File name:

PortableApps.com_Platform_Setup_29.5.3.paf.exe

Full analysis: https://app.any.run/tasks/831af95b-cd7d-49be-9e0a-7fb4cdb0d939
Verdict: Malicious activity
Analysis date: July 23, 2024, 01:04:15
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

FA3CFE5874612ACE62AC41853200EFA6

SHA1:

D7C6263C99DBC271AC54260BB44C3336AC857AD6

SHA256:

B6FB17E3B8DAE7036AD95FE90608CF3A673973D3342F42311586672790328A27

SSDEEP:

98304:NaX6stlTIixW7qizkvNsMR3vXnHO+0BFe2OoiphqepmEe7MqsUr6S5cydlg8DPOL:wpoFD5wX26GqxhVm+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • PortableApps.com_Platform_Setup_29.5.3.paf.exe (PID: 2152)
      • PortableAppsUpdater.exe (PID: 6812)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • PortableApps.com_Platform_Setup_29.5.3.paf.exe (PID: 2152)
      • PortableAppsUpdater.exe (PID: 6812)
    • The process creates files with name similar to system file names

      • PortableApps.com_Platform_Setup_29.5.3.paf.exe (PID: 2152)
      • PortableAppsUpdater.exe (PID: 6812)
    • Executable content was dropped or overwritten

      • PortableApps.com_Platform_Setup_29.5.3.paf.exe (PID: 2152)
      • PortableAppsUpdater.exe (PID: 6812)
    • Drops 7-zip archiver for unpacking

      • PortableApps.com_Platform_Setup_29.5.3.paf.exe (PID: 2152)
    • Write to the desktop.ini file (may be used to cloak folders)

      • PortableApps.com_Platform_Setup_29.5.3.paf.exe (PID: 2152)
    • Reads security settings of Internet Explorer

      • PortableApps.com_Platform_Setup_29.5.3.paf.exe (PID: 2152)
      • PortableAppsPlatform.exe (PID: 4212)
      • PortableAppsUpdater.exe (PID: 6812)
      • Start.exe (PID: 4404)
    • Checks for Java to be installed

      • PortableAppsPlatform.exe (PID: 4212)
    • Reads the date of Windows installation

      • PortableAppsPlatform.exe (PID: 4212)
      • Start.exe (PID: 4404)
    • Creates file in the systems drive root

      • PortableAppsPlatform.exe (PID: 4212)
    • Checks Windows Trust Settings

      • PortableAppsUpdater.exe (PID: 6812)
  • INFO

    • Reads the computer name

      • PortableApps.com_Platform_Setup_29.5.3.paf.exe (PID: 2152)
      • Start.exe (PID: 4404)
      • PortableAppsPlatform.exe (PID: 4212)
      • PortableAppsUpdater.exe (PID: 6812)
      • TextInputHost.exe (PID: 364)
      • 7za.exe (PID: 4648)
    • Checks supported languages

      • PortableApps.com_Platform_Setup_29.5.3.paf.exe (PID: 2152)
      • Start.exe (PID: 4404)
      • PortableAppsPlatform.exe (PID: 4212)
      • PortableAppsUpdater.exe (PID: 6812)
      • 7za.exe (PID: 4648)
      • TextInputHost.exe (PID: 364)
    • Create files in a temporary directory

      • PortableApps.com_Platform_Setup_29.5.3.paf.exe (PID: 2152)
      • PortableAppsUpdater.exe (PID: 6812)
      • 7za.exe (PID: 4648)
    • Checks proxy server information

      • slui.exe (PID: 5576)
      • PortableAppsUpdater.exe (PID: 6812)
    • Reads the software policy settings

      • slui.exe (PID: 5576)
      • PortableAppsUpdater.exe (PID: 6812)
    • Reads Environment values

      • Start.exe (PID: 4404)
      • PortableAppsUpdater.exe (PID: 6812)
      • PortableAppsPlatform.exe (PID: 4212)
    • Process checks computer location settings

      • Start.exe (PID: 4404)
      • PortableAppsPlatform.exe (PID: 4212)
    • Reads the machine GUID from the registry

      • PortableAppsUpdater.exe (PID: 6812)
    • Creates files or folders in the user directory

      • PortableAppsUpdater.exe (PID: 6812)
    • Manual execution by a user

      • Taskmgr.exe (PID: 4636)
    • Reads security settings of Internet Explorer

      • Taskmgr.exe (PID: 4636)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:30 16:56:02+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 412160
UninitializedDataSize: 16384
EntryPoint: 0x3665
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 29.5.3.0
ProductVersionNumber: 29.5.3.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: For additional details, visit PortableApps.com
CompanyName: PortableApps.com
FileDescription: PortableApps.com Platform
FileVersion: 29.5.3.0
InternalName: PortableApps.com Platform
LegalCopyright: PortableApps.com
LegalTrademarks: PortableApps.com is a registered trademark of Rare Ideas, LLC.
OriginalFileName: PortableApps.com_Platform_Setup_29.5.3.paf.exe
PortableAppscomAppID: PortableApps.com
PortableAppscomFormatVersion: 3.8.0.0
PortableAppscomInstallerVersion: 3.8.3.0
ProductName: PortableApps.com Platform
ProductVersion: 29.5.3.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
145
Monitored processes
9
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start portableapps.com_platform_setup_29.5.3.paf.exe slui.exe start.exe no specs portableappsplatform.exe no specs portableappsupdater.exe textinputhost.exe no specs 7za.exe no specs conhost.exe no specs taskmgr.exe

Process information

PID
CMD
Path
Indicators
Parent process
364"C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mcaC:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Version:
123.26505.0.0
Modules
Images
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\textinputhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\vcruntime140_app.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
2152"C:\Users\admin\Desktop\PortableApps.com_Platform_Setup_29.5.3.paf.exe" C:\Users\admin\Desktop\PortableApps.com_Platform_Setup_29.5.3.paf.exe
explorer.exe
User:
admin
Company:
PortableApps.com
Integrity Level:
MEDIUM
Description:
PortableApps.com Platform
Exit code:
0
Version:
29.5.3.0
Modules
Images
c:\users\admin\desktop\portableapps.com_platform_setup_29.5.3.paf.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4212"C:\Users\admin\Desktop\PortableApps\PortableApps.com\PortableAppsPlatform.exe" C:\Users\admin\Desktop\PortableApps\PortableApps.com\PortableAppsPlatform.exeStart.exe
User:
admin
Company:
PortableApps.com
Integrity Level:
MEDIUM
Description:
PortableApps.com Platform
Version:
29.5.3.0
Modules
Images
c:\users\admin\desktop\portableapps\portableapps.com\portableappsplatform.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
4404C:\Users\admin\Desktop\Start.exeC:\Users\admin\Desktop\Start.exePortableApps.com_Platform_Setup_29.5.3.paf.exe
User:
admin
Company:
PortableApps.com
Integrity Level:
MEDIUM
Description:
Start PortableApps.com
Exit code:
0
Version:
29.5.3.0
Modules
Images
c:\users\admin\desktop\start.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
4636"C:\WINDOWS\system32\taskmgr.exe" /7C:\Windows\System32\Taskmgr.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Manager
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
4648"C:\Users\admin\Desktop\PortableApps\PortableApps.com\App\7-Zip\7za.exe" x "C:\Users\admin\AppData\Local\Temp\nsk9C44.tmp\update.7z" -o"C:\Users\admin\AppData\Local\Temp\nsk9C44.tmp" -aoaC:\Users\admin\Desktop\PortableApps\PortableApps.com\App\7-Zip\7za.exePortableAppsUpdater.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip Console
Exit code:
0
Version:
24.07
Modules
Images
c:\users\admin\desktop\portableapps\portableapps.com\app\7-zip\7za.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
5576C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6364\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe7za.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6812"C:\Users\admin\Desktop\PortableApps\PortableApps.com\PortableAppsUpdater.exe" /MODE=ADD /SHOWFREEWARE=all /KEYBOARDFRIENDLY=false /ADVANCED=false /SHOWINSTALLEDAPPS=false /HIDEPORTABLE=true /BETA=false /HIDE64BIT=false /INSTALL32BITDUALMODE=always /CONNECTION=AutomaticC:\Users\admin\Desktop\PortableApps\PortableApps.com\PortableAppsUpdater.exe
PortableAppsPlatform.exe
User:
admin
Company:
PortableApps.com
Integrity Level:
MEDIUM
Description:
PortableApps.com Updater
Version:
29.5.3.0
Modules
Images
c:\users\admin\desktop\portableapps\portableapps.com\portableappsupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
11 465
Read events
11 435
Write events
29
Delete events
1

Modification events

(PID) Process:(4404) Start.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4404) Start.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(4404) Start.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(4404) Start.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(4212) PortableAppsPlatform.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\TPG\Recognizers
Operation:writeName:GestureTimeout
Value:
1500
(PID) Process:(4212) PortableAppsPlatform.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4212) PortableAppsPlatform.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(4212) PortableAppsPlatform.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(4212) PortableAppsPlatform.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6812) PortableAppsUpdater.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
34
Suspicious files
4
Text files
1 028
Unknown types
0

Dropped files

PID
Process
Filename
Type
2152PortableApps.com_Platform_Setup_29.5.3.paf.exeC:\Users\admin\AppData\Local\Temp\nsd1EEF.tmp\InstallTypeUpgrade.icoimage
MD5:36348EA4D162CB644A091DA23028CEFE
SHA256:73EC55F223634FD221CDB947646FF2A75041B8285C6B183EEFD671FD30F039E9
2152PortableApps.com_Platform_Setup_29.5.3.paf.exeC:\Users\admin\AppData\Local\Temp\nsd1EEF.tmp\System.dllexecutable
MD5:192639861E3DC2DC5C08BB8F8C7260D5
SHA256:23D618A0293C78CE00F7C6E6DD8B8923621DA7DD1F63A070163EF4C0EC3033D6
2152PortableApps.com_Platform_Setup_29.5.3.paf.exeC:\Users\admin\AppData\Local\Temp\nsd1EEF.tmp\InstallCloudDropbox.icoimage
MD5:C057C8276F42ED3EA043FAFFEFD2184E
SHA256:F51EA28292105EE4209BB1CD80536D57D23B18259E313A3A6424E6F6F62800CA
2152PortableApps.com_Platform_Setup_29.5.3.paf.exeC:\Users\admin\Desktop\Documents\Pictures\Desktop.iniini
MD5:B5252A47DD57F7349A9D464B5820295D
SHA256:416483A71A9763A1CF2D80BD803A305828494317DA667FE1470395400D95CB60
2152PortableApps.com_Platform_Setup_29.5.3.paf.exeC:\Users\admin\AppData\Local\Temp\nsd1EEF.tmp\InstallCloudBox.icoimage
MD5:8230E343310B8AD58A3642466FFC0CA0
SHA256:4FE8A7B7618E0DDE72117437A6583BB14B5A0E0B9215DBEEABDE6CC404977821
2152PortableApps.com_Platform_Setup_29.5.3.paf.exeC:\Users\admin\Desktop\Documents\Music\Desktop.initext
MD5:83AA1C1DAAF9121E71542DA4141C086D
SHA256:A31E98134CF18699700E32DF10D82FE90EDAFC2FFB0584B89F9ED98C6CA5C5CB
2152PortableApps.com_Platform_Setup_29.5.3.paf.exeC:\Users\admin\AppData\Local\Temp\nsd1EEF.tmp\InstallCloudGoogleDrive.icoimage
MD5:8F8E5010A8B7DB88F0DDF093B726053F
SHA256:43CCCB5BF1E5BAF646B419F33E461D2DC265EA758C4C8FF70F1AC5AA17B0DDD4
2152PortableApps.com_Platform_Setup_29.5.3.paf.exeC:\Users\admin\AppData\Local\Temp\nsd1EEF.tmp\InstallTypeLocalAllUsers.icoimage
MD5:CE880C8089E8DB48164E5A25D7DA7BB7
SHA256:76838E210EA7A131C97D329F603FBB80C4419C4C7748F682FF6B4BAB23EED715
2152PortableApps.com_Platform_Setup_29.5.3.paf.exeC:\Users\admin\AppData\Local\Temp\nsd1EEF.tmp\nsDialogs.dllexecutable
MD5:B7D61F3F56ABF7B7FF0D4E7DA3AD783D
SHA256:89A82C4849C21DFE765052681E1FAD02D2D7B13C8B5075880C52423DCA72A912
2152PortableApps.com_Platform_Setup_29.5.3.paf.exeC:\Users\admin\Desktop\Documents\Desktop.iniini
MD5:D587E3AD01C34A686DDA51EBDAC02A15
SHA256:0EE7ECEFB5E14F073721E20377D2CBCE0CFA25D44CB05E8E9994492086BA8D04
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
57
DNS requests
30
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6812
PortableAppsUpdater.exe
GET
200
95.101.54.131:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgR0ZiEOoTZWMH3%2B6eRfyY97xA%3D%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
239.255.255.250:1900
whitelisted
6012
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3076
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3800
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4204
svchost.exe
4.208.221.206:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
3360
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5368
SearchApp.exe
2.23.209.130:443
www.bing.com
Akamai International B.V.
GB
unknown
5272
svchost.exe
40.126.32.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
  • 51.124.78.146
whitelisted
google.com
  • 216.58.206.46
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted
www.bing.com
  • 2.23.209.130
  • 2.23.209.133
  • 2.23.209.187
  • 2.23.209.182
whitelisted
login.live.com
  • 40.126.32.68
  • 20.190.160.22
  • 20.190.160.17
  • 20.190.160.20
  • 20.190.160.14
  • 40.126.32.133
  • 40.126.32.72
  • 40.126.32.76
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted
slscr.update.microsoft.com
  • 40.127.169.103
whitelisted

Threats

No threats detected
No debug info