File name:

9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d

Full analysis: https://app.any.run/tasks/8689f1a7-5f6c-4dd7-bbec-4fbfec6dc152
Verdict: Malicious activity
Threats:

GCleaner is a type of malware loader that has the capability to deliver numerous malicious software programs, which differ based on the location of the targeted victim. This malware is commonly spread through fraudulent websites that advertise free PC optimization tools

Analysis date: April 29, 2025, 05:39:00
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
gcleaner
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

02988697C09FB17301F59D7AEE8B854A

SHA1:

E1B30768E947F27942F21C86438CFF9774D043F1

SHA256:

9F3D93A3D258F2069FF6E92A3D534F075EFE7079BD35B9DDDA06EC2F2811976D

SSDEEP:

6144:7aWW/s598XdTG75htcdkDkTo+hQAZKhA4dkwBTT7TKG:HWE5odTG75E0kTo8QAZmxeKvt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • GCLEANER has been detected (YARA)

      • 9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe (PID: 5680)
  • SUSPICIOUS

    • Executes application which crashes

      • 9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe (PID: 5680)
    • Reads security settings of Internet Explorer

      • 9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe (PID: 5680)
    • Process requests binary or script from the Internet

      • 9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe (PID: 5680)
    • Executable content was dropped or overwritten

      • 9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe (PID: 5680)
    • Process drops legitimate windows executable

      • 9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe (PID: 5680)
  • INFO

    • Creates files or folders in the user directory

      • WerFault.exe (PID: 7208)
      • WerFault.exe (PID: 7620)
      • WerFault.exe (PID: 7500)
      • WerFault.exe (PID: 7804)
      • WerFault.exe (PID: 8020)
      • WerFault.exe (PID: 7912)
      • WerFault.exe (PID: 8120)
      • 9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe (PID: 5680)
      • WerFault.exe (PID: 7184)
      • WerFault.exe (PID: 3008)
      • WerFault.exe (PID: 1072)
      • WerFault.exe (PID: 1184)
      • WerFault.exe (PID: 5728)
    • Checks supported languages

      • 9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe (PID: 5680)
    • Reads the computer name

      • 9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe (PID: 5680)
    • Checks proxy server information

      • 9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe (PID: 5680)
    • Reads the machine GUID from the registry

      • 9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe (PID: 5680)
    • Reads the software policy settings

      • 9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe (PID: 5680)
    • The sample compiled with english language support

      • 9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe (PID: 5680)
    • Create files in a temporary directory

      • 9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe (PID: 5680)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:10:22 03:01:47+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 268800
InitializedDataSize: 5127168
UninitializedDataSize: -
EntryPoint: 0xada0
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 25.0.0.0
ProductVersionNumber: 46.0.0.0
FileFlagsMask: 0x183a
FileFlags: (none)
FileOS: Unknown (0x20461)
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: Faeroese
CharacterSet: Unknown (31F6)
LegalCopyright: Copyright (C) 2023, parking
OriginalFileName: bigthing.exe
ProductsVersion: 64.84.4.44
ProductName: SolarisOmir
ProductionVersion: 71.86.55.7
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
156
Monitored processes
15
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #GCLEANER 9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe werfault.exe no specs sppextcomobj.exe no specs slui.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs werfault.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1072C:\WINDOWS\SysWOW64\WerFault.exe -u -p 5680 -s 1552C:\Windows\SysWOW64\WerFault.exe9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
1184C:\WINDOWS\SysWOW64\WerFault.exe -u -p 5680 -s 1684C:\Windows\SysWOW64\WerFault.exe9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
3008C:\WINDOWS\SysWOW64\WerFault.exe -u -p 5680 -s 1628C:\Windows\SysWOW64\WerFault.exe9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
5680"C:\Users\admin\AppData\Local\Temp\9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe" C:\Users\admin\AppData\Local\Temp\9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1073741854
Modules
Images
c:\users\admin\appdata\local\temp\9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5728C:\WINDOWS\SysWOW64\WerFault.exe -u -p 5680 -s 1052C:\Windows\SysWOW64\WerFault.exe9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
7184C:\WINDOWS\SysWOW64\WerFault.exe -u -p 5680 -s 1532C:\Windows\SysWOW64\WerFault.exe9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
7208C:\WINDOWS\SysWOW64\WerFault.exe -u -p 5680 -s 796C:\Windows\SysWOW64\WerFault.exe9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
7324C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7372"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7500C:\WINDOWS\SysWOW64\WerFault.exe -u -p 5680 -s 788C:\Windows\SysWOW64\WerFault.exe9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
Total events
20 323
Read events
20 320
Write events
3
Delete events
0

Modification events

(PID) Process:(5680) 9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(5680) 9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(5680) 9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
2
Suspicious files
38
Text files
12
Unknown types
0

Dropped files

PID
Process
Filename
Type
7208WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_9f3d93a3d258f206_70e8c69735c7e88a9c19b5f2dd4ef013caccd19_e5e60fdb_6d99a07e-4c4e-488c-b09a-c62b550da700\Report.wer
MD5:
SHA256:
7500WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_9f3d93a3d258f206_70e8c69735c7e88a9c19b5f2dd4ef013caccd19_e5e60fdb_40f650ba-c4e0-454e-abb7-820883b83cbd\Report.wer
MD5:
SHA256:
7620WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_9f3d93a3d258f206_70e8c69735c7e88a9c19b5f2dd4ef013caccd19_e5e60fdb_9e54d7cd-447b-4024-a851-4d5cc8f6ce84\Report.wer
MD5:
SHA256:
7804WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_9f3d93a3d258f206_70e8c69735c7e88a9c19b5f2dd4ef013caccd19_e5e60fdb_93461a88-dfab-4b61-97cc-e8954e9147e7\Report.wer
MD5:
SHA256:
7912WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_9f3d93a3d258f206_70e8c69735c7e88a9c19b5f2dd4ef013caccd19_e5e60fdb_411f1cc0-4532-43f9-90ea-c9fbd1abe71f\Report.wer
MD5:
SHA256:
7208WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERDE2D.tmp.dmpbinary
MD5:8B52F30809BE448E51308D4189298907
SHA256:42E819F9B6072664AF20DF020511619ACC47FFFAC23DED5B177F793D15C78C67
7500WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERE36E.tmp.xmlxml
MD5:85BB4515C46A909F75CBFF86170157C3
SHA256:1B38D261CF957F0487A0C8D913009A6A06C7CC56459C75280130E8ED1392A22E
7804WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe(3).5680.dmpbinary
MD5:5AF2D015B6750D6D81F879E33721885C
SHA256:CBACBD678ABF7D093D29FDAE63FD3E16DD61F7571C3B3BEB06BA243006F9A380
7208WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERDF66.tmp.WERInternalMetadata.xmlbinary
MD5:CA2D434EA9EC1579D6D7E1B817214E50
SHA256:ECFD8F4CE20738E337D7D6D0C73FA3DF501FBAFAB52D3528E733DA6B4E99E6F6
8020WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_9f3d93a3d258f206_70e8c69735c7e88a9c19b5f2dd4ef013caccd19_e5e60fdb_9e835b29-618f-4488-9c7d-44f4b5ece969\Report.wer
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
20
DNS requests
12
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5680
9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe
GET
302
2.18.160.223:80
http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/dxwebsetup.exe
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5680
9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
5376
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5376
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
6544
svchost.exe
40.126.32.140:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
5680
9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe
2.18.160.223:80
download.microsoft.com
AKAMAI-AS
DE
whitelisted
5680
9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe
2.18.160.223:443
download.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:137
whitelisted
5680
9f3d93a3d258f2069ff6e92a3d534f075efe7079bd35b9ddda06ec2f2811976d.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
google.com
  • 142.250.185.206
whitelisted
login.live.com
  • 40.126.32.140
  • 40.126.32.136
  • 20.190.160.14
  • 40.126.32.74
  • 20.190.160.20
  • 40.126.32.68
  • 20.190.160.130
  • 20.190.160.64
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
download.microsoft.com
  • 2.18.160.223
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted

Threats

No threats detected
No debug info