File name:

OCS-Windows-Agent-2.10.1.0_x64.zip

Full analysis: https://app.any.run/tasks/f3206a20-9c55-47b8-a326-df2a11b8a8aa
Verdict: Malicious activity
Analysis date: December 18, 2024, 12:14:22
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

1AC16B261FE9D2F2500CD4112A0E60F4

SHA1:

C2729931845CF69B98AFAEB29FD1ECAB5BC9CF1E

SHA256:

BC304032CF2958160A890A3E41CEEC8472DBA4F09FFC5223FAF13E091BB00F59

SSDEEP:

98304:9jvTQuT4uIzIwkEbJ3fehUZkQhYEP/EHwezKdCkIJ/szybnwkIIlUPv82DYNgLnc:KdgpwQ1Aw+Zml

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6748)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 6748)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • OCS-Windows-Agent-Setup-x64.exe (PID: 7008)
    • The process creates files with name similar to system file names

      • OCS-Windows-Agent-Setup-x64.exe (PID: 7008)
    • Executable content was dropped or overwritten

      • OCS-Windows-Agent-Setup-x64.exe (PID: 7008)
    • Process drops legitimate windows executable

      • OCS-Windows-Agent-Setup-x64.exe (PID: 7008)
    • The process drops C-runtime libraries

      • OCS-Windows-Agent-Setup-x64.exe (PID: 7008)
    • Executes as Windows Service

      • OcsService.exe (PID: 4944)
    • Starts CMD.EXE for commands execution

      • OcsService.exe (PID: 4944)
    • Creates a software uninstall entry

      • OCS-Windows-Agent-Setup-x64.exe (PID: 7008)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6748)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 6748)
      • OCS-Windows-Agent-Setup-x64.exe (PID: 7008)
    • Reads the computer name

      • OCS-Windows-Agent-Setup-x64.exe (PID: 7008)
      • SetACL.exe (PID: 3544)
      • SetACL.exe (PID: 2072)
      • OCSInventory.exe (PID: 6160)
      • OcsService.exe (PID: 3808)
      • OcsService.exe (PID: 4944)
      • OCSInventory.exe (PID: 4672)
      • OcsSystray.exe (PID: 2432)
      • OCSInventory.exe (PID: 6172)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 6748)
    • Checks supported languages

      • OCS-Windows-Agent-Setup-x64.exe (PID: 7008)
      • SetACL.exe (PID: 3544)
      • SetACL.exe (PID: 2072)
      • OCSInventory.exe (PID: 6160)
      • OcsService.exe (PID: 3808)
      • OCSInventory.exe (PID: 4672)
      • OcsSystray.exe (PID: 2432)
      • OCSInventory.exe (PID: 6952)
      • OCSInventory.exe (PID: 6172)
      • OcsService.exe (PID: 4944)
    • Create files in a temporary directory

      • OCS-Windows-Agent-Setup-x64.exe (PID: 7008)
    • Creates files in the program directory

      • OCS-Windows-Agent-Setup-x64.exe (PID: 7008)
      • OCSInventory.exe (PID: 6160)
      • OCSInventory.exe (PID: 6952)
      • OcsService.exe (PID: 4944)
    • Reads the machine GUID from the registry

      • OcsService.exe (PID: 4944)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2022:11:18 16:09:14
ZipCRC: 0x376bcdfd
ZipCompressedSize: 731
ZipUncompressedSize: 1394
ZipFileName: OCS-Windows-Agent-2.10.1.0_x64/AUTHORS.TXT
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
21
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe ocs-windows-agent-setup-x64.exe no specs ocs-windows-agent-setup-x64.exe setacl.exe no specs conhost.exe no specs setacl.exe no specs conhost.exe no specs ocsinventory.exe no specs ocsservice.exe no specs conhost.exe no specs ocsservice.exe no specs cmd.exe no specs conhost.exe no specs ocsinventory.exe no specs ocssystray.exe no specs cmd.exe no specs conhost.exe no specs ocsinventory.exe no specs cmd.exe no specs conhost.exe no specs ocsinventory.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
624"C:\WINDOWS\system32\cmd.exe" /c "C:\Program Files\OCS Inventory Agent\ocsinventory.exe"C:\Windows\System32\cmd.exeOcsService.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Exit code:
4
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
1876\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2072C:\Users\admin\AppData\Local\Temp\nsnAA01.tmp\SetACL.exe -on "C:\ProgramData\OCS Inventory NG\Agent\Download" -ot file -actn setprot -op "dacl:np;sacl:np" -actn clear -clr "dacl,sacl" -actn rstchldrn -rst "dacl,sacl"C:\Users\admin\AppData\Local\Temp\nsnAA01.tmp\SetACL.exeOCS-Windows-Agent-Setup-x64.exe
User:
admin
Company:
Helge Klein
Integrity Level:
HIGH
Description:
SetACL
Exit code:
0
Version:
3.1.2.86
Modules
Images
c:\users\admin\appdata\local\temp\nsnaa01.tmp\setacl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2432"C:\Program Files\OCS Inventory Agent\OcsSystray.exe"C:\Program Files\OCS Inventory Agent\OcsSystray.exeOCS-Windows-Agent-Setup-x64.exe
User:
admin
Company:
OCS Inventory
Integrity Level:
HIGH
Description:
OCS Inventory Systray applet
Version:
2.10.1.0
Modules
Images
c:\program files\ocs inventory agent\ocssystray.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
3544C:\Users\admin\AppData\Local\Temp\nsnAA01.tmp\SetACL.exe -on "C:\ProgramData\OCS Inventory NG\Agent" -ot file -actn ace -ace "n:S-1-5-18;p:full;s:y;m:set" -ace "n:S-1-5-32-544;p:full;s:y;m:set" -ace "n:S-1-5-32-547;p:read_ex,change;s:y;m:set" -actn setprot -op "dacl:p_nc;sacl:p_nc" -actn clear -clr "dacl,sacl" -actn rstchldrn -rst "dacl,sacl"C:\Users\admin\AppData\Local\Temp\nsnAA01.tmp\SetACL.exeOCS-Windows-Agent-Setup-x64.exe
User:
admin
Company:
Helge Klein
Integrity Level:
HIGH
Description:
SetACL
Exit code:
0
Version:
3.1.2.86
Modules
Images
c:\users\admin\appdata\local\temp\nsnaa01.tmp\setacl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3808"C:\Program Files\OCS Inventory Agent\OcsService.exe" -installC:\Program Files\OCS Inventory Agent\OcsService.exeOCS-Windows-Agent-Setup-x64.exe
User:
admin
Company:
OCS Inventory
Integrity Level:
HIGH
Description:
OCS Inventory Service
Exit code:
0
Version:
2.10.1.0
Modules
Images
c:\program files\ocs inventory agent\ocsservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4444\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4672"C:\Program Files\OCS Inventory Agent\ocsinventory.exe"C:\Program Files\OCS Inventory Agent\OCSInventory.execmd.exe
User:
SYSTEM
Company:
OCS Inventory
Integrity Level:
SYSTEM
Description:
OCS Inventory Agent
Exit code:
4
Version:
2.10.1.0
Modules
Images
c:\program files\ocs inventory agent\ocsinventory.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ole32.dll
4864\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSetACL.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4944"C:\Program Files\OCS Inventory Agent\OcsService.exe"C:\Program Files\OCS Inventory Agent\OcsService.exeservices.exe
User:
SYSTEM
Company:
OCS Inventory
Integrity Level:
SYSTEM
Description:
OCS Inventory Service
Version:
2.10.1.0
Modules
Images
c:\program files\ocs inventory agent\ocsservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\program files\ocs inventory agent\libeay32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
Total events
4 184
Read events
4 161
Write events
23
Delete events
0

Modification events

(PID) Process:(6748) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6748) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6748) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6748) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\OCS-Windows-Agent-2.10.1.0_x64.zip
(PID) Process:(6748) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6748) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6748) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6748) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3808) OcsService.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Application\OCS Inventory Service
Operation:writeName:EventMessageFile
Value:
C:\Program Files\OCS Inventory Agent\OcsService.exe
(PID) Process:(3808) OcsService.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Application\OCS Inventory Service
Operation:writeName:TypesSupported
Value:
7
Executable files
37
Suspicious files
13
Text files
15
Unknown types
2

Dropped files

PID
Process
Filename
Type
6748WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6748.40295\OCS-Windows-Agent-2.10.1.0_x64\AUTHORS.TXTtext
MD5:461CDE85CF8E3CE7DF936E9E3622A2AA
SHA256:B85D2DA0A05376C8F16288688457A076D52F6C003DF0E89AE94E882EE2EC757B
7008OCS-Windows-Agent-Setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsnAA01.tmp\server.inibinary
MD5:5958525E3E14C75C89337A9BBA9B0506
SHA256:768BA0FB5A351AFD14F15651DED5C8FCFB12E298218542DC2C60D3AC25855C94
7008OCS-Windows-Agent-Setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsnAA01.tmp\System.dllexecutable
MD5:C9473CB90D79A374B2BA6040CA16E45C
SHA256:B80A5CBA69D1853ED5979B0CA0352437BF368A5CFB86CB4528EDADD410E11352
7008OCS-Windows-Agent-Setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsnAA01.tmp\agent.inibinary
MD5:59BE2F6EC53ADF79AB58416441EA3FD2
SHA256:0008836D0D5A633322E95EE19332B648FAC60999FD585BCC0FF04CC58FDDFDFE
6748WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6748.40295\OCS-Windows-Agent-2.10.1.0_x64\DISCLAMER.TXTtext
MD5:1E6CE3250539F2EE38496ABBC55291FC
SHA256:1F3EF2BB5419B50C5A9B91986E0B047DD4D964874F0ACC152B0D94495A2C5A48
7008OCS-Windows-Agent-Setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsnAA01.tmp\modern-header.bmpimage
MD5:8C1BB7F46693D33C7C708484F588C247
SHA256:CD40DA2B567E85619D6640FEF0F41D01CF89BED1A318219214ECC95D3AC48340
7008OCS-Windows-Agent-Setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsnAA01.tmp\agent2.inibinary
MD5:6CCA25E3DC218F69DFB668BA5C757369
SHA256:D6C1C37EA33ED35D46C0DDE6C1F5A555CB8494BBB7CC77B0D581B4DF3DED033B
7008OCS-Windows-Agent-Setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsnAA01.tmp\UserInfo.dllexecutable
MD5:200E4D67E7A08D4C92F05E31442095FE
SHA256:01D867E3A1F0AEC39A4FF02FE9FAFEFC78D6A12390A0DA8ECBF4E7DA5379E42E
7008OCS-Windows-Agent-Setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsnAA01.tmp\proxy.inibinary
MD5:B3D3D4F96EC5BF5A4F3ED48AE5CB8C9A
SHA256:B675CDB796457651293C86F6D6C265D30DBE0790CCCD08361F73AE54993BBB3A
7008OCS-Windows-Agent-Setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsnAA01.tmp\local.inibinary
MD5:06F67F6875C9F578509F1C65457875DF
SHA256:4EB25F2DF800FAAF060AFAC330B19EDE713D7218F79148428FB825652652604A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
54
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
3796
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
7080
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7080
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
104.126.37.160:443
www.bing.com
Akamai International B.V.
DE
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
192.168.100.255:138
whitelisted
1176
svchost.exe
20.190.159.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
23.35.238.131:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 88.221.169.152
whitelisted
www.bing.com
  • 104.126.37.160
  • 104.126.37.155
  • 104.126.37.163
  • 104.126.37.139
  • 104.126.37.162
  • 104.126.37.161
  • 104.126.37.153
  • 104.126.37.145
  • 104.126.37.137
  • 104.126.37.168
  • 104.126.37.171
  • 104.126.37.177
  • 104.126.37.170
  • 104.126.37.154
whitelisted
google.com
  • 172.217.16.142
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.71
  • 40.126.31.69
  • 20.190.159.0
  • 20.190.159.68
  • 20.190.159.75
  • 40.126.31.73
  • 40.126.31.71
  • 20.190.159.73
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted

Threats

No threats detected
No debug info