)
      • DrvInst.exe (PID: 1932)
      • DrvInst.exe (PID: 2864)
      • DrvInst.exe (PID: 3028)
      • DrvInst.exe (PID: 3744)
      • DrvInst.exe (PID: 1508)
      • DrvInst.exe (PID: 2984)
      • DrvInst.exe (PID: 912)
    • Removes files from Windows directory

      • DrvInst.exe (PID: 3224)
      • DrvInst.exe (PID: 2560)
      • DrvInst.exe (PID: 1692)
      • DrvInst.exe (PID: 2860)
      • msiexec.exe (PID: 1348)
      • DrvInst.exe (PID: 340)
      • DrvInst.exe (PID: 3028)
      • DrvInst.exe (PID: 1932)
      • DrvInst.exe (PID: 2864)
      • DrvInst.exe (PID: 1508)
      • DrvInst.exe (PID: 3744)
      • DrvInst.exe (PID: 912)
      • DrvInst.exe (PID: 2984)
    • Executed via COM

      • DrvInst.exe (PID: 1692)
      • DrvInst.exe (PID: 2560)
      • DrvInst.exe (PID: 3224)
      • DrvInst.exe (PID: 3028)
      • DrvInst.exe (PID: 340)
      • DrvInst.exe (PID: 2860)
      • DrvInst.exe (PID: 1932)
      • DrvInst.exe (PID: 2696)
      • DrvInst.exe (PID: 2864)
      • DrvInst.exe (PID: 1508)
      • DrvInst.exe (PID: 3744)
      • DrvInst.exe (PID: 2128)
      • DrvInst.exe (PID: 2672)
      • DrvInst.exe (PID: 2984)
      • DrvInst.exe (PID: 1728)
      • rundll32.exe (PID: 3028)
      • DrvInst.exe (PID: 912)
    • Creates COM task schedule object

      • MsiExec.exe (PID: 3916)
      • regsvr32.exe (PID: 1492)
      • regsvr32.exe (PID: 2660)
      • regsvr32.exe (PID: 1412)
      • regsvr32.exe (PID: 924)
  • INFO

    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 2872)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2872)
      • iexplore.exe (PID: 2380)
    • Creates files in the user directory

      • iexplore.exe (PID: 2872)
    • Changes internet zones settings

      • iexplore.exe (PID: 2872)
    • Loads dropped or rewritten executable

      • MsiExec.exe (PID: 3360)
      • MsiExec.exe (PID: 3916)
    • Application launched itself

      • msiexec.exe (PID: 1348)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 1348)
    • Searches for installed software

      • msiexec.exe (PID: 1348)
    • Low-level read access rights to disk partition

      • vssvc.exe (PID: 816)
    • Changes settings of System certificates

      • DrvInst.exe (PID: 2560)
      • iexplore.exe (PID: 2872)
    • Adds / modifies Windows certificates

      • DrvInst.exe (PID: 2560)
      • iexplore.exe (PID: 2872)
    • Reads settings of System Certificates

      • DrvInst.exe (PID: 340)
      • iexplore.exe (PID: 2872)
    • Creates files in the program directory

      • msiexec.exe (PID: 1348)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
79
Monitored processes
38
Malicious processes
13
Suspicious processes
6

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start iexplore.exe iexplore.exe winrar.exe setup.exe no specs setup.exe setup.exe no specs msiexec.exe msiexec.exe msiexec.exe no specs vcredist_x86.exe install.exe no specs vssvc.exe no specs msiexec.exe drvinst.exe drvinst.exe drvinst.exe no specs drvinst.exe no specs drvinst.exe drvinst.exe drvinst.exe drvinst.exe no specs drvinst.exe drvinst.exe drvinst.exe no specs drvinst.exe no specs drvinst.exe no specs rundll32.exe no specs dinotify.exe no specs drvinst.exe no specs drvinst.exe no specs drvinst.exe bshelpcs.exe no specs regsvr32.exe no specs bluesoleilcs.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
340DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{1b432cef-ad86-5aac-9532-2574f8509710}\blueletaudio.inf" "0" "6ec322f4f" "000003C0" "WinSta0\Default" "00000064" "208" "C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k"C:\Windows\system32\DrvInst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
392"C:\Windows\System32\dinotify.exe" pnpui.dll,SimplifiedDINotificationC:\Windows\System32\dinotify.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Device Installation
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dinotify.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\pnpui.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
816C:\Windows\system32\vssvc.exeC:\Windows\system32\vssvc.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
912DrvInst.exe "2" "211" "ROOT\BLUETOOTH_DEVICE\0003" "C:\Windows\INF\oem12.inf" "ivtbtbus.inf:IVT:BtBus_DDI:6.2.84.265:{f12d3cf8-b11d-457e-8641-be2af2d6d204}\ivtbtbus" "65ec43507" "000003C0" "000003E8" "000004B8"C:\Windows\system32\DrvInst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
924"C:\Windows\System32\regsvr32.exe" /s "C:\Windows\system32\BsShell.dll"C:\Windows\System32\regsvr32.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1168"C:\Windows\System32\regsvr32.exe" /s "C:\Windows\system32\skype4com.dll"C:\Windows\System32\regsvr32.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
3
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1296c:\e853ad87bd1607a1cf\.\install.exe /s /v "/qn"c:\e853ad87bd1607a1cf\install.exevcredist_x86.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
External Installer
Exit code:
0
Version:
9.0.21022.8 built by: RTM
Modules
Images
c:\e853ad87bd1607a1cf\install.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
1348C:\Windows\system32\msiexec.exe /VC:\Windows\system32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1412"C:\Windows\System32\regsvr32.exe" /s "C:\Windows\system32\BlueSoleilCSps.dll"C:\Windows\System32\regsvr32.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1492"C:\Windows\System32\regsvr32.exe" /s "C:\Windows\system32\BsHelpCSps.dll"C:\Windows\System32\regsvr32.exeMsiExec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
11 842
Read events
3 453
Write events
6 086
Delete events
2 303

Modification events

(PID) Process:(2872) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
1917251832
(PID) Process:(2872) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30799433
(PID) Process:(2872) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2872) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2872) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2872) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2872) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2872) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
46000000A1000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2872) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2872) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
Executable files
176
Suspicious files
158
Text files
707
Unknown types
133

Dropped files

PID
Process
Filename
Type
2380iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\DG40S-Driver-BlueSoleil_A9.2.496.11[1].zip
MD5:
SHA256:
2872iexplore.exeC:\Users\admin\AppData\Local\Temp\Cab46FF.tmp
MD5:
SHA256:
2872iexplore.exeC:\Users\admin\AppData\Local\Temp\Tar4700.tmp
MD5:
SHA256:
2872iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\VersionManager\ver4740.tmp
MD5:
SHA256:
2872iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\QTO7CY0H.txt
MD5:
SHA256:
2872iexplore.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\UANPRITZ.txt
MD5:
SHA256:
2380iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\DG40S-Driver-BlueSoleil_A9.2.496.11.zip.7fkn8kj.partial
MD5:
SHA256:
2872iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF1DFAC1A8F7924E0C.TMP
MD5:
SHA256:
2872iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\DG40S-Driver-BlueSoleil_A9.2.496.11.zip.7fkn8kj.partial:Zone.Identifier
MD5:
SHA256:
2872iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\DG40S-Driver-BlueSoleil_A9.2.496.11.zip
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
10
DNS requests
7
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2380
iexplore.exe
GET
200
162.241.244.134:80
http://www.avantronics.com/software-driver/DG40S-Driver-BlueSoleil_A9.2.496.11.zip
US
compressed
111 Mb
malicious
2872
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D
US
der
1.47 Kb
whitelisted
2872
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D
US
der
1.47 Kb
whitelisted
2872
iexplore.exe
GET
200
93.184.220.29:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D
US
der
1.47 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2380
iexplore.exe
162.241.244.134:80
www.avantronics.com
CyrusOne LLC
US
malicious
2872
iexplore.exe
93.184.220.29:80
ocsp.digicert.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2872
iexplore.exe
204.79.197.200:443
ieonline.microsoft.com
Microsoft Corporation
US
whitelisted
2872
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted

DNS requests

Domain
IP
Reputation
www.avantronics.com
  • 162.241.244.134
malicious
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ocsp.digicert.com
  • 93.184.220.29
whitelisted
ieonline.microsoft.com
  • 204.79.197.200
whitelisted

Threats

No threats detected
No debug info