File name:

zapret v3.rar

Full analysis: https://app.any.run/tasks/0da56aba-6275-4c84-9286-2986a6c072ef
Verdict: Malicious activity
Analysis date: May 12, 2025, 15:49:59
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
windivert-sys
mal-driver
arch-exec
arch-doc
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

315F3DD9C0436156469458FD965955B1

SHA1:

B04245E4613D919FACA1C96CEE55078508DC5DF8

SHA256:

CC20C1C076B9E1082D738EEBE55AED4A31BD404858F28598AD584F282FC9FA31

SSDEEP:

49152:Bb4FMyNCQMf5udb/DNj7Ze9rm45sDC69wDe1fwTCFvpp+kF3Ps41Vgq/6yTt92Fq:Bb4utV58b/Jj789rv5D6uDefjFvppPEa

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Malicious driver has been detected

      • WinRAR.exe (PID: 4988)
    • Detects Cygwin installation

      • WinRAR.exe (PID: 4988)
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 4988)
    • Starts application with an unusual extension

      • cmd.exe (PID: 684)
  • INFO

    • The sample compiled with english language support

      • WinRAR.exe (PID: 4988)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 4988)
    • Manual execution by a user

      • cmd.exe (PID: 684)
      • notepad.exe (PID: 2392)
      • notepad.exe (PID: 4000)
      • notepad.exe (PID: 6264)
      • notepad.exe (PID: 5600)
      • notepad.exe (PID: 5156)
      • notepad.exe (PID: 3032)
      • notepad.exe (PID: 5512)
    • Changes the display of characters in the console

      • cmd.exe (PID: 684)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 2392)
      • notepad.exe (PID: 4000)
      • notepad.exe (PID: 6264)
      • notepad.exe (PID: 5600)
      • notepad.exe (PID: 5156)
      • notepad.exe (PID: 3032)
      • notepad.exe (PID: 5512)
    • Checks supported languages

      • chcp.com (PID: 6004)
      • winws.exe (PID: 1176)
    • Reads the computer name

      • winws.exe (PID: 1176)
    • Reads the software policy settings

      • slui.exe (PID: 1040)
      • slui.exe (PID: 1660)
    • Checks proxy server information

      • slui.exe (PID: 1660)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 972435
UncompressedSize: 2954293
OperatingSystem: Win32
ArchivedFileName: zapret v3/bin/cygwin1.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
153
Monitored processes
19
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start THREAT winrar.exe sppextcomobj.exe no specs slui.exe rundll32.exe no specs notepad.exe no specs cmd.exe no specs conhost.exe no specs chcp.com no specs winws.exe no specs winws.exe no specs winws.exe conhost.exe no specs slui.exe notepad.exe no specs notepad.exe no specs notepad.exe no specs notepad.exe no specs notepad.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
616"C:\Users\admin\Desktop\zapret v3\bin\winws.exe" --wf-tcp=80,443 --wf-udp=443,50000-50099 --filter-udp=443 --hostlist="list-general.txt" --dpi-desync=fake --dpi-desync-repeats=6 --dpi-desync-fake-quic="C:\Users\admin\Desktop\zapret v3\bin\quic_initial_www_google_com.bin" --new --filter-udp=50000-50099 --ipset="ipset-discord.txt" --dpi-desync=fake --dpi-desync-any-protocol --dpi-desync-cutoff=d3 --dpi-desync-repeats=6 --new --filter-tcp=80 --hostlist="list-general.txt" --dpi-desync=fake,fakedsplit --dpi-desync-autottl=2 --dpi-desync-fooling=md5sig --new --filter-tcp=443 --hostlist="list-discord.txt" --dpi-desync=fake,multidisorder --dpi-desync-split-pos=1,midsld --dpi-desync-repeats=11 --dpi-desync-fooling=md5sig --dpi-desync-fake-tls="C:\Users\admin\Desktop\zapret v3\bin\tls_clienthello_www_google_com.bin" --new --filter-tcp=443 --hostlist="list-youtube.txt" --ipset-exclude-ip=213.59.192.0/18 --dpi-desync=fake,multidisorder --dpi-desync-ttl=1 --dpi-desync-autottl=4 --dpi-desync-split-pos=midsld --dpi-desync-fake-tls="C:\Users\admin\Desktop\zapret v3\bin\tls_clienthello_www_google_com.bin"C:\Users\admin\Desktop\zapret v3\bin\winws.execmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\zapret v3\bin\winws.exe
c:\windows\system32\ntdll.dll
684C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\Desktop\zapret v3\gr 2.bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
c:\windows\system32\advapi32.dll
1040"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1176"C:\Users\admin\Desktop\zapret v3\bin\winws.exe" --wf-tcp=80,443 --wf-udp=443,50000-50099 --filter-udp=443 --hostlist="list-general.txt" --dpi-desync=fake --dpi-desync-repeats=6 --dpi-desync-fake-quic="C:\Users\admin\Desktop\zapret v3\bin\quic_initial_www_google_com.bin" --new --filter-udp=50000-50099 --ipset="ipset-discord.txt" --dpi-desync=fake --dpi-desync-any-protocol --dpi-desync-cutoff=d3 --dpi-desync-repeats=6 --new --filter-tcp=80 --hostlist="list-general.txt" --dpi-desync=fake,fakedsplit --dpi-desync-autottl=2 --dpi-desync-fooling=md5sig --new --filter-tcp=443 --hostlist="list-discord.txt" --dpi-desync=fake,multidisorder --dpi-desync-split-pos=1,midsld --dpi-desync-repeats=11 --dpi-desync-fooling=md5sig --dpi-desync-fake-tls="C:\Users\admin\Desktop\zapret v3\bin\tls_clienthello_www_google_com.bin" --new --filter-tcp=443 --hostlist="list-youtube.txt" --ipset-exclude-ip=213.59.192.0/18 --dpi-desync=fake,multidisorder --dpi-desync-ttl=1 --dpi-desync-autottl=4 --dpi-desync-split-pos=midsld --dpi-desync-fake-tls="C:\Users\admin\Desktop\zapret v3\bin\tls_clienthello_www_google_com.bin"C:\Users\admin\Desktop\zapret v3\bin\winws.exe
cmd.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\zapret v3\bin\winws.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ole32.dll
1660C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2392"C:\WINDOWS\System32\NOTEPAD.EXE" C:\Users\admin\Desktop\zapret v3\gr.batC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
3032"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\zapret v3\list-general.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
4000"C:\WINDOWS\System32\NOTEPAD.EXE" C:\Users\admin\Desktop\zapret v3\gr 2.batC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
4228C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
4988"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\zapret v3.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
3 983
Read events
3 972
Write events
11
Delete events
0

Modification events

(PID) Process:(4988) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(4988) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(4988) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(4988) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\zapret v3.rar
(PID) Process:(4988) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4988) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4988) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(4988) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1176) winws.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\System\WinDivert
Operation:writeName:EventMessageFile
Value:
C:\Users\admin\Desktop\zapret v3\bin\WinDivert64.sys
(PID) Process:(1176) winws.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\System\WinDivert
Operation:writeName:TypesSupported
Value:
7
Executable files
4
Suspicious files
2
Text files
10
Unknown types
0

Dropped files

PID
Process
Filename
Type
4988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4988.33305\zapret v3\bin\winws.exeexecutable
MD5:C547641B69FE682947F1EBB7048ADED0
SHA256:721F2029FC4CC9948E252BF000367376F01345666DEE0F9D384B8742D9B0F2EA
4988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4988.33305\zapret v3\gr.battext
MD5:49BFAF7941E3AA1003297573DCA2CC3A
SHA256:70931F90F63EA99935E94D1CCBEA5F6FA28064AE11D9104652094CDB7D12EF56
4988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4988.33305\zapret v3\bin\tls_clienthello_www_google_com.binbinary
MD5:7AB7AD857C5B8794FBDF1091B494DC94
SHA256:E5938780152169F720383F80EABB309E9477369B83B5EC40CC137C397F862CDE
4988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4988.33305\zapret v3\list-discord.txttext
MD5:D57A59CD427A634F17080D95940E919A
SHA256:EB558C01A448DD15339FD7A152F820F0925509310F3B54C9E249A8026BDAA477
4988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4988.33305\zapret v3\bin\quic_initial_www_google_com.binbinary
MD5:312526D39958D89B1F8AB67789AB985F
SHA256:F4589C57749F956BB30538197A521D7005F8B0A8723B4707E72405E51DDAC50A
4988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4988.33305\zapret v3\ipset-discord.txttext
MD5:40C75BA0A3C07F51CFC98082739C28E1
SHA256:FA0CA1ECB60EAE74C343B2975280F6A6CB6CB44D965ACB33AC5B9502F1C9E3DC
4988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4988.33305\zapret v3\service_install.battext
MD5:F14C44FADE95F4CC8D5C8C701AA2B8D9
SHA256:EA7880BAF0D77FB1F1EF664AA5A280ED8C48D938C07E798BEE682BD0C232D6DA
4988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4988.33305\zapret v3\list-general.txttext
MD5:FEE24D3730BB2FD133CFC4973EEC517E
SHA256:8E75C43057FC5DEBE2937D4DDFBB606207137B5AE95D7598A7C05F6CA808F2CA
4988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4988.33305\zapret v3\list-youtube.txttext
MD5:4849C26DA4DE5B2ADF5528136D086115
SHA256:F67058092755F79294A8762D5C7BE16A450F71EEC955D849909B871D2E08190A
4988WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa4988.33305\zapret v3\test.battext
MD5:3F1D475BE51832D1AD2C439EEAE2D007
SHA256:879A6C4975B0D65B08951EC89325E93DF3C0CE75EB177DA5A90E04C960353E45
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
26
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2104
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2104
svchost.exe
GET
200
23.48.23.193:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5544
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5544
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6544
svchost.exe
40.126.31.1:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
23.48.23.193:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2104
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
6544
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
5544
SIHClient.exe
20.12.23.50:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
login.live.com
  • 40.126.31.1
  • 20.190.159.4
  • 20.190.159.64
  • 40.126.31.130
  • 20.190.159.0
  • 40.126.31.131
  • 20.190.159.73
  • 40.126.31.0
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
google.com
  • 142.250.186.174
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.48.23.193
  • 23.48.23.146
  • 23.48.23.157
  • 23.48.23.147
  • 23.48.23.141
  • 23.48.23.155
  • 23.48.23.153
  • 23.48.23.156
  • 23.48.23.194
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
nexusrules.officeapps.live.com
  • 52.111.243.29
whitelisted

Threats

No threats detected
No debug info