File name:

Pikachu.7z

Full analysis: https://app.any.run/tasks/46995d43-19b4-43b3-8a7c-19dc4e5887f2
Verdict: Malicious activity
Analysis date: November 16, 2024, 10:57:17
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

D9EC059DBFC498E1DA8B0FE894B5EDB5

SHA1:

F3D987DD9CB11339E293BB7D10F8DE69ED30123D

SHA256:

C6C35108EBAF0350CBF6CE17B136D57F2AB9A6222F8C43DE7B9CC9C2CE33C47A

SSDEEP:

98304:/a3fADPwUEvM3ZogpX/iXh0CLLTBYmKENfDjjWrsIPqd3Fc4dcBaA6jWQLed6ZSP:9XDao9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6736)
    • Changes the autorun value in the registry

      • InfDefaultInstall.exe (PID: 2632)
      • InfDefaultInstall.exe (PID: 2076)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • PikachuW7fix.exe (PID: 3104)
      • PikachuW7fix.exe (PID: 5444)
    • Executable content was dropped or overwritten

      • PikachuW7fix.exe (PID: 3104)
      • InfDefaultInstall.exe (PID: 2632)
      • PikachuW7fix.exe (PID: 5444)
      • InfDefaultInstall.exe (PID: 2076)
    • Reads security settings of Internet Explorer

      • PikachuW7fix.exe (PID: 3104)
      • PikachuW7fix.exe (PID: 5444)
  • INFO

    • The process uses the downloaded file

      • WinRAR.exe (PID: 6736)
      • PikachuW7fix.exe (PID: 3104)
      • runonce.exe (PID: 528)
      • runonce.exe (PID: 3864)
      • PikachuW7fix.exe (PID: 5444)
    • Manual execution by a user

      • Pokemon.exe (PID: 6568)
      • PikachuW7fix.exe (PID: 3104)
      • picachu.exe (PID: 5508)
      • Kawai2003.exe (PID: 6340)
      • PikachuW7fix.exe (PID: 5444)
      • Kawai2003.exe (PID: 6088)
      • Pokemon.exe (PID: 5324)
      • Kawai2003.exe (PID: 6560)
      • picachu.exe (PID: 2132)
    • Reads the computer name

      • PikachuW7fix.exe (PID: 3104)
      • PikachuW7fix.exe (PID: 5444)
      • Pokemon.exe (PID: 5324)
      • Kawai2003.exe (PID: 6560)
      • Kawai2003.exe (PID: 6088)
      • picachu.exe (PID: 2132)
    • Create files in a temporary directory

      • PikachuW7fix.exe (PID: 3104)
      • PikachuW7fix.exe (PID: 5444)
      • picachu.exe (PID: 2132)
      • Pokemon.exe (PID: 5324)
      • Kawai2003.exe (PID: 6560)
      • Kawai2003.exe (PID: 6088)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6736)
    • Checks supported languages

      • PikachuW7fix.exe (PID: 3104)
      • PikachuW7fix.exe (PID: 5444)
      • picachu.exe (PID: 2132)
      • Pokemon.exe (PID: 5324)
      • Kawai2003.exe (PID: 6560)
      • Kawai2003.exe (PID: 6088)
    • Process checks computer location settings

      • PikachuW7fix.exe (PID: 3104)
      • PikachuW7fix.exe (PID: 5444)
    • Reads the time zone

      • runonce.exe (PID: 528)
      • runonce.exe (PID: 3864)
    • Reads security settings of Internet Explorer

      • runonce.exe (PID: 528)
      • runonce.exe (PID: 3864)
    • Reads the software policy settings

      • slui.exe (PID: 7160)
      • slui.exe (PID: 1196)
    • Creates files or folders in the user directory

      • picachu.exe (PID: 2132)
      • Kawai2003.exe (PID: 6088)
    • Checks proxy server information

      • slui.exe (PID: 1196)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)

EXIF

ZIP

FileVersion: 7z v0.04
ModifyDate: 2021:07:23 05:57:10+00:00
ArchivedFileName: FILE FIX LOI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
156
Monitored processes
22
Malicious processes
1
Suspicious processes
3

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs picachu.exe no specs sppextcomobj.exe no specs slui.exe pokemon.exe no specs kawai2003.exe no specs pikachuw7fix.exe infdefaultinstall.exe no specs infdefaultinstall.exe runonce.exe no specs grpconv.exe no specs pikachuw7fix.exe infdefaultinstall.exe no specs infdefaultinstall.exe runonce.exe no specs grpconv.exe no specs slui.exe kawai2003.exe no specs picachu.exe no specs pokemon.exe no specs kawai2003.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
528"C:\WINDOWS\system32\runonce.exe" -rC:\Windows\SysWOW64\runonce.exeInfDefaultInstall.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Run Once Wrapper
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\runonce.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
1196C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1500"C:\Windows\System32\grpconv.exe" -oC:\Windows\SysWOW64\grpconv.exerunonce.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Progman Group Converter
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\grpconv.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
2076"C:\WINDOWS\SysWOW64\InfDefaultInstall.exe" "C:\Users\admin\AppData\Local\Temp\RarSFX1\MSVBVM50.INF"C:\Windows\SysWOW64\InfDefaultInstall.exe
PikachuW7fix.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
INF Default Install
Exit code:
0
Version:
5.2.3668.0
Modules
Images
c:\windows\syswow64\infdefaultinstall.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2132"C:\Users\admin\Desktop\Pikachu\picachu.exe" C:\Users\admin\Desktop\Pikachu\picachu.exeexplorer.exe
User:
admin
Company:
CHEN PROGRAM STUDY
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\desktop\pikachu\picachu.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvbvm50.dll
c:\windows\syswow64\user32.dll
2632"C:\WINDOWS\SysWOW64\InfDefaultInstall.exe" "C:\Users\admin\AppData\Local\Temp\RarSFX0\MSVBVM50.INF"C:\Windows\SysWOW64\InfDefaultInstall.exe
PikachuW7fix.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
INF Default Install
Exit code:
0
Version:
5.2.3668.0
Modules
Images
c:\windows\syswow64\infdefaultinstall.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2692"C:\Windows\System32\grpconv.exe" -oC:\Windows\SysWOW64\grpconv.exerunonce.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Progman Group Converter
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\grpconv.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
3028"C:\WINDOWS\System32\InfDefaultInstall.exe" "C:\Users\admin\AppData\Local\Temp\RarSFX1\MSVBVM50.INF"C:\Windows\SysWOW64\InfDefaultInstall.exePikachuW7fix.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
INF Default Install
Exit code:
3221226540
Version:
5.2.3668.0
Modules
Images
c:\windows\syswow64\infdefaultinstall.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
3104"C:\Users\admin\Desktop\FILE FIX LOI\PikachuW7fix.exe" C:\Users\admin\Desktop\FILE FIX LOI\PikachuW7fix.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\file fix loi\pikachuw7fix.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
3864"C:\WINDOWS\system32\runonce.exe" -rC:\Windows\SysWOW64\runonce.exeInfDefaultInstall.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Run Once Wrapper
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\runonce.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
Total events
5 558
Read events
5 532
Write events
24
Delete events
2

Modification events

(PID) Process:(6736) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(6736) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Pikachu.7z
(PID) Process:(6736) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6736) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6736) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6736) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6736) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
(PID) Process:(6736) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:name
Value:
256
(PID) Process:(6736) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6736) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\ArcColumnWidths
Operation:writeName:psize
Value:
80
Executable files
11
Suspicious files
16
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
5444PikachuW7fix.exeC:\Users\admin\AppData\Local\Temp\RarSFX1\MSVBVM50.INFbinary
MD5:D944F6BF76987A127E74630202C97075
SHA256:1057B47D15FDCFB970FBC34958DC67109D3A5FB16581C500CE8E2EB3E5001E6E
2632InfDefaultInstall.exeC:\Windows\SysWOW64\MSVBVM50.DLLexecutable
MD5:157B3267A46A79DD900104F241DA8C4C
SHA256:8611DC1B60AE5C383BBA6CB3FFD8A51AEEBFF23B95844F0AB3D6E5ECD0FADC84
6736WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6736.46071\Pikachu\Kawai2003.exeexecutable
MD5:DCF451DCEAB3CC7A7FF9829B63E33EFD
SHA256:4BA6929C8C7DBE7518C7726B46F13CD7EC540B64A494BAF078C70A9C60327137
6736WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6736.46071\FILE FIX LOI\PikachuW7fix.exeexecutable
MD5:C468468D128519B422E6F2D98DEBF977
SHA256:64C0771E9310804C6319C5777E9FAE371B8F48DC23DE4AE326A4542A643C8E24
6736WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6736.46071\Pikachu\picachu.exeexecutable
MD5:4D19F22156167619C19341F088B1F7E2
SHA256:52B6EF01A6789E24E552B333CB77697CC608F6AF017BA8E30935E1385DFFED15
6736WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6736.46071\Pikachu\Pokemon.exeexecutable
MD5:A7B57E3575F292BD7CF67C4911A5F36A
SHA256:B7B13746AA44E244BB5F25A9BB9123CBA5807923139D7C79AF51B2D1E5AC003B
3104PikachuW7fix.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\MSVBVM50.INFbinary
MD5:D944F6BF76987A127E74630202C97075
SHA256:1057B47D15FDCFB970FBC34958DC67109D3A5FB16581C500CE8E2EB3E5001E6E
3104PikachuW7fix.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\MSVBVM50.DLLexecutable
MD5:157B3267A46A79DD900104F241DA8C4C
SHA256:8611DC1B60AE5C383BBA6CB3FFD8A51AEEBFF23B95844F0AB3D6E5ECD0FADC84
2632InfDefaultInstall.exeC:\Windows\SysWOW64\SET4402.tmpexecutable
MD5:157B3267A46A79DD900104F241DA8C4C
SHA256:8611DC1B60AE5C383BBA6CB3FFD8A51AEEBFF23B95844F0AB3D6E5ECD0FADC84
528runonce.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\ExplorerStartupLog_RunOnce.etlbinary
MD5:9886C3F84F7132AA4735A062ECA649EF
SHA256:0FFA56CB7FE3D7C2495428D7AB449C62636F2657785F19CAF227D19ECC7748D0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
44
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
314 b
whitelisted
624
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
973 b
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
1.01 Kb
whitelisted
6044
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
whitelisted
6692
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
418 b
whitelisted
6692
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
408 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1764
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
5488
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4360
SearchApp.exe
184.86.251.25:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4360
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
6944
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
624
svchost.exe
40.126.32.140:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
624
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4360
SearchApp.exe
184.86.251.22:443
www.bing.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 184.86.251.25
  • 184.86.251.28
  • 184.86.251.22
  • 184.86.251.20
  • 184.86.251.27
  • 184.86.251.23
  • 184.86.251.4
  • 184.86.251.30
  • 184.86.251.24
  • 184.86.251.26
  • 184.86.251.19
  • 184.86.251.21
  • 184.86.251.18
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
google.com
  • 216.58.206.46
whitelisted
login.live.com
  • 40.126.32.140
  • 40.126.32.72
  • 20.190.160.17
  • 20.190.160.22
  • 40.126.32.138
  • 40.126.32.133
  • 40.126.32.76
  • 40.126.32.134
whitelisted
th.bing.com
  • 184.86.251.22
  • 184.86.251.23
  • 184.86.251.24
  • 184.86.251.26
  • 184.86.251.19
  • 184.86.251.25
  • 184.86.251.20
  • 184.86.251.21
  • 184.86.251.18
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted

Threats

No threats detected
No debug info