File name:

freetube-0.22.0-setup-x64.exe

Full analysis: https://app.any.run/tasks/90fb3e6b-a680-456f-ac06-1fa982f033c1
Verdict: Malicious activity
Analysis date: November 07, 2024, 04:31:42
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

4BA2D4200C7A9218052100ED21031E2B

SHA1:

18814638BBEC9B7BD3FE935068B43ACDD022C1A6

SHA256:

C4A643228CD9AED87F3448CDC1B8F54117A77AEF611609E00C482BF65D1A152D

SSDEEP:

786432:s16yfnh/mBhZ8uKqFUxGN1h1EMxkfkrXb2+mHgUpyF:sNnh/mBhdKqFUMNhe8v2+mHz+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • freetube-0.22.0-setup-x64.exe (PID: 4956)
    • Get information on the list of running processes

      • freetube-0.22.0-setup-x64.exe (PID: 4956)
      • cmd.exe (PID: 4292)
    • Executable content was dropped or overwritten

      • freetube-0.22.0-setup-x64.exe (PID: 4956)
    • Starts CMD.EXE for commands execution

      • freetube-0.22.0-setup-x64.exe (PID: 4956)
    • The process creates files with name similar to system file names

      • freetube-0.22.0-setup-x64.exe (PID: 4956)
    • Drops 7-zip archiver for unpacking

      • freetube-0.22.0-setup-x64.exe (PID: 4956)
    • Process drops legitimate windows executable

      • freetube-0.22.0-setup-x64.exe (PID: 4956)
    • Reads security settings of Internet Explorer

      • freetube-0.22.0-setup-x64.exe (PID: 4956)
    • Creates a software uninstall entry

      • freetube-0.22.0-setup-x64.exe (PID: 4956)
    • Application launched itself

      • FreeTube.exe (PID: 7144)
  • INFO

    • Checks supported languages

      • freetube-0.22.0-setup-x64.exe (PID: 4956)
      • FreeTube.exe (PID: 7144)
      • FreeTube.exe (PID: 4816)
      • FreeTube.exe (PID: 2684)
      • FreeTube.exe (PID: 6240)
    • Reads the computer name

      • freetube-0.22.0-setup-x64.exe (PID: 4956)
      • FreeTube.exe (PID: 7144)
      • FreeTube.exe (PID: 2684)
      • FreeTube.exe (PID: 4816)
    • Create files in a temporary directory

      • freetube-0.22.0-setup-x64.exe (PID: 4956)
      • FreeTube.exe (PID: 7144)
    • Creates files or folders in the user directory

      • freetube-0.22.0-setup-x64.exe (PID: 4956)
      • FreeTube.exe (PID: 7144)
      • FreeTube.exe (PID: 4816)
    • Manual execution by a user

      • FreeTube.exe (PID: 7144)
    • Checks proxy server information

      • FreeTube.exe (PID: 7144)
    • Process checks computer location settings

      • FreeTube.exe (PID: 7144)
      • FreeTube.exe (PID: 6240)
    • Reads the machine GUID from the registry

      • FreeTube.exe (PID: 7144)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:12:15 22:26:14+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 473088
UninitializedDataSize: 16384
EntryPoint: 0x338f
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.22.0.0
ProductVersionNumber: 0.22.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: PrestonN
FileDescription: A private YouTube client
FileVersion: 0.22.0
LegalCopyright: Copyleft © 2020-2024 freetubeapp@protonmail.com
ProductName: FreeTube
ProductVersion: 0.22.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
123
Monitored processes
9
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start freetube-0.22.0-setup-x64.exe cmd.exe no specs conhost.exe no specs tasklist.exe no specs find.exe no specs freetube.exe no specs freetube.exe no specs freetube.exe freetube.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2684"C:\Users\admin\AppData\Local\Programs\FreeTube\FreeTube.exe" --type=gpu-process --user-data-dir="C:\Users\admin\AppData\Roaming\FreeTube" --gpu-preferences=UAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --field-trial-handle=1848,i,3760306284014865114,16894881573375648642,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand --variations-seed-version --mojo-platform-channel-handle=1836 /prefetch:2C:\Users\admin\AppData\Local\Programs\FreeTube\FreeTube.exeFreeTube.exe
User:
admin
Company:
PrestonN
Integrity Level:
LOW
Description:
A private YouTube client
Version:
0.22.0
Modules
Images
c:\users\admin\appdata\local\programs\freetube\freetube.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3620"C:\WINDOWS\system32\find.exe" "FreeTube.exe"C:\Windows\SysWOW64\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (grep) Utility
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\find.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
4292"C:\WINDOWS\system32\cmd.exe" /c tasklist /FI "USERNAME eq %USERNAME%" /FI "IMAGENAME eq FreeTube.exe" /FO csv | "C:\WINDOWS\system32\find.exe" "FreeTube.exe"C:\Windows\SysWOW64\cmd.exefreetube-0.22.0-setup-x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
4432\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4816"C:\Users\admin\AppData\Local\Programs\FreeTube\FreeTube.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --user-data-dir="C:\Users\admin\AppData\Roaming\FreeTube" --standard-schemes=app --secure-schemes=app --fetch-schemes=app --field-trial-handle=2260,i,3760306284014865114,16894881573375648642,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand --variations-seed-version --mojo-platform-channel-handle=2156 /prefetch:3C:\Users\admin\AppData\Local\Programs\FreeTube\FreeTube.exe
FreeTube.exe
User:
admin
Company:
PrestonN
Integrity Level:
MEDIUM
Description:
A private YouTube client
Version:
0.22.0
Modules
Images
c:\users\admin\appdata\local\programs\freetube\freetube.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4956"C:\Users\admin\Desktop\freetube-0.22.0-setup-x64.exe" C:\Users\admin\Desktop\freetube-0.22.0-setup-x64.exe
explorer.exe
User:
admin
Company:
PrestonN
Integrity Level:
MEDIUM
Description:
A private YouTube client
Exit code:
0
Version:
0.22.0
Modules
Images
c:\users\admin\desktop\freetube-0.22.0-setup-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6240"C:\Users\admin\AppData\Local\Programs\FreeTube\FreeTube.exe" --type=renderer --user-data-dir="C:\Users\admin\AppData\Roaming\FreeTube" --standard-schemes=app --secure-schemes=app --fetch-schemes=app --app-path="C:\Users\admin\AppData\Local\Programs\FreeTube\resources\app.asar" --no-sandbox --no-zygote --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --field-trial-handle=2948,i,3760306284014865114,16894881573375648642,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand --variations-seed-version --mojo-platform-channel-handle=2944 /prefetch:1C:\Users\admin\AppData\Local\Programs\FreeTube\FreeTube.exeFreeTube.exe
User:
admin
Company:
PrestonN
Integrity Level:
MEDIUM
Description:
A private YouTube client
Version:
0.22.0
Modules
Images
c:\users\admin\appdata\local\programs\freetube\freetube.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6332tasklist /FI "USERNAME eq admin" /FI "IMAGENAME eq FreeTube.exe" /FO csv C:\Windows\SysWOW64\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
7144"C:\Users\admin\AppData\Local\Programs\FreeTube\FreeTube.exe" C:\Users\admin\AppData\Local\Programs\FreeTube\FreeTube.exeexplorer.exe
User:
admin
Company:
PrestonN
Integrity Level:
MEDIUM
Description:
A private YouTube client
Version:
0.22.0
Modules
Images
c:\users\admin\appdata\local\programs\freetube\freetube.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
2 339
Read events
2 307
Write events
14
Delete events
18

Modification events

(PID) Process:(4956) freetube-0.22.0-setup-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\609c326f-6a5e-5cd1-9fc0-6e966fad073f
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\Programs\FreeTube
(PID) Process:(4956) freetube-0.22.0-setup-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\609c326f-6a5e-5cd1-9fc0-6e966fad073f
Operation:writeName:KeepShortcuts
Value:
true
(PID) Process:(4956) freetube-0.22.0-setup-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\609c326f-6a5e-5cd1-9fc0-6e966fad073f
Operation:writeName:ShortcutName
Value:
FreeTube
(PID) Process:(4956) freetube-0.22.0-setup-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\609c326f-6a5e-5cd1-9fc0-6e966fad073f
Operation:writeName:DisplayName
Value:
FreeTube 0.22.0
(PID) Process:(4956) freetube-0.22.0-setup-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\609c326f-6a5e-5cd1-9fc0-6e966fad073f
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Local\Programs\FreeTube\Uninstall FreeTube.exe" /currentuser
(PID) Process:(4956) freetube-0.22.0-setup-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\609c326f-6a5e-5cd1-9fc0-6e966fad073f
Operation:writeName:QuietUninstallString
Value:
"C:\Users\admin\AppData\Local\Programs\FreeTube\Uninstall FreeTube.exe" /currentuser /S
(PID) Process:(4956) freetube-0.22.0-setup-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\609c326f-6a5e-5cd1-9fc0-6e966fad073f
Operation:writeName:DisplayVersion
Value:
0.22.0
(PID) Process:(4956) freetube-0.22.0-setup-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\609c326f-6a5e-5cd1-9fc0-6e966fad073f
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\Programs\FreeTube\FreeTube.exe,0
(PID) Process:(4956) freetube-0.22.0-setup-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\609c326f-6a5e-5cd1-9fc0-6e966fad073f
Operation:writeName:Publisher
Value:
PrestonN
(PID) Process:(4956) freetube-0.22.0-setup-x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\609c326f-6a5e-5cd1-9fc0-6e966fad073f
Operation:writeName:NoModify
Value:
1
Executable files
22
Suspicious files
162
Text files
13
Unknown types
3

Dropped files

PID
Process
Filename
Type
4956freetube-0.22.0-setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsu11E7.tmp\app-64.7z
MD5:
SHA256:
4956freetube-0.22.0-setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsu11E7.tmp\7z-out\icudtl.dat
MD5:
SHA256:
4956freetube-0.22.0-setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsu11E7.tmp\7z-out\LICENSES.chromium.html
MD5:
SHA256:
4956freetube-0.22.0-setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsu11E7.tmp\nsis7z.dllexecutable
MD5:80E44CE4895304C6A3A831310FBF8CD0
SHA256:B393F05E8FF919EF071181050E1873C9A776E1A0AE8329AEFFF7007D0CADF592
4956freetube-0.22.0-setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsu11E7.tmp\StdUtils.dllexecutable
MD5:C6A6E03F77C313B267498515488C5740
SHA256:B72E9013A6204E9F01076DC38DABBF30870D44DFC66962ADBF73619D4331601E
4956freetube-0.22.0-setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsu11E7.tmp\modern-wizard.bmpimage
MD5:52FF52EEE3B944B862C11C268A02C196
SHA256:2079F7A3EBA60E0D9EE827A7208AA052A71B384873B641DE5E299AEB8E733109
4956freetube-0.22.0-setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsu11E7.tmp\nsExec.dllexecutable
MD5:EC0504E6B8A11D5AAD43B296BEEB84B2
SHA256:5D9CEB1CE5F35AEA5F9E5A0C0EDEEEC04DFEFE0C77890C80C70E98209B58B962
4956freetube-0.22.0-setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsu11E7.tmp\7z-out\LICENSE.electron.txttext
MD5:4D42118D35941E0F664DDDBD83F633C5
SHA256:5154E165BD6C2CC0CFBCD8916498C7ABAB0497923BAFCD5CB07673FE8480087D
4956freetube-0.22.0-setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsu11E7.tmp\UAC.dllexecutable
MD5:ADB29E6B186DAA765DC750128649B63D
SHA256:2F7F8FC05DC4FD0D5CDA501B47E4433357E887BBFED7292C028D99C73B52DC08
4956freetube-0.22.0-setup-x64.exeC:\Users\admin\AppData\Local\Temp\nsu11E7.tmp\7z-out\chrome_200_percent.pakpgc
MD5:3969308AAE1DC1C2105BBD25901BCD01
SHA256:20C93F2CFD69F3249CDFD46F317B37A9432ECC0DE73323D24ECF65CE0F3C1BB6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
28
DNS requests
12
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6944
svchost.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6944
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
93.95.230.186:443
https://api.invidious.io/instances.json
unknown
ini
5.77 Kb
POST
204
104.126.37.144:443
https://www.bing.com/threshold/xls.aspx
unknown
whitelisted
GET
200
140.82.121.5:443
https://api.github.com/repos/freetubeapp/freetube/releases?per_page=1
unknown
text
56.9 Kb
whitelisted
GET
200
174.143.201.50:443
https://write.as/freetube/feed/
unknown
xml
262 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
104.126.37.128:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
6944
svchost.exe
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5488
MoUsoCoreWorker.exe
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6944
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5488
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 104.126.37.128
  • 104.126.37.168
  • 104.126.37.155
  • 104.126.37.160
  • 104.126.37.139
  • 104.126.37.145
  • 104.126.37.130
  • 104.126.37.186
  • 104.126.37.170
whitelisted
google.com
  • 142.250.185.174
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
api.invidious.io
  • 93.95.230.186
unknown
api.github.com
  • 140.82.121.6
whitelisted
write.as
  • 174.143.201.50
whitelisted
self.events.data.microsoft.com
  • 20.189.173.5
whitelisted

Threats

No threats detected
No debug info