File name:

OCS-Windows-Agent-2.10.1.0_x64.zip

Full analysis: https://app.any.run/tasks/f3206a20-9c55-47b8-a326-df2a11b8a8aa
Verdict: Malicious activity
Analysis date: December 18, 2024, 12:14:22
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

1AC16B261FE9D2F2500CD4112A0E60F4

SHA1:

C2729931845CF69B98AFAEB29FD1ECAB5BC9CF1E

SHA256:

BC304032CF2958160A890A3E41CEEC8472DBA4F09FFC5223FAF13E091BB00F59

SSDEEP:

98304:9jvTQuT4uIzIwkEbJ3fehUZkQhYEP/EHwezKdCkIJ/szybnwkIIlUPv82DYNgLnc:KdgpwQ1Aw+Zml

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6748)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 6748)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • OCS-Windows-Agent-Setup-x64.exe (PID: 7008)
    • The process creates files with name similar to system file names

      • OCS-Windows-Agent-Setup-x64.exe (PID: 7008)
    • Executable content was dropped or overwritten

      • OCS-Windows-Agent-Setup-x64.exe (PID: 7008)
    • The process drops C-runtime libraries

      • OCS-Windows-Agent-Setup-x64.exe (PID: 7008)
    • Process drops legitimate windows executable

      • OCS-Windows-Agent-Setup-x64.exe (PID: 7008)
    • Executes as Windows Service

      • OcsService.exe (PID: 4944)
    • Creates a software uninstall entry

      • OCS-Windows-Agent-Setup-x64.exe (PID: 7008)
    • Starts CMD.EXE for commands execution

      • OcsService.exe (PID: 4944)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 6748)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6748)
    • Checks supported languages

      • OCS-Windows-Agent-Setup-x64.exe (PID: 7008)
      • SetACL.exe (PID: 3544)
      • SetACL.exe (PID: 2072)
      • OCSInventory.exe (PID: 6160)
      • OcsService.exe (PID: 3808)
      • OCSInventory.exe (PID: 4672)
      • OcsService.exe (PID: 4944)
      • OCSInventory.exe (PID: 6172)
      • OcsSystray.exe (PID: 2432)
      • OCSInventory.exe (PID: 6952)
    • Reads the computer name

      • OCS-Windows-Agent-Setup-x64.exe (PID: 7008)
      • SetACL.exe (PID: 3544)
      • SetACL.exe (PID: 2072)
      • OCSInventory.exe (PID: 6160)
      • OcsService.exe (PID: 3808)
      • OcsService.exe (PID: 4944)
      • OCSInventory.exe (PID: 4672)
      • OcsSystray.exe (PID: 2432)
      • OCSInventory.exe (PID: 6172)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 6748)
      • OCS-Windows-Agent-Setup-x64.exe (PID: 7008)
    • Create files in a temporary directory

      • OCS-Windows-Agent-Setup-x64.exe (PID: 7008)
    • Creates files in the program directory

      • OCS-Windows-Agent-Setup-x64.exe (PID: 7008)
      • OCSInventory.exe (PID: 6160)
      • OcsService.exe (PID: 4944)
      • OCSInventory.exe (PID: 6952)
    • Reads the machine GUID from the registry

      • OcsService.exe (PID: 4944)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2022:11:18 16:09:14
ZipCRC: 0x376bcdfd
ZipCompressedSize: 731
ZipUncompressedSize: 1394
ZipFileName: OCS-Windows-Agent-2.10.1.0_x64/AUTHORS.TXT
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
21
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe ocs-windows-agent-setup-x64.exe no specs ocs-windows-agent-setup-x64.exe setacl.exe no specs conhost.exe no specs setacl.exe no specs conhost.exe no specs ocsinventory.exe no specs ocsservice.exe no specs conhost.exe no specs ocsservice.exe no specs cmd.exe no specs conhost.exe no specs ocsinventory.exe no specs ocssystray.exe no specs cmd.exe no specs conhost.exe no specs ocsinventory.exe no specs cmd.exe no specs conhost.exe no specs ocsinventory.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
624"C:\WINDOWS\system32\cmd.exe" /c "C:\Program Files\OCS Inventory Agent\ocsinventory.exe"C:\Windows\System32\cmd.exeOcsService.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Exit code:
4
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
1876\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2072C:\Users\admin\AppData\Local\Temp\nsnAA01.tmp\SetACL.exe -on "C:\ProgramData\OCS Inventory NG\Agent\Download" -ot file -actn setprot -op "dacl:np;sacl:np" -actn clear -clr "dacl,sacl" -actn rstchldrn -rst "dacl,sacl"C:\Users\admin\AppData\Local\Temp\nsnAA01.tmp\SetACL.exeOCS-Windows-Agent-Setup-x64.exe
User:
admin
Company:
Helge Klein
Integrity Level:
HIGH
Description:
SetACL
Exit code:
0
Version:
3.1.2.86
Modules
Images
c:\users\admin\appdata\local\temp\nsnaa01.tmp\setacl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2432"C:\Program Files\OCS Inventory Agent\OcsSystray.exe"C:\Program Files\OCS Inventory Agent\OcsSystray.exeOCS-Windows-Agent-Setup-x64.exe
User:
admin
Company:
OCS Inventory
Integrity Level:
HIGH
Description:
OCS Inventory Systray applet
Version:
2.10.1.0
Modules
Images
c:\program files\ocs inventory agent\ocssystray.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
3544C:\Users\admin\AppData\Local\Temp\nsnAA01.tmp\SetACL.exe -on "C:\ProgramData\OCS Inventory NG\Agent" -ot file -actn ace -ace "n:S-1-5-18;p:full;s:y;m:set" -ace "n:S-1-5-32-544;p:full;s:y;m:set" -ace "n:S-1-5-32-547;p:read_ex,change;s:y;m:set" -actn setprot -op "dacl:p_nc;sacl:p_nc" -actn clear -clr "dacl,sacl" -actn rstchldrn -rst "dacl,sacl"C:\Users\admin\AppData\Local\Temp\nsnAA01.tmp\SetACL.exeOCS-Windows-Agent-Setup-x64.exe
User:
admin
Company:
Helge Klein
Integrity Level:
HIGH
Description:
SetACL
Exit code:
0
Version:
3.1.2.86
Modules
Images
c:\users\admin\appdata\local\temp\nsnaa01.tmp\setacl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
3808"C:\Program Files\OCS Inventory Agent\OcsService.exe" -installC:\Program Files\OCS Inventory Agent\OcsService.exeOCS-Windows-Agent-Setup-x64.exe
User:
admin
Company:
OCS Inventory
Integrity Level:
HIGH
Description:
OCS Inventory Service
Exit code:
0
Version:
2.10.1.0
Modules
Images
c:\program files\ocs inventory agent\ocsservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4444\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4672"C:\Program Files\OCS Inventory Agent\ocsinventory.exe"C:\Program Files\OCS Inventory Agent\OCSInventory.execmd.exe
User:
SYSTEM
Company:
OCS Inventory
Integrity Level:
SYSTEM
Description:
OCS Inventory Agent
Exit code:
4
Version:
2.10.1.0
Modules
Images
c:\program files\ocs inventory agent\ocsinventory.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ole32.dll
4864\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeSetACL.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4944"C:\Program Files\OCS Inventory Agent\OcsService.exe"C:\Program Files\OCS Inventory Agent\OcsService.exeservices.exe
User:
SYSTEM
Company:
OCS Inventory
Integrity Level:
SYSTEM
Description:
OCS Inventory Service
Version:
2.10.1.0
Modules
Images
c:\program files\ocs inventory agent\ocsservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\program files\ocs inventory agent\libeay32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
Total events
4 184
Read events
4 161
Write events
23
Delete events
0

Modification events

(PID) Process:(6748) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6748) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6748) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6748) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\OCS-Windows-Agent-2.10.1.0_x64.zip
(PID) Process:(6748) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6748) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6748) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6748) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3808) OcsService.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Application\OCS Inventory Service
Operation:writeName:EventMessageFile
Value:
C:\Program Files\OCS Inventory Agent\OcsService.exe
(PID) Process:(3808) OcsService.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Application\OCS Inventory Service
Operation:writeName:TypesSupported
Value:
7
Executable files
37
Suspicious files
13
Text files
15
Unknown types
2

Dropped files

PID
Process
Filename
Type
6748WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6748.40295\OCS-Windows-Agent-2.10.1.0_x64\CHANGELOGtext
MD5:B5FE24B59C801B14E2F0095865685DA6
SHA256:BC2265453F330D9A7316082DABBB02DDD4FEF97883715D2F4A316FEC2339B172
6748WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6748.40295\OCS-Windows-Agent-2.10.1.0_x64\AUTHORS.TXTtext
MD5:461CDE85CF8E3CE7DF936E9E3622A2AA
SHA256:B85D2DA0A05376C8F16288688457A076D52F6C003DF0E89AE94E882EE2EC757B
6748WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6748.40295\OCS-Windows-Agent-2.10.1.0_x64\DISCLAMER.TXTtext
MD5:1E6CE3250539F2EE38496ABBC55291FC
SHA256:1F3EF2BB5419B50C5A9B91986E0B047DD4D964874F0ACC152B0D94495A2C5A48
7008OCS-Windows-Agent-Setup-x64.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6748.40295\OCS-Windows-Agent-2.10.1.0_x64\OCS-Windows-Agent-Setup-x64.logtext
MD5:85CB0A7C85F412D906A259BF9492EE74
SHA256:432203B41A8E419BCD746E5922A2EB43C3502C6799302F117D59DC58D1E662FC
7008OCS-Windows-Agent-Setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsnAA01.tmp\advsplash.dllexecutable
MD5:88C3BA1802AEF228541820767453E058
SHA256:2722555EC1F72523774B64D25FD4C2B460000BFE82140876D6100DC4FB1F62B1
7008OCS-Windows-Agent-Setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsnAA01.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
7008OCS-Windows-Agent-Setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsnAA01.tmp\modern-header.bmpimage
MD5:8C1BB7F46693D33C7C708484F588C247
SHA256:CD40DA2B567E85619D6640FEF0F41D01CF89BED1A318219214ECC95D3AC48340
7008OCS-Windows-Agent-Setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsnAA01.tmp\UserInfo.dllexecutable
MD5:200E4D67E7A08D4C92F05E31442095FE
SHA256:01D867E3A1F0AEC39A4FF02FE9FAFEFC78D6A12390A0DA8ECBF4E7DA5379E42E
7008OCS-Windows-Agent-Setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsnAA01.tmp\nsDialogs.dllexecutable
MD5:12465CE89D3853918ED3476D70223226
SHA256:5157FE688CCA27D348171BD5A8B117DE348C0844CA5CB82BC68CBD7D873A3FDC
6748WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa6748.40295\OCS-Windows-Agent-2.10.1.0_x64\LICENSE.TXTtext
MD5:EE2216A32601B1FFBFDC6E855BDC8294
SHA256:F033BD077056CF6E22FB662A36D75E7F84A079A8A5F11ECC90F754119D88A51B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
54
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3796
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
7080
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7080
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
104.126.37.160:443
www.bing.com
Akamai International B.V.
DE
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
192.168.100.255:138
whitelisted
1176
svchost.exe
20.190.159.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
23.35.238.131:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 184.30.21.171
  • 88.221.169.152
whitelisted
www.bing.com
  • 104.126.37.160
  • 104.126.37.155
  • 104.126.37.163
  • 104.126.37.139
  • 104.126.37.162
  • 104.126.37.161
  • 104.126.37.153
  • 104.126.37.145
  • 104.126.37.137
  • 104.126.37.168
  • 104.126.37.171
  • 104.126.37.177
  • 104.126.37.170
  • 104.126.37.154
whitelisted
google.com
  • 172.217.16.142
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.71
  • 40.126.31.69
  • 20.190.159.0
  • 20.190.159.68
  • 20.190.159.75
  • 40.126.31.73
  • 40.126.31.71
  • 20.190.159.73
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted

Threats

No threats detected
No debug info