File name:

ZoomInfoContactContributor-57-3.exe

Full analysis: https://app.any.run/tasks/9d75db2d-1526-4322-8be0-c6e606fdcec6
Verdict: Malicious activity
Analysis date: October 31, 2023, 03:05:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

0C4CBC3957BD9651AF06F76AD32B1FA2

SHA1:

A0C2D8CDFC71545623EA01D143F213AD66499F35

SHA256:

C5CCC464818ECCA316D98C67A79FC51192835CBC1EBA3060A22537D0382EEB41

SSDEEP:

3072:FHonJ5U5TPVobeaOETMsfKnFgem6Nh2/Qz1Kz+Rd4CYM:FHoPUlPeDOETMXiYQB8d4CY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • ZoomInfoContactContributor-57-3.exe (PID: 3820)
      • coordinator.exe (PID: 1648)
    • Application was dropped or rewritten from another process

      • ZoomInfoContactContributor-57-3.exe (PID: 3820)
      • coordinator.exe (PID: 1648)
    • Drops the executable file immediately after the start

      • ZoomInfoContactContributor-57-3.exe (PID: 3820)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • ZoomInfoContactContributor-57-3.exe (PID: 3820)
    • The process creates files with name similar to system file names

      • ZoomInfoContactContributor-57-3.exe (PID: 3820)
    • Reads Microsoft Outlook installation path

      • ZoomInfoContactContributor-57-3.exe (PID: 3820)
    • Reads the Internet Settings

      • ZoomInfoContactContributor-57-3.exe (PID: 3820)
      • coordinator.exe (PID: 1648)
    • Process drops legitimate windows executable

      • ZoomInfoContactContributor-57-3.exe (PID: 3820)
    • Starts CMD.EXE for commands execution

      • ZoomInfoContactContributor-57-3.exe (PID: 3820)
    • Powershell version downgrade attack

      • powershell.exe (PID: 2296)
    • The process drops C-runtime libraries

      • ZoomInfoContactContributor-57-3.exe (PID: 3820)
    • Loads Python modules

      • coordinator.exe (PID: 1648)
    • Executing commands from a ".bat" file

      • ZoomInfoContactContributor-57-3.exe (PID: 3820)
  • INFO

    • Reads the computer name

      • ZoomInfoContactContributor-57-3.exe (PID: 3820)
      • coordinator.exe (PID: 1648)
    • Checks supported languages

      • ZoomInfoContactContributor-57-3.exe (PID: 3820)
      • coordinator.exe (PID: 1648)
    • Reads Microsoft Office registry keys

      • ZoomInfoContactContributor-57-3.exe (PID: 3820)
      • coordinator.exe (PID: 1648)
    • Manual execution by a user

      • OUTLOOK.EXE (PID: 4076)
      • powershell.exe (PID: 2296)
    • Create files in a temporary directory

      • ZoomInfoContactContributor-57-3.exe (PID: 3820)
      • coordinator.exe (PID: 1648)
    • Checks proxy server information

      • ZoomInfoContactContributor-57-3.exe (PID: 3820)
      • coordinator.exe (PID: 1648)
    • Reads Internet Explorer settings

      • OUTLOOK.EXE (PID: 4076)
    • Creates files or folders in the user directory

      • ZoomInfoContactContributor-57-3.exe (PID: 3820)
      • coordinator.exe (PID: 1648)
    • The executable file from the user directory is run by the CMD process

      • coordinator.exe (PID: 1648)
    • Application launched itself

      • msedge.exe (PID: 3520)
    • Reads the machine GUID from the registry

      • coordinator.exe (PID: 1648)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (94.8)
.exe | Win32 Executable MS Visual C++ (generic) (3.4)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.5)
.exe | Generic Win/DOS Executable (0.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:12:05 23:50:52+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24064
InitializedDataSize: 164864
UninitializedDataSize: 1024
EntryPoint: 0x30fa
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.57
ProductVersionNumber: 2.0.0.57
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: ASCII
FileDescription: -
FileVersion: 57
LegalCopyright: (c) Zoom Information, Inc.
ProductName: ZoomInfo Contact Contributor
ProductVersion: 57
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
67
Monitored processes
24
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start zoominfocontactcontributor-57-3.exe outlook.exe outlook.exe no specs cmd.exe no specs coordinator.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs powershell.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
316C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\ZoomInfoCEUtility\launch.bat""C:\Windows\System32\cmd.exeZoomInfoContactContributor-57-3.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1032"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2252 --field-trial-handle=1264,i,17191271930167694979,2564428226484504911,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptbase.dll
1244"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1244 --field-trial-handle=1264,i,17191271930167694979,2564428226484504911,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\cryptbase.dll
1244"C:\Windows\system32\notepad.exe" C:\Users\admin\AppData\Local\ZoomInfoCEUtility\launch.batC:\Windows\System32\notepad.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1620"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3956 --field-trial-handle=1264,i,17191271930167694979,2564428226484504911,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptbase.dll
1648"C:\Users\admin\AppData\Local\ZoomInfoCEUtility\2258\coordinator.exe" C:\Users\admin\AppData\Local\ZoomInfoCEUtility\2258\coordinator.exe
cmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\zoominfoceutility\2258\coordinator.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\usp10.dll
2128"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=1460 --field-trial-handle=1264,i,17191271930167694979,2564428226484504911,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2296"C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe" C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
2812"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3220 --field-trial-handle=1264,i,17191271930167694979,2564428226484504911,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
2860"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2284 --field-trial-handle=1264,i,17191271930167694979,2564428226484504911,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptbase.dll
Total events
18 450
Read events
18 203
Write events
218
Delete events
29

Modification events

(PID) Process:(4076) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
On
(PID) Process:(4076) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1041
Value:
On
(PID) Process:(4076) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1046
Value:
On
(PID) Process:(4076) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1036
Value:
On
(PID) Process:(4076) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1031
Value:
On
(PID) Process:(4076) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1040
Value:
On
(PID) Process:(4076) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1049
Value:
On
(PID) Process:(4076) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:3082
Value:
On
(PID) Process:(4076) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1042
Value:
On
(PID) Process:(4076) OUTLOOK.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1055
Value:
On
Executable files
231
Suspicious files
680
Text files
1 045
Unknown types
28

Dropped files

PID
Process
Filename
Type
4076OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\CVR45FB.tmp.cvr
MD5:
SHA256:
4076OUTLOOK.EXEC:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
MD5:
SHA256:
3328OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\CVR66F0.tmp.cvr
MD5:
SHA256:
3820ZoomInfoContactContributor-57-3.exeC:\Users\admin\AppData\Local\ZoomInfoCEUtility\ZoomInfo_Grow.zip
MD5:
SHA256:
3820ZoomInfoContactContributor-57-3.exeC:\Users\admin\AppData\Local\Temp\nsoB053.tmp\FindProcDLL.dllexecutable
MD5:83CD62EAB980E3D64C131799608C8371
SHA256:A6122E80F1C51DC72770B4F56C7C482F7A9571143FBF83B19C4D141D0CB19294
4076OUTLOOK.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\{6B7F08BB-0D35-42F8-8996-E4B265053B78}\{E82FFC11-EE89-4AB6-9975-B29FF5DFF0B9}.htmlhtml
MD5:DEA0BA939CD3FAD9D51A03EBA582BF69
SHA256:DB7764BB46A6CFCFF4902CD048564B058E3583BE6FF8D2C5EF00279E29ECEC0B
3820ZoomInfoContactContributor-57-3.exeC:\Users\admin\AppData\Local\Temp\nsoB053.tmp\nsDialogs.dllexecutable
MD5:C10E04DD4AD4277D5ADC951BB331C777
SHA256:E31AD6C6E82E603378CB6B80E67D0E0DCD9CF384E1199AC5A65CB4935680021A
3820ZoomInfoContactContributor-57-3.exeC:\Users\admin\AppData\Local\Temp\nsoB053.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
3820ZoomInfoContactContributor-57-3.exeC:\Users\admin\AppData\Local\Temp\nsoB053.tmp\GetVersion.dllexecutable
MD5:2E2412281A205ED8D53AAFB3EF770A2D
SHA256:DB09ADB6E17B6A0B31823802431FF5209018EE8C77A193AC8077E42E5F15FB00
4076OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\mso6732.tmphtml
MD5:A8934077843220A8E31367C7BBE15E6C
SHA256:A2DB0201D36F07F3F99D1ADF8B8EAFB9CF9BB803D024FCC9327B77AF56346861
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
25
DNS requests
28
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3820
ZoomInfoContactContributor-57-3.exe
GET
302
216.58.213.115:80
http://cswapper.freshcontacts.com/client/download2?client_version=57&client_id={A1CF6C7A-BFA7-4AE5-AAB9-0B3E769D0A79}&outlook_bitness=32&reachout=true&appid=3
unknown
unknown
3912
msedge.exe
GET
302
142.250.187.147:80
http://cswapper.freshcontacts.com/client/installsuccess?client_version=57&os_version=Windows%206.1%20Service%20Pack%201%207601%2032%20[%20]&outlook_version=14&outlook_bitness=32&autostart=1&client_id={A1CF6C7A-BFA7-4AE5-AAB9-0B3E769D0A79}&reachout=true&appid=3
unknown
unknown
3820
ZoomInfoContactContributor-57-3.exe
GET
200
142.251.140.91:80
http://storage.googleapis.com/coordinator-packages-public/swapper-2258.zip
unknown
compressed
89.7 Mb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2656
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
unknown
4
System
192.168.100.255:137
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
4076
OUTLOOK.EXE
64.4.26.155:80
config.messenger.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3820
ZoomInfoContactContributor-57-3.exe
216.58.213.115:80
cswapper.freshcontacts.com
GOOGLE
US
unknown
3820
ZoomInfoContactContributor-57-3.exe
142.251.140.91:80
storage.googleapis.com
GOOGLE
US
unknown
3912
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3520
msedge.exe
239.255.255.250:1900
whitelisted
3912
msedge.exe
142.250.187.147:80
cswapper.freshcontacts.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
config.messenger.msn.com
  • 64.4.26.155
whitelisted
cswapper.freshcontacts.com
  • 216.58.213.115
  • 142.250.187.147
whitelisted
storage.googleapis.com
  • 142.251.140.91
  • 172.217.169.155
  • 172.217.169.219
  • 216.58.214.155
  • 142.250.184.155
  • 142.250.187.123
  • 142.250.187.155
  • 142.250.187.187
  • 172.217.17.123
  • 172.217.17.155
  • 172.217.20.91
  • 216.58.212.27
  • 216.58.212.59
  • 216.58.213.123
  • 142.251.140.27
  • 142.251.140.59
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
nav-edge.smartscreen.microsoft.com
  • 20.105.95.163
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
data-edge.smartscreen.microsoft.com
  • 20.105.95.163
whitelisted
www.zoominfo.com
  • 104.16.137.15
  • 104.16.136.15
whitelisted
www.bing.com
  • 13.107.21.200
  • 204.79.197.200
whitelisted
login.zoominfo.com
  • 104.16.137.15
  • 104.16.136.15
unknown

Threats

Found threats are available for the paid subscriptions
4 ETPRO signatures available at the full report
No debug info