File name:

PortableApps.com_Platform_Setup_29.5.3.paf.exe

Full analysis: https://app.any.run/tasks/831af95b-cd7d-49be-9e0a-7fb4cdb0d939
Verdict: Malicious activity
Analysis date: July 23, 2024, 01:04:15
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

FA3CFE5874612ACE62AC41853200EFA6

SHA1:

D7C6263C99DBC271AC54260BB44C3336AC857AD6

SHA256:

B6FB17E3B8DAE7036AD95FE90608CF3A673973D3342F42311586672790328A27

SSDEEP:

98304:NaX6stlTIixW7qizkvNsMR3vXnHO+0BFe2OoiphqepmEe7MqsUr6S5cydlg8DPOL:wpoFD5wX26GqxhVm+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • PortableApps.com_Platform_Setup_29.5.3.paf.exe (PID: 2152)
      • PortableAppsUpdater.exe (PID: 6812)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • PortableApps.com_Platform_Setup_29.5.3.paf.exe (PID: 2152)
      • PortableAppsUpdater.exe (PID: 6812)
    • The process creates files with name similar to system file names

      • PortableApps.com_Platform_Setup_29.5.3.paf.exe (PID: 2152)
      • PortableAppsUpdater.exe (PID: 6812)
    • Executable content was dropped or overwritten

      • PortableApps.com_Platform_Setup_29.5.3.paf.exe (PID: 2152)
      • PortableAppsUpdater.exe (PID: 6812)
    • Drops 7-zip archiver for unpacking

      • PortableApps.com_Platform_Setup_29.5.3.paf.exe (PID: 2152)
    • Write to the desktop.ini file (may be used to cloak folders)

      • PortableApps.com_Platform_Setup_29.5.3.paf.exe (PID: 2152)
    • Reads security settings of Internet Explorer

      • PortableApps.com_Platform_Setup_29.5.3.paf.exe (PID: 2152)
      • Start.exe (PID: 4404)
      • PortableAppsPlatform.exe (PID: 4212)
      • PortableAppsUpdater.exe (PID: 6812)
    • Reads the date of Windows installation

      • Start.exe (PID: 4404)
      • PortableAppsPlatform.exe (PID: 4212)
    • Checks for Java to be installed

      • PortableAppsPlatform.exe (PID: 4212)
    • Creates file in the systems drive root

      • PortableAppsPlatform.exe (PID: 4212)
    • Checks Windows Trust Settings

      • PortableAppsUpdater.exe (PID: 6812)
  • INFO

    • Checks supported languages

      • PortableApps.com_Platform_Setup_29.5.3.paf.exe (PID: 2152)
      • PortableAppsPlatform.exe (PID: 4212)
      • Start.exe (PID: 4404)
      • PortableAppsUpdater.exe (PID: 6812)
      • TextInputHost.exe (PID: 364)
      • 7za.exe (PID: 4648)
    • Reads the computer name

      • PortableApps.com_Platform_Setup_29.5.3.paf.exe (PID: 2152)
      • Start.exe (PID: 4404)
      • PortableAppsPlatform.exe (PID: 4212)
      • PortableAppsUpdater.exe (PID: 6812)
      • TextInputHost.exe (PID: 364)
      • 7za.exe (PID: 4648)
    • Create files in a temporary directory

      • PortableApps.com_Platform_Setup_29.5.3.paf.exe (PID: 2152)
      • PortableAppsUpdater.exe (PID: 6812)
      • 7za.exe (PID: 4648)
    • Reads the software policy settings

      • slui.exe (PID: 5576)
      • PortableAppsUpdater.exe (PID: 6812)
    • Checks proxy server information

      • slui.exe (PID: 5576)
      • PortableAppsUpdater.exe (PID: 6812)
    • Process checks computer location settings

      • Start.exe (PID: 4404)
      • PortableAppsPlatform.exe (PID: 4212)
    • Reads Environment values

      • Start.exe (PID: 4404)
      • PortableAppsPlatform.exe (PID: 4212)
      • PortableAppsUpdater.exe (PID: 6812)
    • Manual execution by a user

      • Taskmgr.exe (PID: 4636)
    • Reads security settings of Internet Explorer

      • Taskmgr.exe (PID: 4636)
    • Reads the machine GUID from the registry

      • PortableAppsUpdater.exe (PID: 6812)
    • Creates files or folders in the user directory

      • PortableAppsUpdater.exe (PID: 6812)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:30 16:56:02+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 412160
UninitializedDataSize: 16384
EntryPoint: 0x3665
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 29.5.3.0
ProductVersionNumber: 29.5.3.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: For additional details, visit PortableApps.com
CompanyName: PortableApps.com
FileDescription: PortableApps.com Platform
FileVersion: 29.5.3.0
InternalName: PortableApps.com Platform
LegalCopyright: PortableApps.com
LegalTrademarks: PortableApps.com is a registered trademark of Rare Ideas, LLC.
OriginalFileName: PortableApps.com_Platform_Setup_29.5.3.paf.exe
PortableAppscomAppID: PortableApps.com
PortableAppscomFormatVersion: 3.8.0.0
PortableAppscomInstallerVersion: 3.8.3.0
ProductName: PortableApps.com Platform
ProductVersion: 29.5.3.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
145
Monitored processes
9
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start portableapps.com_platform_setup_29.5.3.paf.exe slui.exe start.exe no specs portableappsplatform.exe no specs portableappsupdater.exe textinputhost.exe no specs 7za.exe no specs conhost.exe no specs taskmgr.exe

Process information

PID
CMD
Path
Indicators
Parent process
364"C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mcaC:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Version:
123.26505.0.0
Modules
Images
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\textinputhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\systemapps\microsoftwindows.client.cbs_cw5n1h2txyewy\vcruntime140_app.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
2152"C:\Users\admin\Desktop\PortableApps.com_Platform_Setup_29.5.3.paf.exe" C:\Users\admin\Desktop\PortableApps.com_Platform_Setup_29.5.3.paf.exe
explorer.exe
User:
admin
Company:
PortableApps.com
Integrity Level:
MEDIUM
Description:
PortableApps.com Platform
Exit code:
0
Version:
29.5.3.0
Modules
Images
c:\users\admin\desktop\portableapps.com_platform_setup_29.5.3.paf.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4212"C:\Users\admin\Desktop\PortableApps\PortableApps.com\PortableAppsPlatform.exe" C:\Users\admin\Desktop\PortableApps\PortableApps.com\PortableAppsPlatform.exeStart.exe
User:
admin
Company:
PortableApps.com
Integrity Level:
MEDIUM
Description:
PortableApps.com Platform
Version:
29.5.3.0
Modules
Images
c:\users\admin\desktop\portableapps\portableapps.com\portableappsplatform.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
4404C:\Users\admin\Desktop\Start.exeC:\Users\admin\Desktop\Start.exePortableApps.com_Platform_Setup_29.5.3.paf.exe
User:
admin
Company:
PortableApps.com
Integrity Level:
MEDIUM
Description:
Start PortableApps.com
Exit code:
0
Version:
29.5.3.0
Modules
Images
c:\users\admin\desktop\start.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
4636"C:\WINDOWS\system32\taskmgr.exe" /7C:\Windows\System32\Taskmgr.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Manager
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
4648"C:\Users\admin\Desktop\PortableApps\PortableApps.com\App\7-Zip\7za.exe" x "C:\Users\admin\AppData\Local\Temp\nsk9C44.tmp\update.7z" -o"C:\Users\admin\AppData\Local\Temp\nsk9C44.tmp" -aoaC:\Users\admin\Desktop\PortableApps\PortableApps.com\App\7-Zip\7za.exePortableAppsUpdater.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7-Zip Console
Exit code:
0
Version:
24.07
Modules
Images
c:\users\admin\desktop\portableapps\portableapps.com\app\7-zip\7za.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
5576C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6364\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe7za.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6812"C:\Users\admin\Desktop\PortableApps\PortableApps.com\PortableAppsUpdater.exe" /MODE=ADD /SHOWFREEWARE=all /KEYBOARDFRIENDLY=false /ADVANCED=false /SHOWINSTALLEDAPPS=false /HIDEPORTABLE=true /BETA=false /HIDE64BIT=false /INSTALL32BITDUALMODE=always /CONNECTION=AutomaticC:\Users\admin\Desktop\PortableApps\PortableApps.com\PortableAppsUpdater.exe
PortableAppsPlatform.exe
User:
admin
Company:
PortableApps.com
Integrity Level:
MEDIUM
Description:
PortableApps.com Updater
Version:
29.5.3.0
Modules
Images
c:\users\admin\desktop\portableapps\portableapps.com\portableappsupdater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
11 465
Read events
11 435
Write events
29
Delete events
1

Modification events

(PID) Process:(4404) Start.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4404) Start.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(4404) Start.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(4404) Start.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(4212) PortableAppsPlatform.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\TPG\Recognizers
Operation:writeName:GestureTimeout
Value:
1500
(PID) Process:(4212) PortableAppsPlatform.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4212) PortableAppsPlatform.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(4212) PortableAppsPlatform.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(4212) PortableAppsPlatform.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6812) PortableAppsUpdater.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
34
Suspicious files
4
Text files
1 028
Unknown types
0

Dropped files

PID
Process
Filename
Type
2152PortableApps.com_Platform_Setup_29.5.3.paf.exeC:\Users\admin\AppData\Local\Temp\nsd1EEF.tmp\System.dllexecutable
MD5:192639861E3DC2DC5C08BB8F8C7260D5
SHA256:23D618A0293C78CE00F7C6E6DD8B8923621DA7DD1F63A070163EF4C0EC3033D6
2152PortableApps.com_Platform_Setup_29.5.3.paf.exeC:\Users\admin\AppData\Local\Temp\nsd1EEF.tmp\LangDLL.dllexecutable
MD5:549EE11198143574F4D9953198A09FE8
SHA256:131AA0DF90C08DCE2EECEE46CCE8759E9AFFF04BF15B7B0002C2A53AE5E92C36
2152PortableApps.com_Platform_Setup_29.5.3.paf.exeC:\Users\admin\AppData\Local\Temp\nsd1EEF.tmp\InstallLocationCustom.icoimage
MD5:F83DC55D453732C387FB866CCE6A6DEC
SHA256:CD57E5E8CFC9D5570DCBB944F9FD8676F3132C8F9497659EB148A0EC77B92C8C
2152PortableApps.com_Platform_Setup_29.5.3.paf.exeC:\Users\admin\AppData\Local\Temp\nsd1EEF.tmp\InstallTypeUpgrade.icoimage
MD5:36348EA4D162CB644A091DA23028CEFE
SHA256:73EC55F223634FD221CDB947646FF2A75041B8285C6B183EEFD671FD30F039E9
2152PortableApps.com_Platform_Setup_29.5.3.paf.exeC:\Users\admin\AppData\Local\Temp\nsd1EEF.tmp\InstallTypeNew.icoimage
MD5:5BF124D896DFB5B6430EA011EE0B1501
SHA256:8A25F3B78E5EF376A25B7A4831B1179D734AF99F08FCB2C459CA4F1B9FE9A6F5
2152PortableApps.com_Platform_Setup_29.5.3.paf.exeC:\Users\admin\AppData\Local\Temp\nsd1EEF.tmp\InstallTypeLocal.icoimage
MD5:A8676F0BDFE1EE2547B87CFC6CED01DB
SHA256:1011AA4843604F7B5D6EB59A8E41B27F83007DFEC67AEF6F63FA6DFD54399E74
2152PortableApps.com_Platform_Setup_29.5.3.paf.exeC:\Users\admin\AppData\Local\Temp\nsd1EEF.tmp\InstallTypePortable.icoimage
MD5:611F381C5719498D509371E941899AEB
SHA256:3976DAC3C983E9EB276B2A00324B1577449391AB5BB9A1F8CB395213AFBF3D30
2152PortableApps.com_Platform_Setup_29.5.3.paf.exeC:\Users\admin\AppData\Local\Temp\nsd1EEF.tmp\InstallCloudGoogleDrive.icoimage
MD5:8F8E5010A8B7DB88F0DDF093B726053F
SHA256:43CCCB5BF1E5BAF646B419F33E461D2DC265EA758C4C8FF70F1AC5AA17B0DDD4
2152PortableApps.com_Platform_Setup_29.5.3.paf.exeC:\Users\admin\AppData\Local\Temp\nsd1EEF.tmp\InstallCloudOneDrive.icoimage
MD5:314ED4E313894FAD9EF7AF45D71F2D11
SHA256:1FEE7F9360E24F5C3DDD4E05AAF5368749FC60B3AB24E1AF5B86B2A8FB170612
2152PortableApps.com_Platform_Setup_29.5.3.paf.exeC:\Users\admin\AppData\Local\Temp\nsd1EEF.tmp\InstallCloudBox.icoimage
MD5:8230E343310B8AD58A3642466FFC0CA0
SHA256:4FE8A7B7618E0DDE72117437A6583BB14B5A0E0B9215DBEEABDE6CC404977821
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
57
DNS requests
30
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6812
PortableAppsUpdater.exe
GET
200
95.101.54.131:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgR0ZiEOoTZWMH3%2B6eRfyY97xA%3D%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
239.255.255.250:1900
whitelisted
6012
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3076
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3800
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4204
svchost.exe
4.208.221.206:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
3360
slui.exe
20.83.72.98:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5368
SearchApp.exe
2.23.209.130:443
www.bing.com
Akamai International B.V.
GB
unknown
5272
svchost.exe
40.126.32.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
  • 51.124.78.146
whitelisted
google.com
  • 216.58.206.46
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted
www.bing.com
  • 2.23.209.130
  • 2.23.209.133
  • 2.23.209.187
  • 2.23.209.182
whitelisted
login.live.com
  • 40.126.32.68
  • 20.190.160.22
  • 20.190.160.17
  • 20.190.160.20
  • 20.190.160.14
  • 40.126.32.133
  • 40.126.32.72
  • 40.126.32.76
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted
slscr.update.microsoft.com
  • 40.127.169.103
whitelisted

Threats

No threats detected
No debug info